Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

impossible to forward port 8080 and 3389 with iptables (ubuntu)

Posted on 2008-06-25
11
Medium Priority
?
1,664 Views
Last Modified: 2013-11-15
Hello :)

I came accross a very (to me) wierd problem ..
somehow, it seem I'm unable to forward port 8080 and 3389, while most of the other ports (I didnt test everything) are working perfectly.

here is how my network look:

[network: 192.168.0.x] > [ubuntubox eth0: 192.168.0.11 eth1: 10.0.0.2] > [router 10.0.0.1]
the router has 10.0.0.2 as DMZ

so far, everything is ok, all computers behind the box have access to internet.
now, when I want to forward some port into my LAN, problems arise:

for exemple, I tried to forward the port 21 to 192.168.0.9, in doing as follow:

sudo iptables -A FORWARD -i eth1 -o eth0 -p tcp --dport 21  -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A PREROUTING -t nat -p tcp -i eth1 --dport 21 -j DNAT --to-destination 192.168.0.9:21

no problem there. but when I'm trying the very same things, with port 8080, to any of my LAN, it wont work. at all. same goes for 3389.
there is no firewall on the server I'm trying to reach inside the lan, and no other service blocking the way.
it just wont connect.
I tried with port 21, 80, 5900, all of those were ok.

if it's any help, here is the extra package I installed on ubuntu: apache, bind, ntop, lynx.
and also, there was some wierd error while booting, something like: ACPI Invalid PBLK Length
but I don't think it's related.

thanks in advance!

edit: I can see however that the timeout on port 8080 and 3389 is longer when I did the forward, than when I remove the entry from iptables
0
Comment
Question by:mistoiic
  • 5
  • 3
  • 3
11 Comments
 
LVL 6

Expert Comment

by:kosmoraios
ID: 21867004
Sounds like your ISP, not IPTables. 8080 is a common proxy port (also old Wingate *shudder*) and 3389 is Remote Desktop Protocol. Both of these are routinely blocked by ISPs, personal firewalls, and other security applications.
0
 
LVL 6

Expert Comment

by:kosmoraios
ID: 21867016
If I would have paid more attention to your question, I would have seen that you are trying to forward to your internal LAN. Sorry. Is there anything internally that may be blocking those ports?
0
 

Author Comment

by:mistoiic
ID: 21867102
not that I'm aware of :)

it seems to be random, some port are ok, while some are not.
some minutes ago, I did try to redirect port 3000 (ntop html report) to another IP,
it worked.

another thing I tried, is to forward vnc (5900) to 192.168.0.6 (worked)
then, I made vnc listen to port 8080, forward that to 192.168.0.6. it failed. but a long timeout
(while local connection are ok)
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 6

Accepted Solution

by:
kosmoraios earned 750 total points
ID: 21867721
If you're using ipchains as well as iptables, check your ipchains configuration to make sure that those ports aren't being blocked. If you're using a template or default configuration file, they might be blocked by default.

The nature of those two ports strongly leads me to believe they are being blocked by something.
0
 
LVL 29

Expert Comment

by:Jan Springer
ID: 21867786
You don't indicate whether the rules are accepted in iptables and whether you have logged the rules to determine whether iptables is the problem or the destination location.
0
 

Author Comment

by:mistoiic
ID: 21868360
I did try 8080 because I needed it,
but I also tried 8081 later, and it did not work, while 26352 was ok. it's a mystery to me :(
I didnt log anything, and the rule is accepted (ie no error) no matter what port I try.

I will try to log the rules forwarding 8080, and report back :)
0
 

Author Comment

by:mistoiic
ID: 21868392
could a broken network interface cause this?
I can change it, at least to eliminate one possibility :)
0
 
LVL 29

Expert Comment

by:Jan Springer
ID: 21868480
are you using this network interface in the rule that doesn't work?
0
 

Author Comment

by:mistoiic
ID: 21869038
I don't know if it's broken .. just a possibility that crossed my mind ;]
0
 
LVL 29

Assisted Solution

by:Jan Springer
Jan Springer earned 750 total points
ID: 21869103
you're too funny.  

can you ping the IP of that NIC?  can you ping the IP at the other end of that NIC?

does a "netstat -i" show errors on that interface?

does "ethtool" show anything interesting?

is that NIC connected to a switch?  do the speeds and duplexes match?
0
 

Author Closing Comment

by:mistoiic
ID: 31473478
after a long battle, I decided to use a more advanced router instead of the linux, which is now working flawlessly. thanks for your help still, and sorry for the delay
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

1. Introduction As many people are interested in Linux but not as many are interested or knowledgeable (enough) to install Linux on their system, here is a safe way to try out Linux on your existing (Windows) system. The idea is that you insta…
It’s 2016. Password authentication should be dead — or at least close to dying. But, unfortunately, it has not traversed Quagga stage yet. Using password authentication is like laundering hotel guest linens with a washboard — it’s Passé.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
Suggested Courses
Course of the Month11 days, 21 hours left to enroll

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question