Koozali.org: home of the SME Server

Dansguardian stop the trafic www

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« on: April 27, 2005, 08:51:46 PM »
Hello,

I have a SME Server 6.0.1, and the system is very stable, I run dansguardian and it work fine, but sometimes the trafic http not work, I cant visit the Webs, but the trafic icmp work fine, I can "ping" to webs and there respond. Only I can restart the system, then all work fine.

Please, anything can help me?

Thansk very much!!

Sorry if the post is repeat, I dont see it.

Offline raem

  • *
  • 3,972
  • +4/-0
Dansguardian stop the trafic www
« Reply #1 on: April 28, 2005, 12:16:36 PM »
Did you follow all the configuration steps in the HOWTO ?
What makes you think Dansguardian is the problem ?
Any error messages ?

If you disable Dansguardian do you still have the problem ?
...

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #2 on: April 29, 2005, 11:25:10 PM »
I follow the steps, I see all log in /var/log and I search or look error but nothing. I try to restart the deamon, "dansguardian, httpd, squid" Nothing to do.

Please help me.

Thanks

Offline raem

  • *
  • 3,972
  • +4/-0
Dansguardian stop the trafic www
« Reply #3 on: April 30, 2005, 04:30:13 AM »
One question at a time then !

What makes you think Dansguardian is the problem ?
...

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #4 on: May 09, 2005, 05:47:09 PM »
I dont konow. I Read all log, and all its ok.

I not that to do.
Please, any idea?

Thanks to all

Offline raem

  • *
  • 3,972
  • +4/-0
Dansguardian stop the trafic www
« Reply #5 on: May 10, 2005, 02:40:44 AM »
If you don't know then I certainly don't know.

Is your DNS server (in server manager review configuration) set to the same IP as your server's local IP  address ?
...

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #6 on: May 10, 2005, 09:05:35 AM »
sorry, I dont understand you, sorry for my english. Please can you repeat.

Thanks

Offline raem

  • *
  • 3,972
  • +4/-0
Dansguardian stop the trafic www
« Reply #7 on: May 10, 2005, 09:27:35 AM »
What is the IP setting for
server manager/review configuration/DNS server ?
eg 192.....

What is your server local IP ?
eg 192.....
...

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #8 on: May 10, 2005, 01:34:25 PM »
The server have two ethernet card:

eth0 - 10.0.0.1 (LAN)
eth1 - 192.168.0.1 (ROUTER)

The router of DSL is 192.168.0.1

This is the question?


-------

Code: [Select]
Parámetros de red
Modo de servidor servergateway
Dirección IP local/máscara de subred 10.0.0.1/255.255.255.0
Dirección IP externa/máscara de subred 192.168.0.100/255.255.255.0
Puerta de enlace 192.168.0.1
Redes locales adicionales 10.0.0.0/255.255.255.0
Servidor DHCP disabled
Nombres del servidor
Servidor DNS 10.0.0.1

Offline raem

  • *
  • 3,972
  • +4/-0
Dansguardian stop the trafic www
« Reply #9 on: May 10, 2005, 02:32:11 PM »
Perhaps yoru configuration is incorrect.
Read the manual carefully
http://mirror.contribs.org/smeserver/contribs/bobk/SME_Manual/chpt-03.2.html
...

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #10 on: May 10, 2005, 02:34:39 PM »
Thanks very much!!

I read now.

Offline grattman

  • ****
  • 122
  • +0/-0
Ongoing problem
« Reply #11 on: May 10, 2005, 05:02:03 PM »
Ray,

I posted previously on this subject. I have the same issue on two seperate SME servers. Anytime I modify anything to do with a user, www traffic ceases. Email works fine though.

I am also assuming it is DandGuardian, because if I restart it, all is good in the world. It worked fine for a couple of months and then all of the sudden developed this problem.

I would love to get to the bottom of this as it is a hassle to restart DG everytime I edit a user in any manner.

Thanks in advance
...

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #12 on: May 10, 2005, 05:41:11 PM »
grattman,

I try to restart the demons one by one but not work.

Just is it a coment.

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #13 on: May 11, 2005, 01:59:42 PM »
I have noticed who when the users of the LAN sail much by Internet the service stops before.  he can be that log fills some or some breaks?

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #14 on: May 26, 2005, 11:34:01 PM »
grattman,

you have been able to fix it? I no.

I have also reviewed the IPTABLES configuration removing a report when the traffic is stopped and when it works and everything is equal.

I believe that also they could be the ports, but rarest she is than without doing nothing the traffic stops Web.

A data is safe, when there is a greater navigation, before cuts the traffic.

Please, This may be crazy, help me!

Thanks

Offline raem

  • *
  • 3,972
  • +4/-0
Re: Ongoing problem
« Reply #15 on: May 27, 2005, 12:55:19 AM »
verti & grattman

Please give some more info to try & eliminate possible issues.

What are your server specs ? memory, cpu, traffic volume (low, high) ?
Are you also running Clamav & Spamassassin ?
Are you using RBL lists ?

With Dansguardian are you using the squidguard rules and did you configure your system to update the rules weekly as per HOWTO ?
Is the location of the blacklists you specified in /etc/cron.weekly/dansguardian still current ?

Did you change the Transparent proxy port in sme server to 8080 ?
What settings do you have in your browser(s) for proxy port, ie auto detect or something specific ?

Have you added any masq/iptables rules to control access to ports 3128, 80 ?

Have you done any additional or extensive configuration of Dansguardian with regard to blocking sites, eg using other lists etc ?
...

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #16 on: May 27, 2005, 01:16:19 AM »
Specs of Server:

IBM xSeries x306
Pentium IV 3Ghz
1GB RAM
80 GB Serial ATA
2 Ethernet GBit

I Running Clamav & Spamassassin
I not use RBL List

I not use rules of squidguard
I not use blacklist

I change the transparent proxy in sme to 8080 with:

Code: [Select]
/sbin/e-smith/db configuration setprop squid TransparentPort 8080
/sbin/e-smith/signal-event post-upgrade
/sbin/e-smith/signal-event reboot


I dont remenber if the rules to control to port 3128,80 is work fine, how to review this?

In the how to say this:

Code: [Select]
$OUT .= " /sbin/iptables --append Forward$AllowLocals -s $local -p tcp --destination-port 80 -j DROP\n";
$OUT .= " /sbin/iptables --append Forward$AllowLocals -d $local -p tcp --destination-port 80 -j DROP\n";
$OUT .= " /sbin/iptables --append Input$AllowLocals -s $local -p tcp --destination-port 80 -j DROP\n";
$OUT .= " /sbin/iptables --append Forward$AllowLocals -s $local -p tcp --destination-port 3128 -j DROP\n";
$OUT .= " /sbin/iptables --append Forward$AllowLocals -d $local -p tcp --destination-port 3128 -j DROP\n";
$OUT .= " /sbin/iptables --append Input$AllowLocals -s $local -p tcp --destination-port 3128 -j DROP\n";


...I dont know

THANKS VERY MUCH!!

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #17 on: May 27, 2005, 01:28:51 AM »
Code: [Select]
Review configuration



Networking Parameters

Server Mode
servergateway

Local IP address / subnet mask
192.168.0.200/255.255.255.0

External IP address / subnet mask
192.168.1.100/255.255.255.0

Gateway
192.168.1.120

Additional local networks
192.168.0.0/255.255.255.0

DHCP server
disabled


Server names

DNS server
192.168.0.200

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #18 on: May 27, 2005, 01:36:32 AM »
but when they spend days lets work, I have noticed that whichever greater are the navigation traffic before is cut.

Thanks

Offline raem

  • *
  • 3,972
  • +4/-0
Dansguardian stop the trafic www
« Reply #19 on: May 27, 2005, 01:57:51 AM »
verti

Your server specs and config details look OK

How many users on your system accessing web sites at any time ?


> I dont remenber if the rules to control to port 3128,80 is work fine, how to review this?

I assume by this comment that you have NOT implemented any additional iptables rules, correct ?


> but when they spend days lets work, I have noticed that whichever greater are the navigation traffic before is cut.

Sorry, I cannot interpret what you are saying here, can anyone else help with the correct meaning ?
...

Offline raem

  • *
  • 3,972
  • +4/-0
Dansguardian stop the trafic www
« Reply #20 on: May 27, 2005, 02:18:47 AM »
You may want to install the System Monitor contrib
e-smith-sysmon-4.0-8.noarch.rpm
& associated rpms
from serts knudsen site
and also use
iptraf
to monitor latency and internet traffic to see if there is any correlation between events when hhtp access fails.
Look in /var/log/messages and other log files also, when/after the http access problem occurs
...

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #21 on: May 27, 2005, 09:16:24 AM »
I dont remember if I implemented a additional iptables rules. This is my iptables config:

Code: [Select]
Chain INPUT (policy DROP)
target prot opt source destination
state_chk all -- anywhere anywhere
local_chk all -- anywhere anywhere
PPPconn all -- anywhere anywhere
DROP all -- BASE-ADDRESS.MCAST.NET/4 anywhere
DROP all -- anywhere BASE-ADDRESS.MCAST.NET/4
InboundICMP icmp -- anywhere anywhere
denylog icmp -- anywhere anywhere
InboundTCP tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN
denylog tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN
InboundUDP udp -- anywhere anywhere
denylog udp -- anywhere anywhere
gre-in gre -- anywhere anywhere
denylog gre -- anywhere anywhere
denylog all -- anywhere anywhere

Chain FORWARD (policy DROP)
target prot opt source destination
state_chk all -- anywhere anywhere
local_chk all -- anywhere anywhere
ForwardedTCP tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN
ForwardedUDP udp -- anywhere anywhere
denylog all -- anywhere anywhere

Chain OUTPUT (policy ACCEPT)
target prot opt source destination
PPPconn all -- anywhere anywhere
DROP all -- BASE-ADDRESS.MCAST.NET/4 anywhere
DROP all -- anywhere BASE-ADDRESS.MCAST.NET/4
OutboundICMP icmp -- anywhere anywhere
denylog icmp -- anywhere anywhere
ACCEPT all -- anywhere anywhere

Chain ForwardedTCP (1 references)
target prot opt source destination
ForwardedTCP_5847 all -- anywhere anywhere
denylog tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN

Chain ForwardedTCP_5847 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere 192.168.0.150 tcp dpt:3380
ACCEPT tcp -- anywhere 192.168.0.150 tcp dpt:3389

Chain ForwardedUDP (1 references)
target prot opt source destination
ForwardedUDP_5847 all -- anywhere anywhere
denylog udp -- anywhere anywhere

Chain ForwardedUDP_5847 (1 references)
target prot opt source destination

Chain InboundICMP (1 references)
target prot opt source destination
InboundICMP_5847 all -- anywhere anywhere
denylog icmp -- anywhere anywhere

Chain InboundICMP_5847 (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere icmp echo-request
ACCEPT icmp -- anywhere anywhere icmp echo-reply
ACCEPT icmp -- anywhere anywhere icmp destination-unreachable
ACCEPT icmp -- anywhere anywhere icmp source-quench
ACCEPT icmp -- anywhere anywhere icmp time-exceeded
ACCEPT icmp -- anywhere anywhere icmp parameter-problem
denylog all -- anywhere anywhere

Chain InboundTCP (1 references)
target prot opt source destination
InboundTCP_5847 all -- anywhere anywhere
denylog tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN

Chain InboundTCP_5847 (1 references)
target prot opt source destination
denylog all -- anywhere !192.168.1.100
ACCEPT tcp -- anywhere anywhere tcp dpt:auth
denylog tcp -- anywhere anywhere tcp dpt:ftp
ACCEPT tcp -- anywhere anywhere tcp dpt:www
ACCEPT tcp -- anywhere anywhere tcp dpt:https
denylog tcp -- anywhere anywhere tcp dpt:imap2
denylog tcp -- anywhere anywhere tcp dpt:imaps
denylog tcp -- anywhere anywhere tcp dpt:ldap
denylog tcp -- anywhere anywhere tcp dpt:pop3
denylog tcp -- anywhere anywhere tcp dpt:pop3s
denylog tcp -- anywhere anywhere tcp dpt:1723
ACCEPT tcp -- anywhere anywhere tcp dpt:smtp
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh
denylog tcp -- anywhere anywhere tcp dpt:ssmtp
denylog tcp -- anywhere anywhere tcp dpt:telnet

Chain InboundUDP (1 references)
target prot opt source destination
InboundUDP_5847 all -- anywhere anywhere
denylog udp -- anywhere anywhere

Chain InboundUDP_5847 (1 references)
target prot opt source destination
denylog all -- anywhere !192.168.1.100

Chain OutboundICMP (1 references)
target prot opt source destination
OutboundICMP_5847 all -- anywhere anywhere
denylog icmp -- anywhere anywhere

Chain OutboundICMP_5847 (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere icmp echo-request
ACCEPT icmp -- anywhere anywhere icmp echo-reply
ACCEPT icmp -- anywhere anywhere icmp destination-unreachable
ACCEPT icmp -- anywhere anywhere icmp source-quench
ACCEPT icmp -- anywhere anywhere icmp time-exceeded
ACCEPT icmp -- anywhere anywhere icmp parameter-problem
denylog all -- anywhere anywhere

Chain PPPconn (2 references)
target prot opt source destination
PPPconn_1 all -- anywhere anywhere

Chain PPPconn_1 (1 references)
target prot opt source destination

Chain denylog (28 references)
target prot opt source destination
DROP udp -- anywhere anywhere udp dpt:route
DROP udp -- anywhere anywhere udp dpts:netbios-ns:netbios-ssn
DROP tcp -- anywhere anywhere tcp dpts:netbios-ns:netbios-ssn
LOG all -- anywhere anywhere LOG level warning prefix denylog:'
DROP all -- anywhere anywhere

Chain gre-in (1 references)
target prot opt source destination
denylog all -- anywhere !192.168.1.100
denylog all -- anywhere anywhere

Chain local_chk (2 references)
target prot opt source destination
local_chk_5847 all -- anywhere anywhere

Chain local_chk_5847 (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- 192.168.0.0/24 anywhere

Chain state_chk (2 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED

NAT
Chain PREROUTING (policy ACCEPT)
target prot opt source destination
PortForwarding all -- anywhere anywhere
SMTPProxy tcp -- anywhere anywhere tcp dpt:smtp
TransProxy tcp -- anywhere anywhere tcp dpt:www

Chain POSTROUTING (policy ACCEPT)
target prot opt source destination
PostroutingOutbound all -- anywhere anywhere

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

Chain PortForwarding (1 references)
target prot opt source destination
PortForwarding_5847 all -- anywhere 192.168.1.100

Chain PortForwarding_5847 (1 references)
target prot opt source destination
DNAT tcp -- anywhere anywhere tcp dpt:3380 to:192.168.0.150:3380
DNAT tcp -- anywhere anywhere tcp dpt:3389 to:192.168.0.150:3389

Chain PostroutingOutbound (1 references)
target prot opt source destination
ACCEPT all -- 192.168.1.100 anywhere
MASQUERADE all -- anywhere anywhere

Chain SMTPProxy (1 references)
target prot opt source destination
ACCEPT all -- anywhere localhost
ACCEPT all -- anywhere www.marianoluna.com
ACCEPT all -- anywhere 192.168.1.100
DNAT tcp -- anywhere anywhere to:192.168.0.200:25

Chain TransProxy (1 references)
target prot opt source destination
ACCEPT all -- anywhere localhost
ACCEPT all -- anywhere www.marianoluna.com
ACCEPT all -- anywhere 192.168.1.100
DNAT tcp -- anywhere anywhere to:192.168.0.200:8080

MANGLE
Chain PREROUTING (policy ACCEPT)
target prot opt source destination

Chain INPUT (policy ACCEPT)
target prot opt source destination

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination
TOS tcp -- anywhere anywhere tcp dpt:ftp TOS set Minimize-Delay
TOS tcp -- anywhere anywhere tcp dpt:ssh TOS set Minimize-Delay
TOS tcp -- anywhere anywhere tcp dpt:telnet TOS set Minimize-Delay
TOS tcp -- anywhere anywhere tcp dpt:smtp TOS set Minimize-Delay
TOS tcp -- anywhere anywhere tcp dpt:www TOS set Minimize-Delay
TOS tcp -- anywhere anywhere tcp dpt:pop3 TOS set Minimize-Delay
TOS tcp -- anywhere anywhere tcp dpt:ftp-data TOS set Maximize-Throughput

Chain POSTROUTING (policy ACCEPT)
target prot opt source destination

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #22 on: May 27, 2005, 09:23:37 AM »
10 users browse the Internet for this server.

I read all login /var/log betwen the 01.16 pm, hour of fail and nothing to do. I dont see anything. All is correct.[/img]

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #23 on: May 27, 2005, 09:27:31 AM »
Quote
> but when they spend days lets work, I have noticed that whichever greater are the navigation traffic before is cut.

Sorry, I cannot interpret what you are saying here, can anyone else help with the correct meaning ?


Sorry for my english, I say:

I have noticed, when there is greater volume of navigation by Internet before fails the http traffic

Thanks

Offline raem

  • *
  • 3,972
  • +4/-0
Dansguardian stop the trafic www
« Reply #24 on: May 27, 2005, 10:07:07 AM »
verti

You are quoting different configuration details. What setup are you using ?

The server have two ethernet card:
eth0 - 10.0.0.1 (LAN)
eth1 - 192.168.0.1 (ROUTER)
The router of DSL is 192.168.0.1
Parámetros de red
Modo de servidor   servergateway
Dirección IP local/máscara de subred   10.0.0.1/255.255.255.0
Dirección IP externa/máscara de subred   192.168.0.100/255.255.255.0
Puerta de enlace   192.168.0.1
Redes locales adicionales   10.0.0.0/255.255.255.0
Servidor DHCP   disabled
Nombres del servidor
Servidor DNS   10.0.0.1


....then later...

Review configuration
Networking Parameters
Server Mode
servergateway
Local IP address / subnet mask
192.168.0.200/255.255.255.0
External IP address / subnet mask
192.168.1.100/255.255.255.0
Gateway
192.168.1.120
Additional local networks
192.168.0.0/255.255.255.0
DHCP server
disabled
Server names
DNS server
192.168.0.200
...

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #25 on: May 27, 2005, 10:11:56 AM »
my present configuration is the second, I change when reinstall all system to fix the problem.


Review configuration
Networking Parameters
Server Mode
servergateway
Local IP address / subnet mask
192.168.0.200/255.255.255.0
External IP address / subnet mask
192.168.1.100/255.255.255.0
Gateway
192.168.1.120
Additional local networks
192.168.0.0/255.255.255.0
DHCP server
disabled
Server names
DNS server
192.168.0.200

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #26 on: May 27, 2005, 10:35:23 AM »
Do you want that I copy a few lines of logs between minutes of fail?

Offline raem

  • *
  • 3,972
  • +4/-0
Dansguardian stop the trafic www
« Reply #27 on: May 27, 2005, 11:22:26 AM »
verti

> servergateway
> External IP address / subnet mask
> 192.168.1.100/255.255.255.0
> Gateway
> 192.168.1.120

In that config why aren't your External & Gateway IP's public IP's (& subnet mask too) as provided by your ISP.
I assume you have a bridged modem using ADSL.
...

Offline verti

  • **
  • 30
  • +0/-0
    • http://www.davidmartinez.org
Dansguardian stop the trafic www
« Reply #28 on: May 27, 2005, 12:30:28 PM »
Yes, my ISP bridged me with modem (192.168.1.120) to internet, this modem is connected directly to eth1 (192.168.1.100).

The modem have a ip static public in the Internet.