View previous topic :: View next topic |
Author |
Message |
juliedeville n00b
data:image/s3,"s3://crabby-images/14c20/14c20699cdf7e07ed6ab9b097e628fa30cacbd62" alt="n00b n00b"
Joined: 14 Oct 2024 Posts: 44
|
Posted: Sun Feb 23, 2025 6:05 pm Post subject: UFW: Missing kernel modules |
|
|
I am trying to setup UFW, and I am getting some errors when I try to enable it. I enabled all of the necessary kernel modules from the wiki pages for iptables and ufw, but still no luck.
Code: | ERROR: problem running ufw-init
Warning: Extension limit revision 0 not supported, missing kernel module?
iptables-restore: line 75 failed
Warning: Extension limit revision 0 not supported, missing kernel module?
iptables-restore: line 55 failed
Problem running '/etc/ufw/before.rules'
Problem running '/etc/ufw/user.rules'
|
|
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
alamahant Advocate
data:image/s3,"s3://crabby-images/0ef21/0ef2195d2dcf511779850b5ca76ca86afef01f52" alt="Advocate Advocate"
Joined: 23 Mar 2019 Posts: 3953
|
Posted: Sun Feb 23, 2025 6:47 pm Post subject: |
|
|
See if you have
Code: |
CONFIG_NFT_LIMIT=m
and
CONFIG_NFT_CONNLIMIT=m
|
in your kernel .config.Apparently you did not enable all of the needed kernel functionality for iptables. _________________
data:image/s3,"s3://crabby-images/c1f96/c1f965372c1efa0ce84272efe08b760f4a91ea94" alt="Smile :)" |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
juliedeville n00b
data:image/s3,"s3://crabby-images/14c20/14c20699cdf7e07ed6ab9b097e628fa30cacbd62" alt="n00b n00b"
Joined: 14 Oct 2024 Posts: 44
|
Posted: Sun Feb 23, 2025 8:10 pm Post subject: |
|
|
Thank you for your reply. Those were not enabled, but enabling them did not fix the issue. Also I meant to specify that only to my knowledge have I enabled all of the modules on the wiki pages, and some were marked as deprecated. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
alamahant Advocate
data:image/s3,"s3://crabby-images/0ef21/0ef2195d2dcf511779850b5ca76ca86afef01f52" alt="Advocate Advocate"
Joined: 23 Mar 2019 Posts: 3953
|
Posted: Sun Feb 23, 2025 8:49 pm Post subject: |
|
|
Quote: |
but enabling them did not fix the issue
|
You should
Code: |
make menuconfig(find the symbols and enable them,then save the file)->make->make modules_install->make install->reboot
|
_________________
data:image/s3,"s3://crabby-images/c1f96/c1f965372c1efa0ce84272efe08b760f4a91ea94" alt="Smile :)" |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
NeddySeagoon Administrator
data:image/s3,"s3://crabby-images/a49a9/a49a9a4fe0fe25e0741dcc999a03bccdab82f66e" alt="Administrator Administrator"
data:image/s3,"s3://crabby-images/d8dd4/d8dd4736dc8f2a6c0a1c8a1fd947722cbc66685b" alt=""
Joined: 05 Jul 2003 Posts: 54921 Location: 56N 3W
|
Posted: Sun Feb 23, 2025 9:03 pm Post subject: |
|
|
juliedeville,
What does show?
Are you running the kernel you think you are?
Code: | $ uname -a
Linux neddy_static 6.13.0-gentoo #1 SMP PREEMPT_DYNAMIC Sat Jan 25 10:37:52 GMT 2025 x86_64 AMD Ryzen 9 5950X 16-Core Processor AuthenticAMD GNU/Linux |
The time and date, Sat Jan 25 10:37:52 GMT 2025 are the build time and date of the running kernel.
Yours should be nowish, if you have just done a kernel update and reboot. Does it look right.? _________________ Regards,
NeddySeagoon
Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
Goverp Advocate
data:image/s3,"s3://crabby-images/0ef21/0ef2195d2dcf511779850b5ca76ca86afef01f52" alt="Advocate Advocate"
data:image/s3,"s3://crabby-images/55f5a/55f5a51472be276a5ef3bf5e345a36e49f1c4c9f" alt=""
Joined: 07 Mar 2007 Posts: 2209
|
Posted: Mon Feb 24, 2025 9:20 am Post subject: |
|
|
I find UFW module requirements a bit of a quagmire. The ebuild has several checks, though I'm not sure they're right. I haven't read the wiki items recently, so I won't comment, but AFAIR remember both those and the ebuild were insufficient. UFW supplies its own checker: Code: | /usr/share/ufw/check-requirements | that might tell a more complete story, though I wouldn't put money on it! _________________ Greybeard |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
|