Infatti la porta 80 è aperta, quindi non sembra essere un problema di firewall.
Ti consiglio di usare il comando
iptables -L -nv
per controllare le regole inserite, così puoi anche controllare il contatore dei pacchetti e vedere se effettivamente la regola è valutata.
Per quanto riguarda la prima regola, sei sicuro di averla scritta bene?
Ti consiglio di usare il comando
iptables -L -nv
per controllare le regole inserite, così puoi anche controllare il contatore dei pacchetti e vedere se effettivamente la regola è valutata.
Per quanto riguarda la prima regola, sei sicuro di averla scritta bene?
mi sembra di averla fatta giusta (ho copiato e incollato)....cmq per essere veramente sicuro ho rifatto tutto
di seguito posto tutto il procedimento:
Codice:
vsx-077:/# /sbin/iptables -F
vsx-077:/# iptables -L -nv
Chain INPUT (policy ACCEPT 3813 packets, 3668K bytes)
pkts bytes target prot opt in out source destination
0 0 fail2ban-ssh tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 3278 packets, 1238K bytes)
pkts bytes target prot opt in out source destination
Chain fail2ban-ssh (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN 0 -- * * 0.0.0.0/0 0.0.0.0/0
vsx-077:/# /sbin/iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables: No chain/target/match by that name
vsx-077:/# iptables -L -nv
Chain INPUT (policy ACCEPT 3813 packets, 3668K bytes)
pkts bytes target prot opt in out source destination
0 0 fail2ban-ssh tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 3278 packets, 1238K bytes)
pkts bytes target prot opt in out source destination
Chain fail2ban-ssh (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN 0 -- * * 0.0.0.0/0 0.0.0.0/0
vsx-077:/# /sbin/iptables -A INPUT -p tcp --dport 22 -j ACCEPT
vsx-077:/# /sbin/iptables -A INPUT -p tcp --dport 80 -j ACCEPT
vsx-077:/# /sbin/iptables -P INPUT DROP
vsx-077:/# /sbin/iptables -P OUTPUT ACCEPT
vsx-077:/# /sbin/iptables -P FORWARD DROP
vsx-077:/# iptables -L -nv
Chain INPUT (policy DROP 2 packets, 126 bytes)
pkts bytes target prot opt in out source destination
0 0 fail2ban-ssh tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
35 2652 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 11 packets, 1244 bytes)
pkts bytes target prot opt in out source destination
Chain fail2ban-ssh (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN 0 -- * * 0.0.0.0/0 0.0.0.0/0
vsx-077:/# iptables -L -nv
Chain INPUT (policy ACCEPT 3813 packets, 3668K bytes)
pkts bytes target prot opt in out source destination
0 0 fail2ban-ssh tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 3278 packets, 1238K bytes)
pkts bytes target prot opt in out source destination
Chain fail2ban-ssh (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN 0 -- * * 0.0.0.0/0 0.0.0.0/0
vsx-077:/# /sbin/iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables: No chain/target/match by that name
vsx-077:/# iptables -L -nv
Chain INPUT (policy ACCEPT 3813 packets, 3668K bytes)
pkts bytes target prot opt in out source destination
0 0 fail2ban-ssh tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 3278 packets, 1238K bytes)
pkts bytes target prot opt in out source destination
Chain fail2ban-ssh (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN 0 -- * * 0.0.0.0/0 0.0.0.0/0
vsx-077:/# /sbin/iptables -A INPUT -p tcp --dport 22 -j ACCEPT
vsx-077:/# /sbin/iptables -A INPUT -p tcp --dport 80 -j ACCEPT
vsx-077:/# /sbin/iptables -P INPUT DROP
vsx-077:/# /sbin/iptables -P OUTPUT ACCEPT
vsx-077:/# /sbin/iptables -P FORWARD DROP
vsx-077:/# iptables -L -nv
Chain INPUT (policy DROP 2 packets, 126 bytes)
pkts bytes target prot opt in out source destination
0 0 fail2ban-ssh tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
35 2652 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 11 packets, 1244 bytes)
pkts bytes target prot opt in out source destination
Chain fail2ban-ssh (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN 0 -- * * 0.0.0.0/0 0.0.0.0/0
P.S. dopo aver fatto iptables -F ho verificato il sito ed era accessibile.....dopo tutto il procedimento è risultato nuovamente inaccessibile




magari questa sera do un'occhiata a come si inserisce una nuova guida poi vi faccio sapere ^_^