Firewall rules are not pickup from mysql

Dragnell

I have been trying to set up a cluster since monday but unfortunately there is some problem with the firewall script that does not update the rules

Code: Select all

| id | service      | port   | protocol | allowed_ip      | auth |
|  1 | web          | 80:443 | TCP      |       | NULL |
|  4 | mail         | 25     | TCP      |       | NULL |
| 11 | configurator | 4242   | TCP      |       | NULL |
| 12 | ssh          | 22     | TCP      | | NULL |
| 13 | mysql        | 3306   | TCP      | | NULL |

Code: Select all

Chain INPUT (policy DROP)
target     prot opt source               destination         
DROP       tcp  --  anywhere             anywhere             tcp flags:!FIN,SYN,RST,ACK/SYN state NEW
ACCEPT     all  --  anywhere             anywhere           
ACCEPT     all  --  anywhere             anywhere             state RELATED,ESTABLISHED
ACCEPT     icmp --  anywhere             anywhere             icmp echo-request
ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:4242
ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:smtp
ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:submission
ACCEPT     tcp  --  anywhere             anywhere             tcp dpts:http:https
ACCEPT     tcp  --        anywhere             tcp dpt:ssh
ACCEPT     tcp  --  localnet/24          anywhere             tcp dpt:ssh

Chain FORWARD (policy DROP)
target     prot opt source               destination         

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination         

the script is deep into the code , as far as i can see and i have no other way to add rules, or disable the firewall, any idea how to fix this? Thanks
Re: Firewall rules are not pickup from mysql

FlorianB

Hello again,
I made tests with my colleague Mentor yesterday.
We didn't notice any firewall rules problem but it looks like a synchro problem of DB instance (as usual).
Could you try to do a :

Code: Select all

echo "show slave status\G" |/usr/mailcleaner/bin/mc_mysql -s mc_config
And then post the answer here please.
We should find a double Yes row about sync.
I'll post an answer about SSL ports and SSL enable or not problem in the corresponding thread but we noticed no problem about that except the fast that no notification appear asking to restart the firewall service for these changes and it is necessary !
Mentor corrected some things to make this notification appears so if you use the final version or the Updater for the beta version, you should already notice that on change of these values.
MailCleaner Team

