(2) Bastille uitdraai, fout voor unreal waar?

Pagina: 1
Acties:

  • shotputty
  • Registratie: Januari 2000
  • Laatst online: 29-09-2025

shotputty

I'll be back

Topicstarter
Ik probeer uit te vissen waarom ik niet kan unrealen van achter deze firewall. Ik heb er niet zoveel verstand van, ziet iemand waar het mis zit?
Dit zijn de instellingen:

# Q: Would you like to run the packet filtering script? [N]
Firewall.ip_intro="Y"
# Q:
Firewall.ip_detail_level_kludge="Y"
# Q: Do you need the advanced networking options?
Firewall.ip_advnetwork="Y"
# Q: DNS servers: [0.0.0.0/0]
Firewall.ip_s_dns="0.0.0.0/0"
# Q: Trusted interface names: [lo]
Firewall.ip_s_trustiface="lo eth1"
# Q: Public interfaces: [eth+ ppp+ slip+]
Firewall.ip_s_publiciface="eth0 ppp+ slip+"
# Q: TCP services to audit: [telnet ftp imap pop-3 finger sunrpc exec login linuxconf ssh]
Firewall.ip_s_tcpaudit="telnet ftp imap pop-3 finger sunrpc exec login linuxconf ssh"
# Q: UDP services to audit: [31337]
Firewall.ip_s_udpaudit="31337"
# Q: TCP service names or port numbers to allow on public interfaces:[ ]
Firewall.ip_s_publictcp="ssh 10000"
# Q: Force passive mode? [N]
Firewall.ip_s_passiveftp="N"
# Q: TCP services to block: [2049 2065:2090 6000:6020 7100]
Firewall.ip_s_tcpblock="2049 2065:2090 6000:6020 7100"
# Q: UDP services to block: [2049 6770]
Firewall.ip_s_udpblock="2049 6770"
# Q: ICMP allowed types: [destination-unreachable echo-reply time-exceeded]
Firewall.ip_s_icmpallowed="destination-unreachable echo-reply time-exceeded"
# Q: Enable source address verification? [Y]
Firewall.ip_s_srcaddr="Y"
# Q: Masqueraded networks: [ ]
Firewall.ip_s_ipmasq="192.168.0.0"
# Q: Kernel modules to masquerade: [ftp raudio vdolive]
Firewall.ip_s_kernelmasq="ftp raudio vdolive cuseeme irc quake user"
# Q: Reject method: [DENY]
Firewall.ip_s_rejectmethod="DENY"
# Q: Interfaces for DHCP queries: [ ]
Firewall.ip_s_dhcpiface="eth0"
# Q: ICMP types to disallow outbound: [destination-unreachable time-exceeded]
Firewall.ip_s_icmpout="destination-unreachable time-exceeded"
# Q: Should Bastille run the firewall and enable it at boot time? [N]
Firewall.ip_enable_firewall="Y"
# Q: Would you like to disable SUID status for mount/umount?
FilePermissions.suidmount="Y"
# Q: Would you like to disable SUID status for ping? [Y]
FilePermissions.suidping="N"
# Q: Would you like to disable SUID status for at? [Y]
FilePermissions.suidat="Y"
# Q: Would you like to disable SUID status for the r-tools? [Y]
FilePermissions.suidrtool="Y"
# Q: Would you like to disable SUID status for usernetctl? [Y]
FilePermissions.suidusernetctl="Y"
# Q: Would you like to disable SUID status for traceroute? [Y]
FilePermissions.suidtrace="Y"
# Q: May we take strong steps to disallow the dangerous r-protocols? [Y]
AccountSecurity.protectrhost="Y"
# Q: Would you like to enforce password aging? [Y]
AccountSecurity.passwdage="N"
# Q: Would you like to restrict the use of cron to administrative accounts? [Y]
AccountSecurity.cronuser="Y"
# Q: Should we allow root to login on tty's 1-6? [Y]
AccountSecurity.rootttylogins="Y"
# Q: Would you like to password-protect the LILO prompt? [N]
BootSecurity.protectlilo="N"
# Q: Would you like to reduce the LILO delay time to zero? [N]
BootSecurity.lilodelay="N"
# Q: Do you ever boot Linux from the hard drive? [Y]
BootSecurity.lilosub_drive="Y"
# Q: Would you like to write the LILO changes to a boot floppy? [N]
BootSecurity.lilosub_floppy="N"
# Q: Would you like to disable CTRL-ALT-DELETE rebooting? [N]
BootSecurity.secureinittab="N"
# Q: Would you like to password protect single-user mode? [Y]
BootSecurity.passsum="N"
# Q: Would you like to set a default-deny on TCP Wrappers and xinetd? [N]
SecureInetd.tcpd_default_deny="Y"
# Q: May we deactivate telnet? [y]
SecureInetd.deactivate_telnet="N"
# Q: May we deactivate ftp? [y]
SecureInetd.deactivate_ftp="Y"
# Q: Would you like to disable the compiler? [N]
DisableUserTools.compiler="N"
# Q: Would you like to put limits on system resource usage? [Y]
ConfigureMiscPAM.limitsconf="Y"
# Q: Should we restrict console access to a small group of user accounts? [N]
ConfigureMiscPAM.consolelogin="N"
# Q: Would you like to add additional logging? [Y]
Logging.morelogging="N"
# Q: Would you like to set up process accounting? [N]
Logging.pacct="N"
# Q: Would you like to deactivate the routing daemons? [Y]
MiscellaneousDaemons.routing="Y"
# Q: Do you want to leave sendmail running in daemon mode? [Y]
Sendmail.sendmaildaemon="Y"
# Q: Would you like to run sendmail via cron to process the queue? [N]
Sendmail.sendmailcron="N"
# Q: Would you like to disable the VRFY and EXPN sendmail commands? [Y]
Sendmail.vrfyexpn="Y"
# Q: Would you like to bind the web server to listen only to the localhost? [N]
Apache.bindapachelocal="N"
# Q: Would you like to bind the web server to a particular interface? [N]
Apache.bindapachenic="N"
# Q: Would you like to deactivate the following of symbolic links? [Y]
Apache.symlink="N"
# Q: Would you like to deactivate server-side includes? [Y]
Apache.ssi="N"
# Q: Would you like to disable CGI scripts, at least for now? [Y]
Apache.cgi="N"
# Q: Would you like to disable indexes? [N]
Apache.apacheindex="N"
# Q: Would you like to disable printing? [N]
Printing.printing="N"
# Q: Would you like to install TMPDIR/TMP scripts? [N]
TMPDIR.tmpdir="N"

Mijn specs; Arm 47cm | Benchpress 175kg | Shotput 16,99m | BW 125kg


  • shotputty
  • Registratie: Januari 2000
  • Laatst online: 29-09-2025

shotputty

I'll be back

Topicstarter
Ik heb even op http://www.planetunreal.com/TheAdminPage/portforwarding.htm
gekeken en daar stond dus dit hieronder. Ik heb alles toegevoegd aan de config file van Bastille in /etc/bastille/config. Het werkt niet.... ;(

If your Gateway is a Linux server... add these in addition to your firewall rules.
#PORTFORWARD FOR UT
ipmasqadm portfw -a -P udp -L EXTERNAL_IP 7777 -R UT_SERVER_IP 7777
ipchains -A forward -p udp -s EXTERNAL_IP 7777 -j MASQ
ipmasqadm portfw -a -P udp -L EXTERNAL_IP 7778 -R UT_SERVER_IP 7778
ipchains -A forward -p udp -s EXTERNAL_IP 7778 -j MASQ
ipmasqadm portfw -a -P udp -L EXTERNAL_IP 7779 -R UT_SERVER_IP 7779
ipchains -A forward -p udp -s EXTERNAL_IP 7779 -j MASQ
#THIS IS THE PORT FOR THE WEB ADMIN PAGE
ipmasqadm portfw -a -P tcp -L EXTERNAL_IP 8888 -R UT_SERVER_IP 8888
ipchains -A forward -p tcp -s EXTERNAL_IP 8888 -j MASQ

Kan iemand mij hier mee helpen? :o

Mijn specs; Arm 47cm | Benchpress 175kg | Shotput 16,99m | BW 125kg


  • IceStorm
  • Registratie: Februari 2000
  • Laatst online: 20:35

IceStorm

This place is GoT-like!!!

Van [forum=19] naar [forum=23] :)

  • Sjonny
  • Registratie: Maart 2001
  • Laatst online: 23:01

Sjonny

Fratser

Op maandag 15 oktober 2001 01:15 schreef shotputty het volgende:
Ik heb even op http://www.planetunreal.com/TheAdminPage/portforwarding.htm
gekeken en daar stond dus dit hieronder. Ik heb alles toegevoegd aan de config file van Bastille in /etc/bastille/config. Het werkt niet.... ;(
dit zijn dus allemaal normale linux commando's. Bastille heeft zijn eigen config files, en uit die yes/no dingen maakt hij zijn eigen linux commando's zodat jij ze niet zelf hoeft te verzinnen ...
mik die regels in een script en voer het uit, en kom dan nog es zeuren als het niet werkt ;)

(en vervang die EXTERNAL_IP en UT_SERVER_IP in echte ip's natuurlijk!)

The problem is in the part of your brain that handles intelligence.


  • imdos
  • Registratie: Maart 2000
  • Laatst online: 05-08 12:09

imdos

I use FreeNAS and Ubuntu

Heb je wel een variabele ingevuld dus UT_SERVER_IP=a.b.c.d
en dan aanroepen met $UT_SERVER_IP en hetzelfde voor $EXTERNAL_IP

pvoutput. Waarom makkelijk doen, als het ook moeilijk kan! Every solution has a new problem


  • blouweKip
  • Registratie: November 1999
  • Laatst online: 10-08 18:05
heb alles toegevoegd aan de config file van Bastille in /etc/bastille/config. Het werkt niet...
Die regels zijn dan ook alleen bedoeld om een ut-server achter je firewall te runnen, UT moet wel gewoon het internet opkunnen zonder dit soor regels

Welke kernel heb je? (2.2/2.4?)

"For my friends, anything; for my enemies, the law."


  • shotputty
  • Registratie: Januari 2000
  • Laatst online: 29-09-2025

shotputty

I'll be back

Topicstarter
Ehh, ik waardeer jullie tips :o en ik begrijp nu dat ik vanalles fout doe. Ik wist niet dat die regels voor een server bedoeld waren. Ik kan zowiezo niet op internet komen met unreal, hij telt wel servers, tot 3000 ofzo maar pingen dat lukt hem niet, die zijn allemaal 9999. En ik kan dus ook geen servers joinen.
Ik had ooit een red hat 6.2 gateway zonder firewall, toen werkte het wel. Misschien moet ik in plaats van die regeltjes toevoegen gewoon wat regels weghalen in bastille. is er iemand die ziet waar het geblokkeeerd wordt? Voordat ik met scripts (?) ga werken...... het vervelende is dat ik de firewall niet kan uitzetten omdat hij gelijk mijn gateway is. ;(

Mijn specs; Arm 47cm | Benchpress 175kg | Shotput 16,99m | BW 125kg

Pagina: 1