Bug 713902 - Port is still open even though all services at the system-config-firewall is not checked.
Summary: Port is still open even though all services at the system-config-firewall is ...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: system-config-firewall
Version: 15
Hardware: i686
OS: Linux
unspecified
urgent
Target Milestone: ---
Assignee: Thomas Woerner
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-06-16 18:10 UTC by Arif Tri Waluyo
Modified: 2011-07-12 10:37 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-07-12 10:37:33 UTC
Type: ---


Attachments (Terms of Use)

Description Arif Tri Waluyo 2011-06-16 18:10:19 UTC
Description of problem:
Port 22:ssh
Port 80:http
port 443:https

Version-Release number of selected component (if applicable):
system-config-firewall 1.2.29.3.fc15

How reproducible:
always

Steps to Reproduce:
1.uncheck all service in the system-config-firewall
2.test status port in the GRC ShieldsUP (https://www.grc.com/x/ne.dll?bh0bkyd2)
3.scan common port

Comment 1 Elad Alfassa 2011-06-17 07:20:48 UTC
Is iptables running?



-- 
Fedora Bugzappers volunteer triage team
https://fedoraproject.org/wiki/BugZappers

Comment 2 Thomas Woerner 2011-06-17 10:36:49 UTC
Please add the output of the commands iptables-save and ip6tables save.

Comment 3 Thomas Woerner 2011-06-17 10:38:13 UTC
This should have been iptables-save and ip6tables-save.

Comment 4 Arif Tri Waluyo 2011-06-17 11:47:36 UTC
output #iptables --list
Chain INPUT (policy ACCEPT)
target     prot opt source               destination         
ACCEPT     all  --  anywhere             anywhere            state RELATED,ESTABLISHED 
ACCEPT     icmp --  anywhere             anywhere            
ACCEPT     all  --  anywhere             anywhere            
REJECT     all  --  anywhere             anywhere            reject-with icmp-host-prohibited 

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination         
REJECT     all  --  anywhere             anywhere            reject-with icmp-host-prohibited 

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

Comment 5 Arif Tri Waluyo 2011-06-17 11:48:13 UTC
(In reply to comment #1)
> Is iptables running?
> 
> 
> 
> -- 
> Fedora Bugzappers volunteer triage team
> https://fedoraproject.org/wiki/BugZappers

It's running

Comment 6 Arif Tri Waluyo 2011-06-17 11:51:56 UTC
(In reply to comment #3)
> This should have been iptables-save and ip6tables-save.
# iptables-save
# Generated by iptables-save v1.4.10 on Fri Jun 17 18:50:25 2011
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [5592:719822]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT 
-A INPUT -p icmp -j ACCEPT 
-A INPUT -i lo -j ACCEPT 
-A INPUT -j REJECT --reject-with icmp-host-prohibited 
-A FORWARD -j REJECT --reject-with icmp-host-prohibited 
COMMIT
# Completed on Fri Jun 17 18:50:25 2011



# ip6tables-save
# Generated by ip6tables-save v1.4.10 on Fri Jun 17 18:51:34 2011
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [2:140]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT 
-A INPUT -p ipv6-icmp -j ACCEPT 
-A INPUT -i lo -j ACCEPT 
-A INPUT -j REJECT --reject-with icmp6-adm-prohibited 
-A FORWARD -j REJECT --reject-with icmp6-adm-prohibited 
COMMIT
# Completed on Fri Jun 17 18:51:34 2011

Comment 7 Thomas Woerner 2011-06-17 12:03:17 UTC
Your firewall is configured properly. There are no open ports.

Are you sure that you are testing the firewall of your system and not another one; for example the firewall that protects your LAN?

Comment 8 Arif Tri Waluyo 2011-06-17 12:46:43 UTC
(In reply to comment #7)
> Your firewall is configured properly. There are no open ports.
> 
> Are you sure that you are testing the firewall of your system and not another
> one; for example the firewall that protects your LAN?

Absolutely sure, or you can try by yourself to test status port in the GRC ShieldsUP.

Comment 9 Arif Tri Waluyo 2011-06-17 14:00:32 UTC
You know, before I was just doing the configuration with system-config-firewall and the result is still existing ports are always open, although I do not activate it. but after I run iptables-save and ip6tables-save, and then I check my firewall status, the results are no ports are open.

My problem is solved, but why this is not automatically be done by system-config-firewall?

Comment 10 Thomas Woerner 2011-06-17 15:57:50 UTC
iptables-save and ip6tables-save are not saving anything. The difference to "iptables --list" "ip6tables --list" is that output is different (in a more readable form for me). The output of the -save commands is normally used to save it in a file via output redirection.

Comment 11 Arif Tri Waluyo 2011-06-22 17:25:47 UTC
(In reply to comment #10)
> iptables-save and ip6tables-save are not saving anything. The difference to
> "iptables --list" "ip6tables --list" is that output is different (in a more
> readable form for me). The output of the -save commands is normally used to
> save it in a file via output redirection.

you're right, after I tried several more times the results vary. this is weird.

Comment 12 Thomas Woerner 2011-06-24 16:53:51 UTC
What is varying?

Comment 13 Arif Tri Waluyo 2011-06-24 18:26:33 UTC
(In reply to comment #12)
> What is varying?

firewall test results. sometimes all ports closed, sometimes there are some ports are still open.

Comment 14 Thomas Woerner 2011-06-27 11:57:36 UTC
Are the ports open in the firewall (iptables-save and ip6tablesa-save) output and/or is the tool reporting that these ports are open?

Comment 15 Arif Tri Waluyo 2011-06-27 16:54:10 UTC
(In reply to comment #14)
> Are the ports open in the firewall (iptables-save and ip6tablesa-save) output
> and/or is the tool reporting that these ports are open?

My firewall output, look comment 6.

the results of the tool reporting are vary. sometimes all ports closed, sometimes there are some ports are still open.
here link of reporting tool.
https://www.grc.com/x/ne.dll?bh0bkyd2

Comment 16 Thomas Woerner 2011-06-29 14:49:46 UTC
I am sorry, but this is not a firewall problem. I can not verify GRC ShieldsUP.
Is your machine really connected to the internet directly without using a wireless access point or a router?

Comment 17 Arif Tri Waluyo 2011-06-29 16:02:35 UTC
I use a CDMA modem with an ISP that gives me a public IP.

Comment 18 Arif Tri Waluyo 2011-06-29 16:06:55 UTC
but what if I do a test with the same device and with the Ubuntu operating system, the result is always the same and none of the ports are open?

Comment 19 Arif Tri Waluyo 2011-06-29 16:08:50 UTC
If it's not a firewall problem, why if I do a test with the same device and with the Ubuntu operating system, the result is always the same and none of the ports are open?

Comment 20 Arif Tri Waluyo 2011-07-08 15:50:57 UTC
there is additional info, if I do a test with fedora 15 LiveUSB. The result is always stealth. But if I did after installing it on the computer. Test results are not always the same. And that I did right after fedora installed.

Comment 21 Arif Tri Waluyo 2011-07-12 03:30:53 UTC
After I ask my ISP, it turns out a gap exists in the router / firewall them. Not on my computer. It looks like these bugs can be closed.

Comment 22 Thomas Woerner 2011-07-12 10:37:33 UTC
Closing as not a bug due to comment #21.


Note You need to log in before you can comment on or make changes to this bug.