store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Tue May 21, 2013 8:35 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 8 posts ] 
Author Message
 Post subject: ASL firewall stops when updating Plesk firewall
Unread postPosted: Mon Mar 12, 2012 12:00 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Some of our clients like to use the Plesk firewall module. When a change is made via the Plesk firewall module the ASL firewall is stopped and needs to be restarted (service asl-firewall start). Could ASL somehow detect this and restart the ASL firewall automatically?

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: ASL firewall stops when updating Plesk firewall
Unread postPosted: Tue Mar 13, 2012 4:57 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Oh wow, so they delete all your firewall rules, dont save the rules that are installed on the system and then reload them? Thats a pretty awful implementation (iptables-save its one command!).

Hmmm... well, to start with I'd report this as a bug to Parallels. They arent saving the rules that are loaded, which is not good (if anything else changes the rules that will get lost too, like all your geoblocking rules for example). Two, they flush ALL the rules to add new ones? WTF? Why are they flushing the rules? If they are adding rules, don't they know about insert and append?

As for detecting it, we'll think about that. For now though, I'd report this as a serious bug in their GUI. They shouldnt be:
1) flushing all the rules, theres no need to do that, you can add, delect, insert and append using iptables natively
2) they should save the rules that are loaded, and reload them
3) this can create a race condition when you have *no* firewall rules because they are flushing and reloading, instead of delete, append, insert.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: ASL firewall stops when updating Plesk firewall
Unread postPosted: Wed Mar 14, 2012 8:17 am 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 10, 2006 12:55 pm
Posts: 656
mikeshinn wrote:
Parallels. WTF?

'Nuff said.

_________________
"Its not a mac. I run linux... I'm actually cool." - scott


Top
 Profile  
 
 Post subject: Re: ASL firewall stops when updating Plesk firewall
Unread postPosted: Wed Mar 14, 2012 8:54 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
We'll contact Parallels. In the meantime, if ASL could do something about this, that would be appreciated.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: ASL firewall stops when updating Plesk firewall
Unread postPosted: Wed Mar 14, 2012 10:45 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Quote:
In the meantime, if ASL could do something about this, that would be appreciated.


We'll do some research, but this may not be as easy to do as you may think. For example, if the rules are flushed and the sysadmin meant to do that for some reason (maintainence, etc.), this may in fact not look any different from the plesk FW manager just flushing all the rules before it adds one (again, this is pretty strange for them to do, its a race condition at the very least).

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: ASL firewall stops when updating Plesk firewall
Unread postPosted: Wed Mar 14, 2012 11:12 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
If Plesk has no hooks for this, then yeah, I understand this might not be easy.

Maybe ASL can check whether the ASL-* chains are active from time to time after 'service asl-firewall start' and if not run 'service asl-firewall start'?

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: ASL firewall stops when updating Plesk firewall
Unread postPosted: Wed Mar 14, 2012 4:34 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Mar 28, 2009 6:58 pm
Posts: 802
Location: Germany
don't know how Plesk does it and if it helps working that "hacky" way...
but what about the way denying the user that plesk is using for triggering the firewall reconfig to do so.
and instead let asl catch the firewall rules from plesk DB and do the firewall job.?!


Top
 Profile  
 
 Post subject: Re: ASL firewall stops when updating Plesk firewall
Unread postPosted: Wed Mar 14, 2012 4:52 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
We actually want the client to be able to modify whitelisted IP addresses for services via the Plesk firewall module. The problem is that ASL's firewall rules get flushed in the process. (I understand that it's Plesk that's not playing nice.)

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 8 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group