xshell Linux connection failure - non-network Question 2

+++++++++++++++++++++++++++++++++++++++++++

Title: xshell failed connection Linux via ssh - non-network Question 2

Time: June 30, 2019

+++++++++++++++++++++++++++++++++++++++++++

  Recently in learning iptables firewall systems limit expansion module, accidentally execute a command to delete a policy of "iptables -t filter -D INPUT 2" , corresponding to the number 2 strategy "-A INPUT -m state --state RELATED, ESTABLISHED -j ACCEPT ". I found hair re-establish the connection properly when connected to a virtual machine through ssh after then delete this strategy. Phenomenon is blocked in the " Connection established.To Escape to local shell, Press 'Ctrl + Alt +]'. ", You can not log in to the operating system.

  Since you are learning firewalls, troubleshoot the problem first of all whether the firewall rules. Then use the command "service iptables stop" Stop the firewall, this time you can find a normal ssh login operating system. So identify problems must appear on the strategy system firewall. ssh in the firewall policy is "-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT", which is also found that the strategy, there are still a very special strategy "-A INPUT -m state --state RELATED, eSTABLISHED -j ACCEPT ", the meaning of this strategy is to establish a data packet has been linked directly through. Strategies are more than two expansion modules with the state, not on personal guess ssh connection may be related to state module.

  After the discovery of this issue, I would ssh policy modification "-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT", delete the state module. After testing, it was found normal ssh logged.

  I hope this can give you solutions to solve practical problems.

Guess you like

Origin www.cnblogs.com/lv1572407/p/11110911.html