OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [suse-security] Impenetrable firewall - SuSE 9.2

From: Armin Schoech (armin.schoechweb.de)
Date: Thu Jul 13 2006 - 02:45:45 CDT


Hi Keith,

> I cannot seem to get any local browser to access the web server with
> the external (srv.asgard.org.nz) IP address. I have tried external
> port scanners and they seem to see no open ports at all.
>
--> this is a feature of the Firewall and is supposed to work like
this. Try to search the list archives for "protect from internal".
Some people have suggested rules to insert into
/etc/sysconfig/scripts/SuSEfirewall2-custom to make this work. See
also no. 25.) in /etc/sysconfig/SuSEfirewall2

Another solution is split-brain DNS which gives the local clients the
internal IP when they ask for the name of your webserver.

Good luck!
Armin

--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-helpsuse.com
Security-related bug reports go to securitysuse.de, not here