I'm trying to a get a SIP connection.
When I disable iptables it works, when they are up it fails.
I want to open port 5060-5080 and 10,000-20,000
Here are my tables
I entered these commandsCode:cat /etc/sysconfig/iptables # Generated by iptables-save v1.4.7 on Sat Nov 24 20:50:53 2012 *filter :INPUT DROP [0:0] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] :WHITELIST - [0:0] :fail2ban-APACHE - [0:0] :fail2ban-ASTERISK - [0:0] :fail2ban-BadBots - [0:0] :fail2ban-SSH - [0:0] :fail2ban-VSFTPD - [0:0] -A INPUT -p tcp -m tcp --dport 21 -j fail2ban-VSFTPD -A INPUT -p tcp -m multiport --dports 80,443 -j fail2ban-BadBots -A INPUT -p tcp -j fail2ban-APACHE -A INPUT -j fail2ban-ASTERISK -A INPUT -p tcp -m tcp --dport 22 -j fail2ban-SSH -A INPUT -p tcp -m tcp --dport 21 -j fail2ban-VSFTPD -A INPUT -p tcp -m multiport --dports 80,443 -j fail2ban-BadBots -A INPUT -p tcp -j fail2ban-APACHE -A INPUT -j fail2ban-ASTERISK -A INPUT -p tcp -m tcp --dport 22 -j fail2ban-SSH -A INPUT ! -i eth0 -j ACCEPT -A INPUT -p tcp -m tcp --tcp-flags ACK ACK -j ACCEPT -A INPUT -m state --state ESTABLISHED -j ACCEPT -A INPUT -m state --state RELATED -j ACCEPT -A INPUT -p udp -m udp --sport 53 --dport 1024:65535 -j ACCEPT -A INPUT -p icmp -m icmp --icmp-type 0 -j ACCEPT -A INPUT -p icmp -m icmp --icmp-type 3 -j ACCEPT -A INPUT -p icmp -m icmp --icmp-type 4 -j ACCEPT -A INPUT -p icmp -m icmp --icmp-type 11 -j ACCEPT -A INPUT -p icmp -m icmp --icmp-type 12 -j ACCEPT -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT -A INPUT -p tcp -m tcp --dport 113 -j ACCEPT -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT -A INPUT -p tcp -m tcp --dport 21 -j ACCEPT -A INPUT -p tcp -m tcp --dport 9001 -j ACCEPT -A INPUT -p tcp -m tcp --dport 9080 -j ACCEPT -A INPUT -p udp -m udp --dport 10000:20000 -j ACCEPT -A INPUT -p tcp -m tcp --dport 4445 -j ACCEPT -A INPUT -p tcp -m tcp --dport 5038 -j ACCEPT -A INPUT -p udp -m udp --dport 123 -j ACCEPT # PPTP requires TCP 1723 port opening -A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT -A INPUT -p udp -m udp --dport 69 -j ACCEPT -A INPUT -p tcp -m tcp --dport 9022 -j ACCEPT -A INPUT -p udp -m udp --dport 5222 -j ACCEPT -A INPUT -s 64.27.1.153/32 -p udp -m udp --dport 4569 -j ACCEPT -A INPUT -s 66.54.140.46/32 -p udp -m udp --dport 4569 -j ACCEPT -A INPUT -s 66.54.140.47/32 -p udp -m udp --dport 4569 -j ACCEPT -A INPUT -p tcp -m tcp --dport 88 -j ACCEPT -A INPUT -p tcp -m tcp --dport 5060 -j ACCEPT -A INPUT -s 74.125.92.125/32 -j ACCEPT -A INPUT -s 74.125.67.84/32 -j ACCEPT -A INPUT -p udp -m multiport --dports 4569,5000:5082 -j WHITELIST -A INPUT -s 68.118.198.120/32 -j ACCEPT -A INPUT -s 192.168.0.0/16 -j ACCEPT -A INPUT -s 172.16.0.0/12 -j ACCEPT -A INPUT -s 10.0.0.0/8 -j ACCEPT -A INPUT -s 127.0.0.0/8 -j ACCEPT -A INPUT -s 10.10.11.0/24 -p tcp -m tcp -j ACCEPT -A WHITELIST -s 64.2.142.26/32 -j ACCEPT -A WHITELIST -s 64.2.142.18/32 -j ACCEPT -A WHITELIST -s 204.155.28.10/32 -j ACCEPT -A WHITELIST -s 209.216.2.211/32 -j ACCEPT -A WHITELIST -s 204.11.192.160/32 -j ACCEPT -A WHITELIST -s 64.251.23.244/32 -j ACCEPT -A WHITELIST -s 67.228.182.2/32 -j ACCEPT -A WHITELIST -s 64.136.174.24/32 -j ACCEPT -A WHITELIST -s 64.136.174.24/32 -j ACCEPT -A WHITELIST -s 69.90.174.98/32 -j ACCEPT -A WHITELIST -s 63.211.239.28/32 -j ACCEPT -A WHITELIST -s 64.34.181.47/32 -j ACCEPT -A fail2ban-APACHE -j RETURN -A fail2ban-APACHE -j RETURN -A fail2ban-ASTERISK -j RETURN -A fail2ban-ASTERISK -j RETURN -A fail2ban-BadBots -j RETURN -A fail2ban-BadBots -j RETURN -A fail2ban-SSH -j RETURN -A fail2ban-SSH -j RETURN -A fail2ban-VSFTPD -j RETURN -A fail2ban-VSFTPD -j RETURN COMMIT # Completed on Sat Nov 24 20:50:53 2012 # Generated by iptables-save v1.4.7 on Sat Nov 24 20:50:53 2012 *mangle :PREROUTING ACCEPT [38310:41252265] :INPUT ACCEPT [37482:41205411] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [26738:3357606] :POSTROUTING ACCEPT [26738:3357606] COMMIT # Completed on Sat Nov 24 20:50:53 2012 # Generated by iptables-save v1.4.7 on Sat Nov 24 20:50:53 2012 *nat :PREROUTING ACCEPT [1241:145918] :POSTROUTING ACCEPT [752:55530] :OUTPUT ACCEPT [752:55530] COMMIT # Completed on Sat Nov 24 20:50:53 2012
iptables -A INPUT -p udp -m udp --dport 5060 -j ACCEPT
iptables -A INPUT -p udp -m udp --dport 10000:20000 -j ACCEPT
Did I do it right?
The connection still fails if I bring the service up.




Adv Reply
Bookmarks