<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Web is not accessible from remote computers in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464058#M15128</link>
    <description>&lt;P&gt;Just an add-on:&lt;BR /&gt;
What kind of system do you have? E.g. RedHat currently uses &lt;CODE&gt;firewalld&lt;/CODE&gt; by default - so you won't find any &lt;CODE&gt;iptables&lt;/CODE&gt;-service. Maybe "the guy that have installed [...] this" is not that bad &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2020 09:29:20 GMT</pubDate>
    <dc:creator>rvany</dc:creator>
    <dc:date>2020-02-11T09:29:20Z</dc:date>
    <item>
      <title>Splunk Web is not accessible from remote computers</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464055#M15125</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have Splunk 8.0.1 installed on Ububntu 18.04.4 LTS. I can connect to port 8000 from the same server with any URL (localhost, 127.0.0.1, server name, server IP address). I can see login page if I use SSH tunneling connecting from remote host with redirect to localhost:8000. But I cannot connect from remote host entering any valid URL to browser - connection times out.&lt;/P&gt;

&lt;P&gt;I have no firewall on my server. I have all Splunk services running and all services ports listening. I can see incoming packets with tcpdump - but no replies. I can connect to other services (SSH and Apache, for example) on my server. &lt;/P&gt;

&lt;P&gt;There are no errors in log files - and no events for incoming connections in web_access.log.&lt;/P&gt;

&lt;P&gt;What else have I to check? &lt;/P&gt;

&lt;P&gt;Best regards, &lt;BR /&gt;
Cyril&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 16:12:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464055#M15125</guid>
      <dc:creator>KSluchanko</dc:creator>
      <dc:date>2020-02-09T16:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web is not accessible from remote computers</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464056#M15126</link>
      <description>&lt;P&gt;Allow the traffic in your firewall, e.g. iptables. Keep in mind that tcpdump is in front of iptables, so it will see traffic even if iptables drops it.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 20:53:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464056#M15126</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2020-02-09T20:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web is not accessible from remote computers</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464057#M15127</link>
      <description>&lt;P&gt;Hi Martin,&lt;/P&gt;

&lt;P&gt;There are no any firewall in effect on the server, as I mentioned above. This is not a point.&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
Cyril&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;UPDATE:&lt;/STRONG&gt; Well, I was completely wrong. After some additional investigations I found that negative output of "systemctl status iptables" and "service status iptables" on this server means nothing. Thanks to the guy that have installed and tuned it this way. Resetting default policy to ACCEPT done the thing. Thanks, Martin. &lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 03:49:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464057#M15127</guid>
      <dc:creator>KSluchanko</dc:creator>
      <dc:date>2020-02-10T03:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web is not accessible from remote computers</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464058#M15128</link>
      <description>&lt;P&gt;Just an add-on:&lt;BR /&gt;
What kind of system do you have? E.g. RedHat currently uses &lt;CODE&gt;firewalld&lt;/CODE&gt; by default - so you won't find any &lt;CODE&gt;iptables&lt;/CODE&gt;-service. Maybe "the guy that have installed [...] this" is not that bad &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 09:29:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464058#M15128</guid>
      <dc:creator>rvany</dc:creator>
      <dc:date>2020-02-11T09:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web is not accessible from remote computers</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464059#M15129</link>
      <description>&lt;P&gt;A default policy of accept may be undesirable in most environments.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 09:33:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464059#M15129</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2020-02-11T09:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web is not accessible from remote computers</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464060#M15130</link>
      <description>&lt;P&gt;Look at initial post. It's Ubuntu 18.04, upgraded from 16.04. It uses ufw by default (and, of course, I've checked 'ufw status' output), and I've tried other options like 'firewall-cmd --state'. So I still think that such kind of 'stealth' firewall configuration is not the best way to operate.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 12:19:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464060#M15130</guid>
      <dc:creator>KSluchanko</dc:creator>
      <dc:date>2020-02-11T12:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web is not accessible from remote computers</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464061#M15131</link>
      <description>&lt;P&gt;This server is quick solution for temporary use in isolated environment - so it does not matter much. Then it will be reinstalled.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 12:21:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464061#M15131</guid>
      <dc:creator>KSluchanko</dc:creator>
      <dc:date>2020-02-11T12:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web is not accessible from remote computers</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464062#M15132</link>
      <description>&lt;P&gt;Yes, right, I read that Ubuntu 18.04 - and then immediately forgot it - my bad &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 12:44:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-is-not-accessible-from-remote-computers/m-p/464062#M15132</guid>
      <dc:creator>rvany</dc:creator>
      <dc:date>2020-02-11T12:44:49Z</dc:date>
    </item>
  </channel>
</rss>

