Getting dropped even when whitelisted

Customer support forums for Atomic Protector (formerly Atomic Secured Linux). There is no such thing as a bad question here as long as it pertains to using Atomic Protector. Newbies feel free to get help getting started or asking questions that may be obvious. Regular users are asked to be gentle. :-)
User avatar
JnascECSI
Forum Regular
Forum Regular
Posts: 306
Joined: Mon Apr 14, 2008 8:29 am
Location: Rhode Island

Getting dropped even when whitelisted

Unread post by JnascECSI »

So not sure why but i have my home IP address whitelisted in ASL, for some reason thou i am getting dropped if i try to get to the ASL GUI. i have flushed and rebooted but still happens. Any idea why it would still happen even after being whitelisted.


Received From: ecs-3->/var/log/messages
Rule: 4151 fired (level 10) -> "Multiple Firewall drop events from same source."
Portion of the log(s):

Code: Select all

May 12 17:08:52 ecs-3 kernel: DROP_ASL_TORTIX IN=em1 OUT= MAC=78:2b:cb:1b:2b:02:00:22:19:1d:fb:94:08:00 SRC=XX.186.XXX.71 DST=10.XXX.XXX.173 LEN=52 TOS=0x00 PREC=0x00 TTL=114 ID=25965 DF PROTO=TCP SPT=13077 DPT=30000 SEQ=4273183466 ACK=0 WINDOW=8192 RES=0x00 SYN URGP=0 OPT (020405B40103030201010402) 
James Nascimento
Chief Information Officer
East Commerce Solutions, Inc.
22 Morris Lane
East Providence, RI 02914
Ph. 800-527-5395 x263
Fax. 888-999-5891
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Getting dropped even when whitelisted

Unread post by mikeshinn »

prupert
Forum Regular
Forum Regular
Posts: 573
Joined: Tue Aug 01, 2006 2:45 pm
Location: Netherlands

Re: Getting dropped even when whitelisted

Unread post by prupert »

It appears that your firewall does not allow your IP address to connect to the ASL web interface (tcp/30000). See https://www.atomicorp.com/wiki/index.ph ... ACL_system

Rather than making the very bold move of enabling FW_WHITELIST (Mike???), which you probably don't want (I certainly wouldn't!), simply make sure that your IP address is allowed to access the ASL web interace. See the above wiki link.

If you do not want to use the "ACL system", which takes care of the firewall configuration for the ASL web interface port, you can add "0.0.0.0/0" to this file and run 'asl -s -f'. Please note that I would not recommended this, as it opens up access to the ASL web interface from all IP addresses. The recommended secure way is to only add your trusted IP address to /etc/asl/firewall/tortixd-access-list.
Lemonbit Internet Dedicated Server Management
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Getting dropped even when whitelisted

Unread post by mikeshinn »

Yes, thats definitely the most secure approach. Some users prefer to allow whitelisted hosts full access to their systems, which is why we've added that option. If that meets your security and usability needs, then feel free to enable it.
Post Reply