HELP with why we can not sftp or ssh to our server

We are having an issue when we try to ssh or sftp to our linode server. We flushed the IPTABLES and were able to connect in with no problem. Once I restored the iptables we are no longer able to connect. Following is the iptable we have in place. Can someone please tell me if they see any issues?

ACCEPT udp – anywhere anywhere udp dpt:20 state NEW,ESTABLISHED

ACCEPT udp -- anywhere anywhere udp dpt:fsp state NEW,ESTABLISHED

ACCEPT udp -- anywhere anywhere udp dpt:domain state NEW,ESTABLISHED

ACCEPT tcp -- anywhere anywhere tcp dpt:https state NEW,ESTABLISHED

ACCEPT tcp -- anywhere anywhere tcp dpt:www state NEW,ESTABLISHED

ACCEPT tcp -- anywhere anywhere tcp dpt:ssmtp state NEW,ESTABLISHED

ACCEPT tcp -- anywhere anywhere tcp dpt:smtp state NEW,ESTABLISHED

DROP icmp -- anywhere anywhere limit: avg 15/sec burst 5

REJECT all -- anywhere anywhere reject-with icmp-host-prohibited

Chain FORWARD (policy DROP)

target prot opt source destination

REJECT all -- anywhere anywhere reject-with icmp-host-prohibited

Chain OUTPUT (policy ACCEPT)

target prot opt source destination

ACCEPT udp -- anywhere anywhere udp spt:20 state ESTABLISHED

ACCEPT udp -- anywhere anywhere udp spt:fsp state ESTABLISHED

ACCEPT udp -- anywhere anywhere udp spt:domain state ESTABLISHED

ACCEPT tcp -- anywhere anywhere tcp spt:ssh state ESTABLISHED

ACCEPT tcp -- anywhere anywhere tcp spt:https state ESTABLISHED

ACCEPT tcp -- anywhere anywhere tcp spt:www state ESTABLISHED

ACCEPT tcp -- anywhere anywhere tcp spt:ssmtp state ESTABLISHED

ACCEPT tcp -- anywhere anywhere tcp spt:smtp state ESTABLISHED

ACCEPT tcp -- anywhere anywhere tcp multiport sports tcpmux:63665 state

NEW,ESTABLISHED

ACCEPT icmp -- anywhere anywhere icmp any

Chain fail2ban-ssh (1 references)

target prot opt source destination

RETURN all -- anywhere anywhere

root@www:~#

All was working up till this morning and we have not made any changes.

Thanks

1 Reply

You don't have a rule in the INPUT chain allowing traffic to port 22 (dpt:ssh). You'll need to add one using whatever mechanism you're using to generate firewall rules.

Edit: oops, this was already answered elsewhere.

Reply

Please enter an answer
Tips:

You can mention users to notify them: @username

You can use Markdown to format your question. For more examples see the Markdown Cheatsheet.

> I’m a blockquote.

I’m a blockquote.

[I'm a link] (https://www.google.com)

I'm a link

**I am bold** I am bold

*I am italicized* I am italicized

Community Code of Conduct