fosiul01
asked on
iftop Report analysis
HI,
I have a vps server, i just installed iftop in my server, and when i ran this, i am relay furious and scared aswell.
have a look at the attached picture
according to picture, you can see, too much trafiq is going out side, and i dont use this server as public use, its just for my own play.
before taking this picture, i have blocked every ports in my server except ssh .
sh-3.2# iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
sh-3.2#
but still so much trafiq is going out,
how this is possible ??
what shall i do ??
ftpdislpay.GIF
I have a vps server, i just installed iftop in my server, and when i ran this, i am relay furious and scared aswell.
have a look at the attached picture
according to picture, you can see, too much trafiq is going out side, and i dont use this server as public use, its just for my own play.
before taking this picture, i have blocked every ports in my server except ssh .
sh-3.2# iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
sh-3.2#
but still so much trafiq is going out,
how this is possible ??
what shall i do ??
ftpdislpay.GIF
ASKER
hi,did u mean,restart iptables? Yes
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
ok i have run the script
and i have saved iptables
after that
-bash-3.2# iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT igmp -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
you expecting something like this , is not it ??
and i have saved iptables
after that
-bash-3.2# iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT igmp -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
you expecting something like this , is not it ??
ASKER
check the attached picture
i have stoped httpd, sendmail everything
after that its httpd is there..
iftopdisplay1.GIF
i have stoped httpd, sendmail everything
after that its httpd is there..
iftopdisplay1.GIF
Hi !
I think the connection it's established is why the connection is like that but without traffic, but I'm not sure.
Try to do :
/etc/init.d/networking restart
This will restart all the network and the config. But this is will not reload the firewall that I give you.
Could you give me the result of :
cat /etc/network/if-pre-up.d/i ptables-st art
Thanks
I think the connection it's established is why the connection is like that but without traffic, but I'm not sure.
Try to do :
/etc/init.d/networking restart
This will restart all the network and the config. But this is will not reload the firewall that I give you.
Could you give me the result of :
cat /etc/network/if-pre-up.d/i
Thanks
ASKER
this cat /etc/network/if-pre-up.d/i ptables-st art not a valid path
What do you have in the folder /etc/network/if-pre-up.d/ ?
ASKER
HI, problem was with VPS provider, its nothing wrong with my side, i have blocked every port but still trafiq is going out side, i spoke with them and they said , they will look in to this matter
anyway thanks
anyway thanks
Do you have reload the config after have changed the iptable rules ?
Best Regards