Firewall problems after connecting to roundcube

Discussion in 'General' started by dawera66, Dec 26, 2022.

  1. dawera66

    dawera66 New Member

    Hello,
    I setup email a few days ago, without problem. However, upon logging into roundcube and attempting to send an email, I could no longer connect to ispconfig and all sites went offline.

    I have spent a few days troubleshooting, including with firewall. No connections are allowed. I am using Google Cloud.

    I even went through process of reinstalling Apache.

    I then tried to update ispconfig.

    I now cannot even ssh into my instance.

    Has anyone ever had a similar problem?

    If so, what was process to go about resolving?

    I am looking for a simple solution to avoid having to completely start over because I only just now setup ispconfig and made bonehead move of not creating a backup to be able to revert to.

    Any help is greatly appreciated.

    Happy new year.
     
  2. till

    till Super Moderator Staff Member ISPConfig Developer

    Using RoundCube can not cause what you describe here, and also an ISPConfig update does not configure sshd, so it can not cause an interruption of the SSH connection. So whatever caused your issue, it is not what you think is causing it and therefore an ispconfig update or Apache reinstall did not help as both are not related to your problem. I would say the more likely reason is that Google cloud blocked you after you tried to send an email and now they even blocked ssh. Are you still bale to login to the system on the console?
     
  3. dawera66

    dawera66 New Member

    Hi Till,

    Thank you for getting back to me.

    I was thinking the same thing, but am a total newbie to google cloud.

    I cannot ssh into the instance at all.

    I do know that when I was troubleshooting I wound up in iptables and did see an IP listed, so took steps to flush all rules.

    I then attempted to check some logs (although cannot remember exact place) and what I saw was a ton of different IP's that were failing to connect to SMTP. I did a traceroute on the IP's and most were originating from Lithuania.

    Does this sound like I was hacked?

    However, to answer your question, I cannot even login via console.
     
  4. Taleman

    Taleman Well-Known Member HowtoForge Supporter

    Have you checked if your IP is blocked in iptables?
    Is that host running fail2ban?
    No.
     
  5. dawera66

    dawera66 New Member

    Hi Taleman,

    I recall there being a 192 address blocked in iptables. i went through process of removing that. Fail2ban was also running as well.

    I went ahead and setup another vm instance to start from scratch.

    However, I'm now seeing all of the info about being unable to use port 25 with Google cloud, so am setting up an smtp relay.

    If you have any methods for hosting own smtp server without a relay using google cloud, and without using a standalone server, please let me know!
     

Share This Page