openSUSE Forums > Archives > Novell Archives » Firewall Kills Samba

Go Back   openSUSE Forums > Archives > Novell Archives
Forums FAQ Members List Search Today's Posts Mark Forums Read


Novell Archives Archived content from Novell openSUSE support forums

 
Page 1 of 2 1 2
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 23-Sep-2005, 14:47
anglers@texs.com
Guest
 
Posts: n/a
Default Firewall Kills Samba

I've spent the past 2 days trying, for the second time, to get my Suse 9.3
Win2K lan to work with the firewall enabled.

Everything works fine with firewall off. Turn it on and NO workgroup
connections.

I've read thousands of threads on this issue so I know it's not just me.
None of the threads seemed to offer resolution of the issue except turn the
firewall off.

Yes ports 137 138 139 443 445 and 631 are open.

I've had good luck with solutions here before.

Anyone care to offer some suggestions?
  #2 (permalink)  
Old 23-Sep-2005, 15:54
R.F. Pels
Guest
 
Posts: n/a
Default Re: Firewall Kills Samba

anglers@texs.com wrote:

> Yes ports 137 138 139 443 445 and 631 are open.


With the firewall on? And from where are you checking this?

Anyway, FWIW, SMB or CIFS or whatever you want to kill it is a security
risk, so, most sensible firewalls close those ports immediately. Unless you
specifically instruct them not to...

--
Ruurd
  #3 (permalink)  
Old 23-Sep-2005, 16:44
anglers@texs.com
Guest
 
Posts: n/a
Default Re: Firewall Kills Samba

> anglers@texs.com wrote:
>
> > Yes ports 137 138 139 443 445 and 631 are open.

>
> With the firewall on? And from where are you checking this?
>
> Anyway, FWIW, SMB or CIFS or whatever you want to kill it is a security
> risk, so, most sensible firewalls close those ports immediately. Unless you
> specifically instruct them not to...
>
> --
> Ruurd


With Firewall on looking in Yast etc/config Editor Network > Firewall >
Susefirewall2

FW_SERVICES_EXT_TCP
FW_SERVICES_EXT_UDP
FW_SERVICES_INT_TCP
FW_SERVICES_INT_UDP


  #4 (permalink)  
Old 24-Sep-2005, 12:00
anglers@texs.com
Guest
 
Posts: n/a
Default Re: Firewall Kills Samba

After much research I've concluded SuseFirewall2 will only function if two
NICs are used, one for the LAN and one outside.

Since this isn't typical or practical in a home or small office real world
I'll have to rely on other firewall solutions, hardware and software.

A huge dissappointment for me as security is the main reason I've moved
from windows to linux. Sigh....

????
  #5 (permalink)  
Old 24-Sep-2005, 12:46
baskitcaise
Guest
 
Posts: n/a
Default Re: Firewall Kills Samba

anglers@texs.com adjusted his/her tinfoil beanie to post:

> After much research I've concluded SuseFirewall2 will only function if
> two NICs are used, one for the LAN and one outside.
>
> Since this isn't typical or practical in a home or small office real
> world I'll have to rely on other firewall solutions, hardware and
> software.
>
> A huge dissappointment for me as security is the main reason I've
> moved
> from windows to linux. Sigh....
>
> ????


Hi Anglers,

Have you tried setting the same interface for internal and external?


--
Mark
Twixt hill and high water
N. Wales, UK
Novell Support Forums SysOp

  #6 (permalink)  
Old 24-Sep-2005, 15:13
Mark Robinson
Guest
 
Posts: n/a
Default Re: Firewall Kills Samba

On Sat, 24 Sep 2005 17:46:51 +0000, baskitcaise wrote:

> anglers@texs.com adjusted his/her tinfoil beanie to post:
>
>> After much research I've concluded SuseFirewall2 will only function if
>> two NICs are used, one for the LAN and one outside.
>>
>> Since this isn't typical or practical in a home or small office real
>> world I'll have to rely on other firewall solutions, hardware and
>> software.
>>
>> A huge dissappointment for me as security is the main reason I've
>> moved
>> from windows to linux. Sigh....
>>
>> ????

>
> Hi Anglers,
>
> Have you tried setting the same interface for internal and external?


Have you tried setting it up by editing
/etc/sysconfig/network/SuSEfirewall2?



--
Mark Robinson
Novell Volunteer SysOp

One by one the penguins steal my sanity...

  #7 (permalink)  
Old 25-Sep-2005, 05:26
Freek
Guest
 
Posts: n/a
Default Re: Firewall Kills Samba

anglers@texs.com wrote:

> After much research I've concluded SuseFirewall2 will only function if two
> NICs are used, one for the LAN and one outside.
>
> Since this isn't typical or practical in a home or small office real world
> I'll have to rely on other firewall solutions, hardware and software.
>
> A huge dissappointment for me as security is the main reason I've moved
> from windows to linux. Sigh....
>
> ????


Did you turn on logging of dropped and may be even accepted packages with
the firewall on. You should find dropped IP packages when Samba does not
work.

Did you set FW_TRUSTED_NETS in SuSEfirewall2?

--
Freek
  #8 (permalink)  
Old 25-Sep-2005, 09:54
baskitcaise
Guest
 
Posts: n/a
Default Re: Firewall Kills Samba

anglers@texs.com adjusted his/her tinfoil beanie to post:

> After much research I've concluded SuseFirewall2 will only function if
> two NICs are used, one for the LAN and one outside.
>


I have setup SuSe with only one nic and have had samba working through
the firewall many a time, IIRC I put the same interface in the internal
and external boxes, you can then open up the local lan for whatever you
want.

However I do have a hardware firewall in my modem/router as well.


--
Mark
Twixt hill and high water
N. Wales, UK
Novell Support Forums SysOp

  #9 (permalink)  
Old 27-Sep-2005, 11:10
anglers@texs.com
Guest
 
Posts: n/a
Default Re: Firewall Kills Samba

Thanks Mark but Yast only seems to allow either assigning my NIC to
external or internal but not both.

Is there some trick to doing that?

  #10 (permalink)  
Old 27-Sep-2005, 11:13
anglers@texs.com
Guest
 
Posts: n/a
Default Re: Firewall Kills Samba

Have you tried setting it up by editing
/etc/sysconfig/network/SuSEfirewall2?

Yes


 
Page 1 of 2 1 2

Bookmarks


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




 

Search Engine Friendly URLs by vBSEO 3.3.0 RC2