
13th September 2005, 16:57
|
|
Junior Member
|
|
Join Date: Sep 2005
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
Robust firewall rules
Absolutely one of the BEST tools I have found!!
Thanks for all the great work.
Is there a way to set more robust firewall rules with ISPConfig?
For instance, I want to limit access to mysql to only a specific subnet say 198.168.1.224/28 Or allow all traffic from a subnet.
Tom
|

13th September 2005, 17:07
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,911
Thanks: 693
Thanked 4,198 Times in 3,213 Posts
|
|
Quote:
|
Originally Posted by tom@ttucker.com
Absolutely one of the BEST tools I have found!!
Thanks for all the great work.
Is there a way to set more robust firewall rules with ISPConfig?
For instance, I want to limit access to mysql to only a specific subnet say 198.168.1.224/28 Or allow all traffic from a subnet.
Tom
|
You can edit the bastille-firewall config in /etc/Bastille/bastille-firewall.cfg and the master template that ISPConfig uses to generate the config file: /root/ispconfig/isp/conf/bastille-firewall.cfg.master amnually.
If this solution is not flexible enough for you, disable the firewall in ISPConfig and setup another firewall software that is more advanced.
|

13th September 2005, 17:14
|
|
Junior Member
|
|
Join Date: Sep 2005
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
Thanks for the instantaneous response! WOW!
Will edits to /etc/Bastille/bastille-firewall.cfg be overwritten with an upgrade to ISPConfig?
|

13th September 2005, 17:39
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,911
Thanks: 693
Thanked 4,198 Times in 3,213 Posts
|
|
Quote:
|
Originally Posted by tom@ttucker.com
Thanks for the instantaneous response! WOW!
Will edits to /etc/Bastille/bastille-firewall.cfg be overwritten with an upgrade to ISPConfig?
|
If you update the firewall in the web-interface, /etc/Bastille/bastille-firewall.cfg will be overwritten with /root/ispconfig/isp/conf/bastille-firewall.cfg.master
If you upgrade ISPConfig, both files will be overwritten.
|

14th September 2005, 02:59
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,594 Times in 2,445 Posts
|
|
Quote:
|
Originally Posted by till
If you update the firewall in the web-interface, /etc/Bastille/bastille-firewall.cfg will be overwritten with /root/ispconfig/isp/conf/bastille-firewall.cfg.master
|
Therefore you should edit /root/ispconfig/isp/conf/bastille-firewall.cfg.master.
|

10th December 2006, 04:04
|
|
Junior Member
|
|
Join Date: Dec 2006
Posts: 8
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
More on ISPConfig Firewall rules
I have just started with ISPConfig and it seems to run VERY nicely out of the box, but I am having trouble with passive mode ftp.
Behind a router with ports 49152-65534 opened, uncommented the line in ProFTP conf "PassivePorts 49152 65534", but can not find a way to make the firewall accept a port range. Whatever I try I get a message in German saying the port number must be between 0 and 65000.
To make it work, I have to turn the firewall OFF for ftp, but that worries me, even if I am behind the router with NAT.
Any ideas?
|

10th December 2006, 15:24
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,911
Thanks: 693
Thanked 4,198 Times in 3,213 Posts
|
|
You can not open port ranges in the ISPConfig firewall. When your server is behoind a router, you can switch of the ISPConfig firewall.
|

10th December 2006, 18:35
|
|
Junior Member
|
|
Join Date: Dec 2006
Posts: 8
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
port ranges not allowed in ISP Config firewall
that's was I figured, but it might be something for future versions. If I were not behind a router, this would be a real problem for ftp passive mode.
thanks for your attention to these forums. You and Falko are really great.
richard
|

28th December 2006, 14:01
|
|
Member
|
|
Join Date: Dec 2006
Posts: 56
Thanks: 1
Thanked 3 Times in 1 Post
|
|
A better way, , ,
Totally firewall MySQL and then set up a secure tunnel using Putty.
I use this to great effect using putty and MySQL Administrator.
Normally, from a remote connection, MySQL Administrator can not access various functions, like setting user/passwords and permissions as well as setting startup settings but with a putty tunnel, MySQL Administrator is seen as connecting locally, localhost, so not only are all MySQL Administrator functions and features are enabled but you end up with the most secure MySQL server possible.
If anyone wants it, I could add a mini-howto or maybe it should be called a micro-mini-howto as it is only 2 steps.
|

29th December 2006, 16:34
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,594 Times in 2,445 Posts
|
|
Quote:
|
Originally Posted by Craig
If anyone wants it, I could add a mini-howto or maybe it should be called a micro-mini-howto as it is only 2 steps. 
|
That would be great. Maybe you can make it up a little bit, e.g. write a short introduction and something about your motivation so that other people understand easily what this is about.
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +2. The time now is 11:18.
|
|
Recent comments
9 hours 56 min ago
15 hours 1 min ago
19 hours 25 min ago
21 hours 14 min ago
1 day 11 hours ago
1 day 11 hours ago
1 day 16 hours ago
1 day 23 hours ago
1 day 23 hours ago
2 days 1 hour ago