Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

  1. #1
    Join Date
    Aug 2011
    Beans
    33

    Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

    Hi,
    I've just successfully upgraded to 14.04 from Ubuntu 13.10, I set GUFW policy to deny both incoming and outgoing traffic, then I allowed
    all the connection to Port 1234 for all the interfaces to all destinations as you may see in below image.

    GUFW.jpg

    The problem I'm facing is that UFW is still blocking connection to port 1234.

    Code:
    [UFW BLOCK] IN= OUT=wlan0 SRC=192.168.1.222 DST=108.***.**.*** LEN=42 TOS=0x00 PREC=0x00 TTL=64 ID=36286 DF PROTO=UDP SPT=37546 DPT=1234 LEN=22
    I tried to purge both UFW and GUFW and install them again, switched among different kernel versions, specify interface/from IP/To IP but UFW is blocking connection to port 1234.

    Any help is appreciated...

    P.S: Allowing all outgoing connection does the trick but that's not what I'm looking for.

    Below the output of sudo iptables -L -n if you want to take a look at it.

    Code:
    Chain INPUT (policy DROP)
    target     prot opt source               destination         
    fail2ban-ssh  tcp  --  0.0.0.0/0            0.0.0.0/0            multiport dports 22
    ufw-before-logging-input  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-before-input  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-input  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-logging-input  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-reject-input  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-track-input  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain FORWARD (policy DROP)
    target     prot opt source               destination         
    ufw-before-logging-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-before-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-logging-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-reject-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-track-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain OUTPUT (policy DROP)
    target     prot opt source               destination         
    ufw-before-logging-output  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-before-output  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-output  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-logging-output  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-reject-output  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-track-output  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain fail2ban-ssh (1 references)
    target     prot opt source               destination         
    RETURN     all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-after-forward (1 references)
    target     prot opt source               destination         
    
    Chain ufw-after-input (1 references)
    target     prot opt source               destination         
    ufw-skip-to-policy-input  udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:137
    ufw-skip-to-policy-input  udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:138
    ufw-skip-to-policy-input  tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:139
    ufw-skip-to-policy-input  tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:445
    ufw-skip-to-policy-input  udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:67
    ufw-skip-to-policy-input  udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:68
    ufw-skip-to-policy-input  all  --  0.0.0.0/0            0.0.0.0/0            ADDRTYPE match dst-type BROADCAST
    
    Chain ufw-after-logging-forward (1 references)
    target     prot opt source               destination         
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
    
    Chain ufw-after-logging-input (1 references)
    target     prot opt source               destination         
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
    
    Chain ufw-after-logging-output (1 references)
    target     prot opt source               destination         
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
    
    Chain ufw-after-output (1 references)
    target     prot opt source               destination         
    
    Chain ufw-before-forward (1 references)
    target     prot opt source               destination         
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0            ctstate RELATED,ESTABLISHED
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 3
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 4
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 11
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 12
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 8
    ufw-user-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-before-input (1 references)
    target     prot opt source               destination         
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0            ctstate RELATED,ESTABLISHED
    ufw-logging-deny  all  --  0.0.0.0/0            0.0.0.0/0            ctstate INVALID
    DROP       all  --  0.0.0.0/0            0.0.0.0/0            ctstate INVALID
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 3
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 4
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 11
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 12
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 8
    ACCEPT     udp  --  0.0.0.0/0            0.0.0.0/0            udp spt:67 dpt:68
    ufw-not-local  all  --  0.0.0.0/0            0.0.0.0/0           
    ACCEPT     udp  --  0.0.0.0/0            224.0.0.251          udp dpt:5353
    ACCEPT     udp  --  0.0.0.0/0            239.255.255.250      udp dpt:1900
    ufw-user-input  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-before-logging-forward (1 references)
    target     prot opt source               destination         
    
    Chain ufw-before-logging-input (1 references)
    target     prot opt source               destination         
    
    Chain ufw-before-logging-output (1 references)
    target     prot opt source               destination         
    
    Chain ufw-before-output (1 references)
    target     prot opt source               destination         
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0            ctstate RELATED,ESTABLISHED
    ufw-user-output  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-logging-allow (0 references)
    target     prot opt source               destination         
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW ALLOW] "
    
    Chain ufw-logging-deny (2 references)
    target     prot opt source               destination         
    RETURN     all  --  0.0.0.0/0            0.0.0.0/0            ctstate INVALID limit: avg 3/min burst 10
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
    
    Chain ufw-not-local (1 references)
    target     prot opt source               destination         
    RETURN     all  --  0.0.0.0/0            0.0.0.0/0            ADDRTYPE match dst-type LOCAL
    RETURN     all  --  0.0.0.0/0            0.0.0.0/0            ADDRTYPE match dst-type MULTICAST
    RETURN     all  --  0.0.0.0/0            0.0.0.0/0            ADDRTYPE match dst-type BROADCAST
    ufw-logging-deny  all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10
    DROP       all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-reject-forward (1 references)
    target     prot opt source               destination         
    
    Chain ufw-reject-input (1 references)
    target     prot opt source               destination         
    
    Chain ufw-reject-output (1 references)
    target     prot opt source               destination         
    
    Chain ufw-skip-to-policy-forward (0 references)
    target     prot opt source               destination         
    DROP       all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-skip-to-policy-input (7 references)
    target     prot opt source               destination         
    DROP       all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-skip-to-policy-output (0 references)
    target     prot opt source               destination         
    DROP       all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-track-forward (1 references)
    target     prot opt source               destination         
    
    Chain ufw-track-input (1 references)
    target     prot opt source               destination         
    
    Chain ufw-track-output (1 references)
    target     prot opt source               destination         
    
    Chain ufw-user-forward (1 references)
    target     prot opt source               destination         
    
    Chain ufw-user-input (1 references)
    target     prot opt source               destination         
    ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:1234
    ACCEPT     udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:1234
    
    Chain ufw-user-limit (0 references)
    target     prot opt source               destination         
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 5 LOG flags 0 level 4 prefix "[UFW LIMIT BLOCK] "
    REJECT     all  --  0.0.0.0/0            0.0.0.0/0            reject-with icmp-port-unreachable
    
    Chain ufw-user-limit-accept (0 references)
    target     prot opt source               destination         
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-user-logging-forward (0 references)
    target     prot opt source               destination         
    
    Chain ufw-user-logging-input (0 references)
    target     prot opt source               destination         
    
    Chain ufw-user-logging-output (0 references)
    target     prot opt source               destination         
    
    Chain ufw-user-output (1 references)
    target     prot opt source               destination
    Last edited by andrey_; July 3rd, 2014 at 02:32 PM.

  2. #2
    Join Date
    Jan 2014
    Beans
    Hidden!

    Re: Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

    From what I see, this firewall configuration will not let ANY traffic out through the OUTPUT chain. You need to ACCEPT pt 1234 on the OUTPUT chain. Source IP/DEST IP doesn't refer to INPUT chain OUTPUT chain

  3. #3
    Join Date
    Aug 2011
    Beans
    33

    Re: Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

    Quote Originally Posted by untrustytahr View Post
    From what I see, this firewall configuration will not let ANY traffic out through the OUTPUT chain. You need to ACCEPT pt 1234 on the OUTPUT chain. Source IP/DEST IP doesn't refer to INPUT chain OUTPUT chain

    I did not add any iptables rules directly , I added the rules the same way I used to add it successfully on 13.10 through GUFW, but now it does not work anymore and cannot understand why
    and how!

    This version of GUFW doesn't have "Allow Out" and "Allow in", you simply put the IP and or port in "To".. maybe it has to do with that...

  4. #4
    Join Date
    Jan 2014
    Beans
    Hidden!

    Re: Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

    Quote Originally Posted by andrey_ View Post
    .. maybe it has to do with that...
    That would be ANOTHER excellent reason not to use it. I don't use it so I couldn't tell you about it. G/UFW are just tools to interact with iptables. You can just manually put a rule on the ouput side.

  5. #5
    Join Date
    Aug 2011
    Beans
    33

    Re: Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

    The thing is that I've been using GUFW since the time I started using Ubuntu and I don't have the time nor the well to configure my firewall in the terminal, and GUFW was
    just good doing that.

    I ended up restoring my 13.10 from time being , and GUFW works fine again, below is sudo iptables -L -n output ( 13.10 ) :

    Code:
    Chain INPUT (policy DROP)
    target     prot opt source               destination         
    ufw-before-logging-input  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-before-input  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-input  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-logging-input  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-reject-input  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-track-input  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain FORWARD (policy DROP)
    target     prot opt source               destination         
    ufw-before-logging-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-before-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-logging-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-reject-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain OUTPUT (policy DROP)
    target     prot opt source               destination         
    ufw-before-logging-output  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-before-output  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-output  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-after-logging-output  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-reject-output  all  --  0.0.0.0/0            0.0.0.0/0           
    ufw-track-output  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-after-forward (1 references)
    target     prot opt source               destination         
    
    Chain ufw-after-input (1 references)
    target     prot opt source               destination         
    ufw-skip-to-policy-input  udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:137
    ufw-skip-to-policy-input  udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:138
    ufw-skip-to-policy-input  tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:139
    ufw-skip-to-policy-input  tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:445
    ufw-skip-to-policy-input  udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:67
    ufw-skip-to-policy-input  udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:68
    ufw-skip-to-policy-input  all  --  0.0.0.0/0            0.0.0.0/0            ADDRTYPE match dst-type BROADCAST
    
    Chain ufw-after-logging-forward (1 references)
    target     prot opt source               destination         
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
    
    Chain ufw-after-logging-input (1 references)
    target     prot opt source               destination         
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
    
    Chain ufw-after-logging-output (1 references)
    target     prot opt source               destination         
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
    
    Chain ufw-after-output (1 references)
    target     prot opt source               destination         
    
    Chain ufw-before-forward (1 references)
    target     prot opt source               destination         
    ufw-user-forward  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-before-input (1 references)
    target     prot opt source               destination         
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
    ufw-logging-deny  all  --  0.0.0.0/0            0.0.0.0/0            state INVALID
    DROP       all  --  0.0.0.0/0            0.0.0.0/0            state INVALID
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 3
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 4
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 11
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 12
    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 8
    ACCEPT     udp  --  0.0.0.0/0            0.0.0.0/0            udp spt:67 dpt:68
    ufw-not-local  all  --  0.0.0.0/0            0.0.0.0/0           
    ACCEPT     udp  --  0.0.0.0/0            224.0.0.251          udp dpt:5353
    ACCEPT     udp  --  0.0.0.0/0            239.255.255.250      udp dpt:1900
    ufw-user-input  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-before-logging-forward (1 references)
    target     prot opt source               destination         
    
    Chain ufw-before-logging-input (1 references)
    target     prot opt source               destination         
    
    Chain ufw-before-logging-output (1 references)
    target     prot opt source               destination         
    
    Chain ufw-before-output (1 references)
    target     prot opt source               destination         
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
    ufw-user-output  all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-logging-allow (0 references)
    target     prot opt source               destination         
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW ALLOW] "
    
    Chain ufw-logging-deny (2 references)
    target     prot opt source               destination         
    RETURN     all  --  0.0.0.0/0            0.0.0.0/0            state INVALID limit: avg 3/min burst 10
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
    
    Chain ufw-not-local (1 references)
    target     prot opt source               destination         
    RETURN     all  --  0.0.0.0/0            0.0.0.0/0            ADDRTYPE match dst-type LOCAL
    RETURN     all  --  0.0.0.0/0            0.0.0.0/0            ADDRTYPE match dst-type MULTICAST
    RETURN     all  --  0.0.0.0/0            0.0.0.0/0            ADDRTYPE match dst-type BROADCAST
    ufw-logging-deny  all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 10
    DROP       all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-reject-forward (1 references)
    target     prot opt source               destination         
    
    Chain ufw-reject-input (1 references)
    target     prot opt source               destination         
    
    Chain ufw-reject-output (1 references)
    target     prot opt source               destination         
    
    Chain ufw-skip-to-policy-forward (0 references)
    target     prot opt source               destination         
    DROP       all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-skip-to-policy-input (7 references)
    target     prot opt source               destination         
    DROP       all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-skip-to-policy-output (0 references)
    target     prot opt source               destination         
    DROP       all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-track-input (1 references)
    target     prot opt source               destination         
    
    Chain ufw-track-output (1 references)
    target     prot opt source               destination         
    
    Chain ufw-user-forward (1 references)
    target     prot opt source               destination         
    
    Chain ufw-user-input (1 references)
    target     prot opt source               destination         
    
    Chain ufw-user-limit (0 references)
    target     prot opt source               destination         
    LOG        all  --  0.0.0.0/0            0.0.0.0/0            limit: avg 3/min burst 5 LOG flags 0 level 4 prefix "[UFW LIMIT BLOCK] "
    REJECT     all  --  0.0.0.0/0            0.0.0.0/0            reject-with icmp-port-unreachable
    
    Chain ufw-user-limit-accept (0 references)
    target     prot opt source               destination         
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           
    
    Chain ufw-user-logging-forward (0 references)
    target     prot opt source               destination         
    
    Chain ufw-user-logging-input (0 references)
    target     prot opt source               destination         
    
    Chain ufw-user-logging-output (0 references)
    target     prot opt source               destination         
    
    Chain ufw-user-output (1 references)
    target     prot opt source               destination         
    ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:1234
    ACCEPT     udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:1234
    Last edited by andrey_; July 4th, 2014 at 12:10 AM.

  6. #6
    Join Date
    Aug 2011
    Beans
    33

    Re: Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

    After further looking into the matter, I found that the only difference between the both sets of iptables (13.10 vs 14.04) is that,
    the non-working one (14.04) has the following extra rules (underlined ):

    Code:
    Chain FORWARD (policy DROP)
    ufw-track-forward  all  --  0.0.0.0/0            0.0.0.0/0 
    
    Chain ufw-before-forward (1 references)
    target     prot opt source               destination
    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0            ctstate RELATED,ESTABLISHED
    
    Chain ufw-track-forward (1 references)
    target     prot opt source               destination  
    


    Also that ctstate is used instead of "state" everywhere, as ctstate is the new standrd.. Any suggestions
    ?

    Last edited by andrey_; July 4th, 2014 at 01:19 AM.

  7. #7
    Join Date
    Jan 2014
    Beans
    Hidden!

    Re: Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

    Quote Originally Posted by andrey_ View Post
    After further looking into the matter, I found that the only difference between the both sets of iptables (13.10 vs 14.04) is that,
    the non-working one (14.04) has the following extra rules (underlined ):
    Are you sure? Look at the very end of the 13.04 firewall. Under the chain ufw-user-output... is that the same?

  8. #8
    Join Date
    Aug 2011
    Beans
    33

    Re: Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

    Thanks, Yes, I've just realized that.. for some reason GUFW is generating "Input" rather than "Output" in iptables rules . I changed that in /lib/ufw/user.rules followed by "sudo service ufw restart" and the firewall works fins again.

    Now the ultimate question : how to solve this issue permanently in GUFW ? I don't want to give up on it to be honest
    Last edited by andrey_; July 4th, 2014 at 01:55 AM.

  9. #9
    Join Date
    Jan 2014
    Beans
    Hidden!

    Re: Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

    Outstanding!!
    As I mentioned earlier, I don't use G/UFW so I don't claim any knowledge. I created a vm to experiment with it and the only way I could see to do it was to create the rule on the INPUT chain and then choose edit and that dialog box did have an option to set direction. Very obtuse way of achieving something. You may want to ask on the GUFW website. They might have some particular workflow in mind when they created it.

    Incidentally, this is an excellent example of why the CLI can be very powerful:

    sudo iptables -I OUTPUT 0 -p tcp --dport 1234 -j ACCEPT

    and another for udp would also do it.

    *edit* that Inserts (-I) into the OUPUT chain at the top (0) a rule to accept tcp/port 1234.
    Last edited by untrustytahr; July 4th, 2014 at 02:09 AM.

  10. #10
    Join Date
    Aug 2011
    Beans
    33

    Re: Ubuntu 14.04: GUFW blocking connections to allowed ports/destinations

    Thanks man, that was a good hint, " edit the rule" --> change the direction to "Output" ... this is sufficient enough for now

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •