Firewall?

MadHag

Verified User
Joined
Aug 26, 2008
Messages
79
Location
French Pyrenees
Err, I am looking for the section that deals with my firewall in DA.

Where is it, I need to open port 53 :confused:

David
 
Debian Etch 4.0

I thought I would be able to find somewhere I could at least open and close ports!

There does'nt seem to be anything for the firewall?
 
MadHag,

DirectAdmin does not include a firewall. Are you on a dedicated server? Are you your own administrator, or do you have managed support? If you're not sure how to do this I recommend you hire someone such as Nobaloney to manage your server and have them set the firewall up.

Alternatively, there is a DA version of the KISS Firewall. You can install it by SSHing into your server and:

Code:
wget -q -O /usr/local/sbin/kiss http://www.oakdns.net/downloads/kiss
chmod 0700 /usr/local/sbin/kiss
echo "/usr/local/sbin/kiss start"  >> /etc/rc.d/rc.local
/usr/local/sbin/kiss start
 
The firewall is up and running, good old Debian, I think even webmin and openpanel are able to manipulate a firewall, maybe they should think about including a feature like that.

Yes it is a dedicated server and yes I am the admin. I don't need to hire anyone I will sort it myself, I was just suprised to see something missing like this.

Thanks for the lead on the KISS firewall, I will look into it. Guess I will head over to the feature requests. :cool:

The problem I have is that a domain is not resolving to my servers ip address.

Zone information
Domain name / Zone: *****.***
Nameserver: ns1.leaseweb.com
ns2.leaseweb.com

Test results in detail

Failures
Test: Server doesn't listen/answer on port 53 for UDP protocol
==> ns1.leaseweb.com./83.149.80.111

Warnings
Test: All addresses should be distinct
==> generic

Successes
Test: At least one nameserver found
==> generic
Test: Delegation response with additional fit in a 512 byte UDP packet
==> generic
Test: No illegal use of dash ('-') in the domain name found
==> generic
Test: Address is not part of a private subnet
==> ns1.leaseweb.com.
==> ns2.leaseweb.com.
Test: Delegation response fit in a 512 byte UDP packet
==> generic
Test: At least two nameservers found
==> generic
Test: No illegal symbols found in domain name
==> generic

nmap is actually showing that the port is open but not allowing dns requests on port 53 which apparently is what that port is for. Now in openpanel which I installed when I first got this server about a week ago and is free and opensource you are able to select ports and permit or deny such requests.

I think this might be the answer to my problem seeing that there is not a interface in DirectAdmin to do it but I need to find out for sure.

SERVER_IP="***.**.**.**"
iptables -A INPUT -p udp -s 0/0 --sport 1024:65535 -d $SERVER_IP --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -p udp -s $SERVER_IP --sport 53 -d 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT
iptables -A INPUT -p udp -s 0/0 --sport 53 -d $SERVER_IP --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -p udp -s $SERVER_IP --sport 53 -d 0/0 --dport 53 -m state --state ESTABLISHED -j ACCEPT

Thanks for your help.

David
 
DirectAdmin is not supposed to be a server administrator control panel. Webmin and DirectAdmin are two different types products. They sometimes do the same things but they cannot really be compared with each other. Like apples and oranges, they are both fruit but still more different than alike.
 
I read the other thread a few minutes ago and recommended Webmin :).

Jeff
 
Back
Top