Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 6 of 6

This is a discussion on vps firewall configuration in the VPS & Dedicated forum
When aura was restored a couple of weeks back the virtuozzo firewall iptables were blocking outgoing SMTP connections - which JPC has fixed. As a ...

  1. #1
    JPC Senior Member
    Join Date
    Jul 2006
    Posts
    92

    vps firewall configuration

    When aura was restored a couple of weeks back the virtuozzo firewall iptables were blocking outgoing SMTP connections - which JPC has fixed. As a result, and also trying to learn something, I've tried changing the 3 settings in the virtuozzo firewall control panel (normal, default accept, and default drop) and testing if I could access webmail. The only way accessing webmail works is "default accept" - I guess I don't understand why the "normal" setting doesn't allow simple webmail access. I've read through virtuozzo firewall chapter and its not very clear to me. Does anyone have any pointers or suggestions on setting this up? And, what about a different firewall like CSF that has a WHM configuration interface. In reading about CSF and its rulesets - their terminology is much more understandable to me than Virtuozzo.

    Any suggestions or comments appreciated.

  2. #2
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    OK, here's a complete guess, but from the sounds of things "normal" is a default setting for IPTables. Since webmail usually runs on ports that are not in the range of what's considered "well known ports" (things like SSH, FTP, HTTP, etc.) then the normal settings for the webmail ports (in general on a non-cpanel server) is probably "block."

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  3. #3
    JPC Senior Member
    Join Date
    Jul 2006
    Posts
    92
    Good suggestion. In "normal" mode I can access ftp, ssh, and http. But not, IMAP, SMTP, or cPanel. I do think its very possible that this is still a ports issue.

  4. #4
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    For best results you should probably explicitly allow or deny everything according to how you want your site configured and not rely on "normal" settings. If a normal setting changes it could cause problems that may not be immeadiately noticable.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  5. #5
    JPC Senior Member
    Join Date
    Jul 2006
    Posts
    92
    The "normal" settings are pretty much unusable in my estimation. So, as you suggest, I will allow/deny individual rules as needed. Thanks.

  6. #6

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •