Re,
Serveur domestique ? Tu as un serveur ouvert vers l'extérieur hébergé chez toi ?
Oui avec site internet (php apache mysql) et asterisk, le seveur gère la domotique.
mais le serveur ne reboot pas lui , pas a ma connaissance du moins ?
Pour Gufw il ne me demande pas le mot de passe ???? il me répond simplement "Mauvaise identification".
Impossible de faire Edition --> Préférence rien est en surbrillance sauf quitter ?
Visiblement il faut faire :
gksudo firestarter
laurent@PC-ubuntu:~$ sudo iptables -L
[sudo] password for laurent:
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT tcp -- dns1.proxad.net anywhere tcpflags:! FIN,SYN,RST,ACK/SYN
ACCEPT udp -- dns1.proxad.net anywhere
ACCEPT tcp -- dns2.proxad.net anywhere tcpflags:! FIN,SYN,RST,ACK/SYN
ACCEPT udp -- dns2.proxad.net anywhere
ACCEPT all -- anywhere anywhere
ACCEPT icmp -- anywhere anywhere limit: avg 10/sec burst 5
DROP all -- anywhere 255.255.255.255
DROP all -- anywhere 192.168.0.255
DROP all -- base-address.mcast.net/8 anywhere
DROP all -- anywhere base-address.mcast.net/8
DROP all -- 255.255.255.255 anywhere
DROP all -- anywhere 0.0.0.0
DROP all -- anywhere anywhere state INVALID
LSI all -f anywhere anywhere limit: avg 10/min burst 5
INBOUND all -- anywhere anywhere
LOG_FILTER all -- anywhere anywhere
LOG all -- anywhere anywhere LOG level info prefix "Unknown Input"
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere limit: avg 10/sec burst 5
LOG_FILTER all -- anywhere anywhere
LOG all -- anywhere anywhere LOG level info prefix "Unknown Forward"
Chain OUTPUT (policy DROP)
target prot opt source destination
^[[B^[[B^[[BACCEPT tcp -- 192.168.0.4 dns1.proxad.net tcp dpt:domain
ACCEPT udp -- 192.168.0.4 dns1.proxad.net udp dpt:domain
^[[A^[[A^[[AACCEPT tcp -- 192.168.0.4 dns2.proxad.net tcp dpt:domain
ACCEPT udp -- 192.168.0.4 dns2.proxad.net udp dpt:domain
ACCEPT all -- anywhere anywhere
DROP all -- base-address.mcast.net/8 anywhere
DROP all -- anywhere base-address.mcast.net/8
DROP all -- 255.255.255.255 anywhere
DROP all -- anywhere 0.0.0.0
DROP all -- anywhere anywhere state INVALID
OUTBOUND all -- anywhere anywhere
LOG_FILTER all -- anywhere anywhere
LOG all -- anywhere anywhere LOG level info prefix "Unknown Output"
Chain INBOUND (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT udp -- anywhere anywhere state RELATED,ESTABLISHED
LSI all -- anywhere anywhere
Chain LOG_FILTER (5 references)
target prot opt source destination
Chain LSI (2 references)
target prot opt source destination
LOG_FILTER all -- anywhere anywhere
LOG tcp -- anywhere anywhere tcpflags: FIN,SYN,RST,ACK/SYN limit: avg 1/sec burst 5 LOG level info prefix "Inbound "
DROP tcp -- anywhere anywhere tcpflags: FIN,SYN,RST,ACK/SYN
LOG tcp -- anywhere anywhere tcpflags: FIN,SYN,RST,ACK/RST limit: avg 1/sec burst 5 LOG level info prefix "Inbound "
DROP tcp -- anywhere anywhere tcpflags: FIN,SYN,RST,ACK/RST
LOG icmp -- anywhere anywhere icmp echo-request limit: avg 1/sec burst 5 LOG level info prefix "Inbound "
DROP icmp -- anywhere anywhere icmp echo-request
LOG all -- anywhere anywhere limit: avg 5/sec burst 5 LOG level info prefix "Inbound "
DROP all -- anywhere anywhere
Chain LSO (0 references)
target prot opt source destination
LOG_FILTER all -- anywhere anywhere
LOG all -- anywhere anywhere limit: avg 5/sec burst 5 LOG level info prefix "Outbound "
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Chain OUTBOUND (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere
ACCEPT tcp -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT udp -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere
laurent@PC-ubuntu:~$
Pour Gufw j'ai fait :
sudo gufw
il m'a demandé le mot de passe , puis j'ai cliqué sur statue (pour l'activer) en suite j'ai cliqué sur ADD onglet avance et j'ai complété par :
Allow - In - UDP - Depuis 212.27.38.253
Mais impossible de voir la tv par internet avec ma freebox avec Gufw ?
Par contre avec firestarter, j'ai trouvé
Onglet: Politique
Edition de la : Politique du trafic entrant
clique droit dans : Autoriser les connexions de l'hote
Nom d'hote : mafreebox.freebox.fr
La maintenant je suis sécurisé
Merci.