Hi all, I configured a firewall with a DROP policy and cacti can't graph the net.. I have these rules:
/sbin/iptables -A OUTPUT -p icmp -m icmp -j ACCEPT
/sbin/iptables -A INPUT -p icmp -m icmp -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -A OUTPUT -p udp -m udp --dport 135 -j ACCEPT
/sbin/iptables -A INPUT -p udp -m udp --sport 135 -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -A OUTPUT -p udp -m udp --dport 161 -j ACCEPT
/sbin/iptables -A INPUT -p udp -m udp --sport 161 -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 161 -j ACCEPT
/sbin/iptables -A INPUT -p tcp -m tcp --sport 161 -m state --state RELATED,ESTABLISHED -j ACCEPT
snmp and pings don't work, any help?
thanks
How to configure iptables with a DROP policy
Moderators: Developers, Moderators
[solved] How to configure iptables with a DROP policy
seems to works with these rules:
# Cacti UDP ping
/sbin/iptables -A OUTPUT -p udp -m udp --dport 33439 -j ACCEPT
/sbin/iptables -A INPUT -p udp -m udp --sport 33439 -m state --state RELATED,ESTABLISHED -j ACCEPT
# SNMP
/sbin/iptables -A OUTPUT -p udp -m udp --dport 161 -j ACCEPT
/sbin/iptables -A INPUT -p udp -m udp --sport 161 -m state --state RELATED,ESTABLISHED -j ACCEPT
# Cacti UDP ping
/sbin/iptables -A OUTPUT -p udp -m udp --dport 33439 -j ACCEPT
/sbin/iptables -A INPUT -p udp -m udp --sport 33439 -m state --state RELATED,ESTABLISHED -j ACCEPT
# SNMP
/sbin/iptables -A OUTPUT -p udp -m udp --dport 161 -j ACCEPT
/sbin/iptables -A INPUT -p udp -m udp --sport 161 -m state --state RELATED,ESTABLISHED -j ACCEPT
Who is online
Users browsing this forum: No registered users and 0 guests