3 ms·
Thanks. Would I add these two lines to the rules? Or something different? -A INPUT -i lo -p tcp --dport 3306 -j ACCEPT -A OUTPUT -i lo -p tcp --sport
by ItsWinterHello 13y ago
Thanks. Would I add these two lines to the rules? Or something different?
-A INPUT -i lo -p tcp --dport 3306 -j ACCEPT
-A OUTPUT -i lo -p tcp --sport 3306 -j ACCEPT
- k3oni 13y agoWell in your firewall rules i don't see any OUTPUT drop/reject so the following should be enough on the master if your master is actually listening on lo and port 3306(you can see this running for example(in linux): netstat -tnlp ): -A INPUT -i lo -p tcp --dport 3306 -j ACCEPT
- ItsWinterHello 13y agoYou're the man! Thank you!
- k3oni 13y agoYou're welcome.
- jlgaddis 13y agoI would highly recommend that (on the master) you only accept traffic to 3306/TCP from the slave and not 0/0. -A INPUT -i eth0 -p tcp -s 10.1.1.1/32 --dport 3306 -j ACCEPT Replace 10.1.1.1 with your slave's IP address.
- ItsWinterHello 13y ago@jlgaddis Do I continue to use the rules mentioned in the original post (i.e. generic rules) on the Slave db and just add the rule you suggested to the master? Do I open up port 3306 at all on the slave for the master to speak with the slave? Sorry for my ignorance on this...