perfsonar-user - Re: [perfsonar-user] Perfsonar ports - tracepath blocked
Subject: perfSONAR User Q&A and Other Discussion
List archive
- From: Brian Candler <>
- To: Andrew Lake <>, "" <>
- Subject: Re: [perfsonar-user] Perfsonar ports - tracepath blocked
- Date: Thu, 18 Feb 2016 13:49:44 +0000
- Domainkey-signature: a=rsa-sha1; c=nofws; d=pobox.com; h=subject:to :references:from:message-id:date:mime-version:in-reply-to :content-type; q=dns; s=sasl; b=GetAylSnt7KEAFp7mesaoojGR45Ioavc xmTLHxjsjssGJ96ozd7zmepUIJe2r9cAzfzuGBGQxGo+IOMYjzXuJlA7n0Tju3lb rpqDCc+7rIGiz1dRJCRbDz1TEYOKZQTVxADBfQN3mT8CZr+Y8Z1g+blo/HgGh/fr AKcY4MKvPEU=
On 16/02/2016 21:54, Andrew Lake wrote:
The boxes here have updated: $ sudo iptables -L -n [sudo] password for brian: Chain INPUT (policy ACCEPT) target prot opt source destination perfSONAR all -- 0.0.0.0/0 0.0.0.0/0 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable Chain FORWARD (policy ACCEPT) target prot opt source destination REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable Chain OUTPUT (policy ACCEPT) target prot opt source destination ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 Chain perfSONAR (1 references) target prot opt source destination ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:5001:5300 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpts:5001:5300 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:5301:5600 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpts:5301:5600 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:5601:5900 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpts:5601:5900 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:6001:6200 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpts:6001:6200 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:8760:9960 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpts:8760:9960 ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 icmp type 255 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW,ESTABLISHED tcp dpt:22 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:123 udp ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 state NEW udp spt:547 dpt:546 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:33434:33634 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpts:8001:8020 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpts:3001:3003 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:4823 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:861 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:8000 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:7123 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:843 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:80 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:443 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:8090 RETURN all -- 0.0.0.0/0 0.0.0.0/0 (aside: the "Accept all 0.0.0.0/0 0.0.0.0/0" rule only applies to packets inbound on the 'lo' interface, as "-v" shows) However, compared to the older boxes, the fail2ban-SSH chain and target link are not there. I don't *think* I installed the fail2ban rules myself. But I did manually add some other rules for other services, so it's not a clean example to work from. Maybe what happened is: - at system installation time, the fail2ban package installed its own iptables rules - then perfsonar overwrote them But that's only a guess. If someone can make a fresh install of latest 3.5 ISO they can check if the fail2ban rules are there or not. Regards, Brian. |
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, (continued)
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Brian Candler, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Brian Candler, 02/16/2016
- RE: [perfsonar-user] Perfsonar ports - tracepath blocked, Garnizov, Ivan (RRZE), 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Brian Candler, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Brian Candler, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Brian Candler, 02/18/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/18/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
Archive powered by MHonArc 2.6.16.