Pagina 1 di 1

Problema con firewall

Inviato: dom 3 giu 2007, 13:43
da mordecai
Ho installato il firewall cioè iptables,ma se do una regola mi da questo errore!
bash-3.1# installpkg iptables-1.3.5-i486-2.tgz
Installing package iptables-1.3.5-i486-2 ([required])...
PACKAGE DESCRIPTION:
iptables: iptables (IP packet filter administration)
iptables:
iptables: iptables is a packet filter administration tool.
iptables:
iptables: Iptables can be used to build internet firewalls based on stateless
iptables: and stateful packet filtering, use NAT and masquerading for sharing
iptables: internet access if you don't have enough public IP addresses, use NAT
iptables: to implement transparent proxies, aid the tc and iproute2 systems
iptables: used to build sophisticated QoS and policy routers, do further packet
iptables: manipulation (mangling) like altering the TOS/DSCP/ECN bits of the IP
iptables: header, and much more. See: http://www.netfilter.org

bash-3.1# iptables -A OUTPUT -p tcp --dport 80 -j DROP
FATAL: Module ip_tables not found.
iptables v1.3.5: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
Devo ricompilare il kernel secondo voi?

IL kernel che uso è 2.6.14

Inviato: dom 3 giu 2007, 16:49
da Bruffandino
Sembra di si.. però è strano perchè nel kernel di default di slackware il supporto a iptables c'è di sicuro.. stai usando un kernel ricompilato da te?

Inviato: dom 3 giu 2007, 16:56
da albatros
Hai caricato i necessari moduli?

Inviato: dom 3 giu 2007, 19:29
da mordecai
Come ho già detto il kernel in uso è il 2.6.14

Inviato: dom 3 giu 2007, 23:24
da albatros
Ok, ma i moduli per iptables sono caricati?
lsmod che dice?

Inviato: dom 3 giu 2007, 23:35
da mordecai

Codice: Seleziona tutto

bash-3.1$ lsmod
Module                  Size  Used by
snd_seq_dummy           2820  0
snd_seq_oss            34432  0
snd_seq_midi_event      6016  1 snd_seq_oss
snd_seq                50640  5 snd_seq_dummy,snd_seq_oss,snd_seq_midi_event
snd_seq_device          7116  3 snd_seq_dummy,snd_seq_oss,snd_seq
snd_pcm_oss            49440  0
snd_mixer_oss          17088  1 snd_pcm_oss
snd_hda_intel          14784  4
snd_hda_codec          85392  1 snd_hda_intel
snd_pcm                83656  4 snd_pcm_oss,snd_hda_intel,snd_hda_codec
snd_timer              22212  3 snd_seq,snd_pcm
snd_page_alloc          7620  2 snd_hda_intel,snd_pcm
snd                    49668  16 snd_seq_dummy,snd_seq_oss,snd_seq,snd_seq_device,snd_pcm_oss,snd_mixer_oss,snd_hda_intel,snd_hda_codec,snd_pcm,snd_timer
vboxdrv                29128  0
arc4                    1600  2
ieee80211_crypt_wep     4224  1
ipw2200               176708  0
ieee80211              47272  1 ipw2200
ieee80211_crypt         4736  2 ieee80211_crypt_wep,ieee80211
bash-3.1$

Inviato: dom 3 giu 2007, 23:52
da albatros
Non hai caricato i moduli.
Carica quelli che ti occorrono in base al tipo di matching dei pacchetti.
Per avere un'idea:
modprobe -l | grep netfilter
Penso possa anche caricarli tutti...
Se non ne hai nessuno o se continui ad avere problemi devi ricompilare il kernel con il supporto a quello che ti serve.