[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

IPTABLES - Dont loading some websites

Posted on 2012-08-20
5
Medium Priority
?
812 Views
Last Modified: 2012-08-21
Hey guys,

Could someone point me whats i`m missing to get my NAT working with some websites?
Some o f my rules on Transparent way:

Modules
ip_tables
iptable_filter
iptable_mangle
iptable_nat
ipt_MASQUERADE
ipt_LOG
ipt_REDIRECT

Open in new window


Polices
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT

Open in new window


iptables -t nat -A POSTROUTING -s 192.168.0.0/255.255.255.0 -o ppp0 -j SNAT xxx.xxx.xxx.xxx

Open in new window


echo 1 > /proc/sys/net/ipv4/ip_forward

Open in new window


Yahoo mail work sometimes.....
Paypal dont load (stuck on an infinite load)
Experts-exchange dont load (stuck on an infinite load)

Those are the websites i`m getting problem for now, other websites work fine...

After get the things working ok in transparent NAT, i will move to add rules focusing in security.
Thanks in advice.
0
Comment
Question by:Wisdown
  • 3
  • 2
5 Comments
 
LVL 1

Author Comment

by:Wisdown
ID: 38311945
Checking my /var/log/syslog i see this message:

send_packet: Operation nont permitted

But, if i set to accept all, how something can get blocked without an rule to block?
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 38315121
are you asking for connecting a website with a browser on the mashine you have configured iptables?
if so, iptables rules are most likely not the reason why you can access one site but not another one
keep in mind that iptables -nomen est omen- is based on ip, ports and such while "accessing" a website is application layer
0
 
LVL 1

Author Comment

by:Wisdown
ID: 38315678
I`m asking for the other workstations.
My setup is:

1 VMWare Runing Debian (guest host is windows) as Gateway with one interface eth0 doing SNAT on ppp0

Other 2 desktops in the network runing windows 7, and 5 other VMware debians runing servers (Apache - Mail - Mysql - 2 DNS Servers).

My guess is my setup is doing some loop in some websites.
The sites start lod and never finish the load, after around 3 min i get an error saying the connection cant be made with the server (website)
0
 
LVL 51

Accepted Solution

by:
ahoffmann earned 1000 total points
ID: 38315795
> My guess is my setup is doing some loop in some websites.
this then has nothing todo with iptables

I'm still confused what you want toarchive and where your problem is

If iptables' SNAT is your problem, then it's a general routing problem and not restricted to websites, if a looping website is your problem, then iptables rules most likely do not count

simple check: can you ping the host in question?
0
 
LVL 1

Author Comment

by:Wisdown
ID: 38319030
Yeah i was able to ping the host, but sites get random no load times...

By the way, i give up try set the debian and did an try on pfsense...
Answering the questions of installer using from my previous setup, everything is working now...

Dunno what the setup did, but at least i get this up finally.
Thanks for try help anyway.
0

Featured Post

A Cyber Security RX to Protect Your Organization

Join us on December 13th for a webinar to learn how medical providers can defend against malware with a cyber security "Rx" that supports a healthy technology adoption plan for every healthcare organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Make the most of your online learning experience.
Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question