problem solved After logging and tracking packets, I figured out the problem. Requests to the ldap deamon were not coming in eth0 but through the loopback. I had to let packets from my external IP to my external IP going either in or out the loopback through ports 389. I did the same thing for ports 25 and 7780 to allow sending emails from web interface and spellchecking with firewall on. |