I have CSF installed on some openVZ virtual machines. The problem I have is that some connections to the server are blocked on ports that are allowed :
config :
Code: Select all
TCP_IN = "20,21,22,25,53,80,110,143,443,465,587,993,995,4949"
TCP_OUT = "20,21,22,25,53,80,110,113,443,465,587,3306,4949,11371"
UDP_IN = "20,21,53"
UDP_OUT = "20,21,53,113,123"
Code: Select all
Feb 21 16:23:01 web2 kernel: Firewall: *TCP_IN Blocked* IN=venet0 OUT= MAC= SRC=XXX.XXX.XXX.XXX DST=XXX.XXX.XXX.XXX LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=5788 DF PROTO=TCP SPT=57502 DPT=80 WINDOW=8192 RES=0x00 SYN URGP=0
Feb 21 16:30:14 web2 kernel: Firewall: *TCP_OUT Blocked* IN= OUT=venet0 SRC=XXX.XXX.XXX.XXX DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=37479 DF PROTO=TCP SPT=45258 DPT=25 WINDOW=14600 RES=0x00 SYN URGP=0
Feb 21 16:32:40 web2 kernel: Firewall: *UDP_OUT Blocked* IN= OUT=venet0 SRC=XXX.XXX.XXX.XXX DST=XXX.XXX.XXX.XXX LEN=76 TOS=0x00 PREC=0xC0 TTL=64 ID=0 DF PROTO=UDP SPT=123 DPT=123 LEN=56