View previous topic :: View next topic |
Author |
Message |
FlyingWafflez n00b
Joined: 27 Dec 2019 Posts: 26
|
Posted: Tue Mar 03, 2020 12:04 am Post subject: Unsure about 'firewalld' required kernel config |
|
|
Hello everyone, I'm trying to get firewalld working on my laptop but I've already broken my install once. Here's a link to my current kernel config: https://pastebin.com/nV0tqX5P The firewalld applet and GUI 'work' but trying to change zone provides no response and "systemctl status firewalld" gives a list of errors about not being able to add chain or rule inets. If anyone could provide some assistance I'd appreciate that.
Output of "systemctl status firewalld"
Code: | ● firewalld.service - firewalld - dynamic firewall daemon
Loaded: loaded (/lib/systemd/system/firewalld.service; enabled; vendor preset: disabled)
Active: active (running) since Mon 2020-03-02 09:45:20 EST; 8h ago
Docs: man:firewalld(1)
Main PID: 1979 (firewalld)
CPU: 941ms
CGroup: /system.slice/firewalld.service
└─1979 /usr/bin/python3.7 /usr/sbin/firewalld --nofork --nopid
Mar 02 09:45:20 thinkpad firewalld[1979]: ERROR: '/sbin/nft add chain inet firewalld raw_PREROUTING { type filter hook prerouting priority -290 ; }' failed: Error: Could>
add chain inet firewalld raw_PREROUTING { type filter hook prerouting priority -290 ; }
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Mar 02 09:45:20 thinkpad firewalld[1979]: ERROR: '/sbin/nft add chain inet firewalld raw_PREROUTING { type filter hook prerouting priority -290 ; }' failed: Error: Could>
add chain inet firewalld raw_PREROUTING { type filter hook prerouting priority -290 ; }
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Mar 02 09:45:20 thinkpad firewalld[1979]: ERROR: COMMAND_FAILED: '/sbin/nft add chain inet firewalld raw_PREROUTING { type filter hook prerouting priority -290 ; }' fail>
add chain inet firewalld raw_PREROUTING { type filter hook prerouting priority -290 ; }
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Mar 02 09:45:56 thinkpad firewalld[1979]: ERROR: '/sbin/nft add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept' failed: Error: Could not p>
add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept
^^^^^^^^^^^^^^
Error: Could not process rule: No such file or directory
add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept
^^^^^^^^^^^^^^
Error: Could not process rule: No such file or directory
add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Mar 02 09:45:56 thinkpad firewalld[1979]: ERROR: '/sbin/nft add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept' failed: Error: Could not p>
add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept
^^^^^^^^^^^^^^
Error: Could not process rule: No such file or directory
add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept
^^^^^^^^^^^^^^
Error: Could not process rule: No such file or directory
add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Mar 02 09:45:56 thinkpad firewalld[1979]: ERROR: COMMAND_FAILED: '/sbin/nft add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept' failed: Er>
add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept
^^^^^^^^^^^^^^
Error: Could not process rule: No such file or directory
add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept
^^^^^^^^^^^^^^
Error: Could not process rule: No such file or directory
add rule inet firewalld filter_IN_home index 4 meta l4proto {icmp, icmpv6} accept
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|
|
|
Back to top |
|
|
Ant P. Watchman
Joined: 18 Apr 2009 Posts: 6920
|
Posted: Tue Mar 03, 2020 12:37 am Post subject: |
|
|
It's probably this:
Code: | # CONFIG_IP6_NF_MATCH_IPV6HEADER is not set |
You should make all the _MATCH targets modules to begin with and let it autoload the ones it needs, or you may get more of these errors. You can remove the rest later. |
|
Back to top |
|
|
FlyingWafflez n00b
Joined: 27 Dec 2019 Posts: 26
|
Posted: Tue Mar 03, 2020 1:40 am Post subject: |
|
|
It to took me two tries, but that seems to have worked!
Thank you! |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|