View previous topic :: View next topic |
Author |
Message |
hinge n00b
Joined: 23 Jun 2005 Posts: 43 Location: Copenhagen
|
Posted: Thu Jul 06, 2006 7:05 pm Post subject: FTP and SSH works from LAN but not from WAN - firewall OK |
|
|
This I don't get....
I have a couple og gentoo computers running on a LAN, all connected to a router with a built in firewall. One of the computers acts as a server with FTP and ssh access. I have never had any problems.....
Until one day last week....
All of a sudden I could not connect to my ftp server nor my SSH from the WAN side (outside my own network, from the internet). In the beginning I thourght that it was my firewall that was screwed up, but I have tried to open the firewall to one of the other couputers and the ssh access works fine for those.
So I don't think that it is my firewall. But what part of my server is messed up - both ssh and ftp is out....when I try to log on through ssh I dont get anything - like the computer is turned off. When I connect the ftp and SSH from within my LAN everything works fine....
Where should I start ??
what could cause this ???
What gives??
Edit....
Ohh yes by the way....I am having problems syncing my portage. When I do a emerge --sync I get:
Code: |
~ # emerge --sync
WARNING: usage of RSYNC_TIMEOUT is deprecated, use PORTAGE_RSYNC_EXTRA_OPTS instead
>>> Starting rsync with rsync://134.147.32.57/gentoo/...
>>> Checking server timestamp ...
Server name: linux.rz.ruhr-uni-bochum.de
IP address: 134.147.32.57
Hardware: Pentium 4 @ 1.5 GHz, 512 MB RAM
Outgoing bandwidth: throttled to 2.5 MByte/s 5 min average
User connection limit: currently none
Server location: Bochum, Ruhrgebiet, Germany
Administrative contact: Markus Passerschr\#366er <linux-support@ruhr-uni-bochum.de>
@ERROR: Unknown module 'gentoo'
rsync error: error starting client-server protocol (code 5) at main.c(1296) [receiver=2.6.8]
>>> Retrying...
>>> Starting retry 1 of 3 with rsync://134.147.32.57/gentoo/
>>> Checking server timestamp ...
Server name: linux.rz.ruhr-uni-bochum.de
IP address: 134.147.32.57
Hardware: Pentium 4 @ 1.5 GHz, 512 MB RAM
Outgoing bandwidth: throttled to 2.5 MByte/s 5 min average
User connection limit: currently none
Server location: Bochum, Ruhrgebiet, Germany
Administrative contact: Markus Passerschr\#366er <linux-support@ruhr-uni-bochum.de>
@ERROR: Unknown module 'gentoo'
rsync error: error starting client-server protocol (code 5) at main.c(1296) [receiver=2.6.8]
>>> Retrying...
>>> Starting retry 2 of 3 with rsync://134.147.32.57/gentoo/
>>> Checking server timestamp ...
Server name: linux.rz.ruhr-uni-bochum.de
IP address: 134.147.32.57
Hardware: Pentium 4 @ 1.5 GHz, 512 MB RAM
Outgoing bandwidth: throttled to 2.5 MByte/s 5 min average
User connection limit: currently none
Server location: Bochum, Ruhrgebiet, Germany
Administrative contact: Markus Passerschr\#366er <linux-support@ruhr-uni-bochum.de>
@ERROR: Unknown module 'gentoo'
rsync error: error starting client-server protocol (code 5) at main.c(1296) [receiver=2.6.8]
>>> Retrying...
>>> Starting retry 3 of 3 with rsync://134.147.32.57/gentoo/
>>> Checking server timestamp ...
Server name: linux.rz.ruhr-uni-bochum.de
IP address: 134.147.32.57
Hardware: Pentium 4 @ 1.5 GHz, 512 MB RAM
Outgoing bandwidth: throttled to 2.5 MByte/s 5 min average
User connection limit: currently none
Server location: Bochum, Ruhrgebiet, Germany
Administrative contact: Markus Passerschr\#366er <linux-support@ruhr-uni-bochum.de>
@ERROR: Unknown module 'gentoo'
rsync error: error starting client-server protocol (code 5) at main.c(1296) [receiver=2.6.8]
!!! Rsync has not successfully finished. It is recommended that you keep
!!! trying or that you use the 'emerge-webrsync' option if you are unable
!!! to use rsync due to firewall or other restrictions. This should be a
!!! temporary problem unless complications exist with your network
!!! (and possibly your system's filesystem) configuration.
|
Could this be related
Last edited by hinge on Thu Jul 06, 2006 8:00 pm; edited 1 time in total |
|
Back to top |
|
|
lxg Veteran
Joined: 12 Nov 2005 Posts: 1019 Location: Aachen, Germany
|
Posted: Thu Jul 06, 2006 8:00 pm Post subject: |
|
|
Hm, even if you're sure that it's not the firewall... Could you please flush all iptables rules and turn all firewalls down for a test run? _________________ lxg.de – codebits and tech talk |
|
Back to top |
|
|
hinge n00b
Joined: 23 Jun 2005 Posts: 43 Location: Copenhagen
|
Posted: Thu Jul 06, 2006 8:24 pm Post subject: |
|
|
My firewall is hardware based...iptables is only when the firewall is linux based - right ??
Otherwise how do I do a iptables flush ?
Tried turning off the firewall...no help...
|
|
Back to top |
|
|
Mroofka Guru
Joined: 25 Jan 2005 Posts: 369 Location: Poland
|
Posted: Thu Jul 06, 2006 8:26 pm Post subject: |
|
|
is router the gentoo box ?? i guess not.
do you forward port's for ssh and ftp on router to your local network ? without this you wont be able to connect the serwer from the outside
Pozdrawaim _________________ "Make install not love"
registred linux User # 379143
"Ready for Anything; Prepared for everything; Surprised by Nothing !" |
|
Back to top |
|
|
hinge n00b
Joined: 23 Jun 2005 Posts: 43 Location: Copenhagen
|
Posted: Thu Jul 06, 2006 8:33 pm Post subject: |
|
|
No my router is not a gentoo box - it is inside my Belkin router.
And yes I do port forwarding - in the router I have a item called "virtual servers" there I can say which port requests shouls go to which computers on the lan....port forwarding.
Please keep en mind that this system has been working for almost a year - until last week.
I am not saying that I didn't do anything - I just dont know what. |
|
Back to top |
|
|
think4urs11 Bodhisattva
Joined: 25 Jun 2003 Posts: 6659 Location: above the cloud
|
Posted: Thu Jul 06, 2006 9:33 pm Post subject: |
|
|
OpenSSH update on the affected machine maybe?
Is the sshd_config still allowing access from external (i.e. bound to the correct ip, no host based restrictions and alike)? _________________ Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself |
|
Back to top |
|
|
hinge n00b
Joined: 23 Jun 2005 Posts: 43 Location: Copenhagen
|
Posted: Fri Jul 07, 2006 10:53 am Post subject: |
|
|
I've done something that I am very used to on windows - but that I have never been forced to do on linux for the 2 years that I've run it....
I have striped the installation and started from scratch.....it is actually a lot of fun.....
Thanks though |
|
Back to top |
|
|
|