On Sat, 18 Oct 2003 15:10:21 -0400,
Eric Gibson <(E-Mail Removed)> wrote:
>
> Is there anyway around this? It never used to happen with
> ipchains... Whenever I run iptables -F, when I stop my shorewall
> script (or if there is an error in the config file, and it stops
> itself.) it completely locks me out of remote access and I have
> to call up my admin and have him drive 15 miles to the site and
> reboot the machine.
You pay an admin to reboot the machine, I thought the object was to
avoid needing to reboot. The Admin is the one that should be playing
with the firewall anyway.
Well, I don't know firewalls that well, but at a guess, default rules
deny outside requests, so when you flush you aren't allowed in.
Either remove the rules manually, and leave the ones you need, or write
a script (to be run nohup) that flushes the rules and adds the ones
required for you to connect (remember it needs to be on your server.)
I don't know if you can modify the default rules to include what you
need to connect. You could probably change the default to accept all
connections, but then you'd need to completely rewrite your rules,
probably not recommended.
Or you could simply reboot the machine to flush the rules (yes, it's
lame, but it would work.)
Michael C.
--
(E-Mail Removed) http://mcsuper5.freeshell.org/
Registered Linux User #303915
http://counter.li.org/