Re: ntpd running before iptables causing port 123 not opened on firewall

This is a discussion on Re: ntpd running before iptables causing port 123 not opened on firewall within the Linux Administration forums, part of the Linux Forums category; Hi, It is good practice to load firewall rules before *ANY* network services load, simple reason being is... While yoyr ...


Go Back   Usenet Forums > Linux Forums > Linux Administration

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-26-2003
Yasser Nabi
 
Posts: n/a
Default Re: ntpd running before iptables causing port 123 not opened on firewall

Hi,

It is good practice to load firewall rules before *ANY* network services
load, simple reason being is... While yoyr firewall hasnt loaded then for
that time being (all be it a short time) the services become exposed to
everyone.

So i would suggest that you rename the iptables startup script to
something like S01iptables. Also make it the last thing to die, that way
while services are coming down you will still have protection.

Hope that helps

On Thu, 05 Jun 2003 21:14:42 +0000, Jason wrote:

> On my RH9 machine, ntpd was S58ntpd under rc3.d, and iptables was
> S99iptables under rc3.d. The end result is when ntpd starts up, it
> tries to modify the iptable rules, and could not. Thus kernel would
> log long list of incoming packets to port 123.
>
> If I restart ntpd manually afterwards, then things seemed to be ok.
>
> Fairly limited exposure to linux admin, I would appreciate suggestions
> here. Should I move ntpd to a different level or change the number to
> 99 (thus causing it to start after iptables?). It seemed that other
> daemons (e.g. httpd) are started before iptables. I don't know which
> should be started first, iptables or net app daemons.
>
> thanks.
>
> -jason


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 01:54 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0