Honeypots mailing list archives

RE: Roo Firewall Problem


From: "Earl Sammons" <esammons () hush com>
Date: Wed, 28 Sep 2005 05:49:22 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Nick/Mike,

Thanks for the feedback and taking time to opening the bug in
bugzilla:
https://bugs.honeynet.org/show_bug.cgi?id=381

Lance and I have been trying with no success to reproduce this
problem.  I've tried the following on an internal "Release
Candidate" version of roo:

ssh in to roo via management interface; remain idle (several times)
Although I experienced the expected idle timeout, the problem did
not occur.

ssh in to roo via management interface; ping -i 10 localhost (to
prevent timeout) for several hours.
The problem did not occur.

Which version of roo are you guys using?
$cat /etc/ROO_BASE_VERSION

Which kernel?
$uname -a

Reaching far here but which NIC are you using for mgmt:
Assuming default of eth2 for mgmt:
$dmesg | grep '^eth2:'

or for any interface:
$dmesg | grep '^eth.:'

Once again, thanks for the feedback.

Earl


On Mon, 26 Sep 2005 12:15:41 -0700 "Michael A. Davis"
<mike () datanerds net> wrote:
Ya, I had the same issue.

Thanks,
Michael A. Davis
Chief Executive Officer
Savid Technologies, Inc.
Main: 708.243.2850
http://www.savidtech.com

This email may contain confidential and privileged information for
the sole
use of the intended recipient. Any review or distribution by
others is
strictly prohibited. If you are not the intended recipient, please
contact
the sender and delete all copies of this message.

-----Original Message-----
From: Nicholas Bachmann [mailto:nickbachmann () gmail com]
Sent: Monday, September 26, 2005 11:41 AM
To: honeypots () securityfocus com
Subject: Roo Firewall Problem

Hi -

Has anybody experienced a problem with the firewall on the
latest Roo randomly blocking all connections to the managment
interface? As soon as I run 'iptables -L', the problem goes
away and I can get in.

Any ideas?

Thanks,
Nick


-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.4

wkYEARECAAYFAkM6k38ACgkQk7+e+4lPSm2kigCfXJ/qcGxnKLU30NGFB/LuP99Fi+kA
oKozPwJBPDQFGXDuQHHOUD3xCeeA
=Y/vh
-----END PGP SIGNATURE-----



Current thread: