Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
shorewall&iptables still not working
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
simonski
Tux's lil' helper
Tux's lil' helper


Joined: 15 Jul 2004
Posts: 98

PostPosted: Sun Jul 18, 2004 11:14 am    Post subject: shorewall&iptables still not working Reply with quote

hi i ve discussed this but its till not working
heres a snapshop of my kernel

Code:
 <M> Connection tracking (required for masq/NAT)                                      ? ?
  ? ?                           <M>   FTP protocol support                                                           ? ?
  ? ?                           < >   Amanda protocol support                                                        ? ?
  ? ?                           <M>   TFTP protocol support                                                          ? ?
  ? ?                           <M>   IRC protocol support                                                           ? ?
  ? ?                           < > Userspace queueing via NETLINK (EXPERIMENTAL)                                    ? ?
  ? ?                           <M> IP tables support (required for filtering/masq/NAT)                              ? ?
  ? ?                           <M>   limit match support                                                            ? ?
  ? ?                           <M>   MAC address match support                                                      ? ?
  ? ?                           <M>   Packet type match support                                                      ? ?
  ? ?                           <M>   netfilter MARK match support                                                   ? ?
  ? ?                           <M>   Multiple port match support                                                    ? ?
  ? ?                           <M>   TOS match support                                                              ? ?
  ? ?                           <M>   recent match support                                                           ? ?
  ? ?                           <M>   ECN match support                                                              ? ?
  ? ?                           <M>   DSCP match support                                                             ? ?
  ? ?                           <M>   AH/ESP match support                                                           ? ?
  ? ?                           <M>   LENGTH match support                                                           ? ?
  ? ?                           <M>   TTL match support                                                              ? ?
  ? ?                           <M>   tcpmss match support                                                           ? ?
  ? ?                           <M>   Helper match support                                                           ? ?
  ? ?                           <M>   Connection state match support                                                 ? ?
  ? ?                           <M>   Connection tracking match support                                              ? ?
  ? ?                           < >   Unclean match support (EXPERIMENTAL)                                           ? ?
  ? ?                           < >   Owner match support (EXPERIMENTAL)                                             ? ?
  ? ?                           <M>   Packet filtering                                                               ? ?
  ? ?                           <M>     REJECT target support                                                        ? ?
  ? ?                           < >     MIRROR target support (EXPERIMENTAL)                                         ? ?
  ? ?                           <M>   Full NAT                                                                       ? ?
  ? ?                           <M>     MASQUERADE target support                                                    ? ?
  ? ?                           <M>     REDIRECT target support                                                      ? ?
  ? ?                           [ ]     NAT of local connections (READ HELP)                                         ? ?
  ? ?                           < >     Basic SNMP-ALG support (EXPERIMENTAL)                                        ? ?
  ? ?                           <M>   Packet mangling                                                                ? ?
  ? ?????????????????????????????(+)?????????????????????????????????????????????????????????????????????????<M>     TOS target support                                                           ? ?
  ? ?                           <M>     ECN target support                                                           ? ?
  ? ?                           <M>     DSCP target support                                                          ? ?
  ? ?                           <M>     MARK target support                                                          ? ?
  ? ?                           <M>   LOG target support                                                             ? ?
  ? ?                           <M>   ULOG target support                                                            ? ?
  ? ?                           <M>   TCPMSS target support                                                          ? ?
  ? ?                           <M> ARP tables support                                                               ? ?
  ? ?                           <M>   ARP packet filtering                                                           ? ?
  ? ?                           <M>   ARP payload mangling                                                           ? ?
  ? ?                           < > ipchains (2.2-style) support                                                     ? ?
  ? ?                           < > ipfwadm (2.0-style) support


thats more or less all i can do in the kernel

next thing i tried was to put needed modules in the autoload
but this doesnt work right from start
see
    # Add the names of modules that you'd like to load when the system
    # starts into this file, one per line. Comments begin with # and
    # are ignored. Read man modules.autoload for additional details.

    # For example:
    # 3c59x
    8139too
    ipt_TOS
    ipt_LOG
    ipt_REJECT
    ipt_pkttype
    ipt_state
    ip_nat_irc
    ip_nat_tftp
    ip_nat_ftp
    ip_conntrack_irc
    ip_conntrack_tftp
    ip_conntrack_ftp
    ipt_multiport
    ipt_conntrack
    iptable_filter
    iptable_mangle
    iptable_nat
    ip_conntrack
    ip_tables


lsmod shows this what also is not for beeing happy
    bash-2.05b# lsmod
    Module Size Used by Not tainted
    8139too 13320 1
    bash-2.05b#


what do i have to do, anyone ever had this problem
im using 2.4.24 kernel
thanks
Back to top
View user's profile Send private message
simonski
Tux's lil' helper
Tux's lil' helper


Joined: 15 Jul 2004
Posts: 98

PostPosted: Sun Jul 18, 2004 11:18 am    Post subject: Reply with quote

an this is what shorewall is saying right now

Code:
bash-2.05b# shorewall start
Loading /usr/share/shorewall/functions...
Processing /etc/shorewall/params ...
Processing /etc/shorewall/shorewall.conf...
Starting Shorewall...
Loading Modules...
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_filter.o: unresolved symbol nf_unregister_hook
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_filter.o: unresolved symbol nf_register_hook
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack.o: unresolved symbol nf_unregister_hook
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack.o: unresolved symbol ip_ct_attach
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack.o: unresolved symbol nf_register_hook
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack_ftp.o: unresolved symbol ip_conntrack_helper_register_Rsmp_e53374b3
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack_ftp.o: unresolved symbol ip_conntrack_expect_related_Rsmp_af1f0e92
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack_ftp.o: unresolved symbol ip_conntrack_helper_unregister_Rsmp_fe35c268
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack_tftp.o: unresolved symbol ip_conntrack_helper_register_Rsmp_e53374b3
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack_tftp.o: unresolved symbol ip_conntrack_expect_related_Rsmp_af1f0e92
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack_tftp.o: unresolved symbol ip_conntrack_helper_unregister_Rsmp_fe35c268
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack_irc.o: unresolved symbol ip_conntrack_helper_register_Rsmp_e53374b3
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack_irc.o: unresolved symbol ip_conntrack_expect_related_Rsmp_af1f0e92
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_conntrack_irc.o: unresolved symbol ip_conntrack_helper_unregister_Rsmp_fe35c268
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol ip_ct_find_helper_Rsmp_516e90fd
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol nf_unregister_hook
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol ip_conntrack_alter_reply_Rsmp_0ad2e21a
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol ip_ct_gather_frags_Rsmp_c1c49f61
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol ip_ct_selective_cleanup_Rsmp_f4ec1842
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol ip_conntrack_lock_Rsmp_a0c1f2a7
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol nf_register_hook
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol ip_conntrack_module_Rsmp_b0361033
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol __ip_ct_find_proto_Rsmp_0b9316db
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol ip_conntrack_tuple_taken_Rsmp_092eec27
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol ip_conntrack_htable_size_Rsmp_8ef8af4c
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol ip_conntrack_destroyed_Rsmp_7819af80
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol invert_tuplepr_Rsmp_5e68d8a9
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/iptable_nat.o: unresolved symbol ip_conntrack_get_Rsmp_fd6b0cb7
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_ftp.o: unresolved symbol ip_nat_helper_unregister_Rsmp_e01fd77f
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_ftp.o: unresolved symbol ip_nat_mangle_tcp_packet_Rsmp_22b1e0bd
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_ftp.o: unresolved symbol ip_conntrack_change_expect_Rsmp_bf061a08
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_ftp.o: unresolved symbol ip_ftp_lock_Rsmp_5d3870e1
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_ftp.o: unresolved symbol ip_nat_setup_info_Rsmp_83adca76
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_ftp.o: unresolved symbol ip_nat_helper_register_Rsmp_5a8d7369
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_tftp.o: unresolved symbol ip_nat_helper_unregister_Rsmp_e01fd77f
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_tftp.o: unresolved symbol ip_conntrack_change_expect_Rsmp_bf061a08
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_tftp.o: unresolved symbol ip_nat_setup_info_Rsmp_83adca76
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_tftp.o: unresolved symbol ip_nat_helper_register_Rsmp_5a8d7369
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_irc.o: unresolved symbol ip_nat_helper_unregister_Rsmp_e01fd77f
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_irc.o: unresolved symbol ip_nat_mangle_tcp_packet_Rsmp_22b1e0bd
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_irc.o: unresolved symbol ip_irc_lock
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_irc.o: unresolved symbol ip_conntrack_change_expect_Rsmp_bf061a08
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_irc.o: unresolved symbol ip_nat_setup_info_Rsmp_83adca76
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_nat_irc.o: unresolved symbol ip_nat_helper_register_Rsmp_5a8d7369
Initializing...
Shorewall has detected the following iptables/netfilter capabilities:
   NAT: Not available
   Packet Mangling: Not available
   Multi-port Match: Not available
   Connection Tracking Match: Not available
Determining Zones...
   Zones: net loc
Validating interfaces file...
Validating hosts file...
Validating Policy file...
Determining Hosts in Zones...
   Net Zone: eth0:0.0.0.0/0
   Local Zone: eth1:0.0.0.0/0
Processing /etc/shorewall/init ...
Deleting user chains...
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
Processing /etc/shorewall/stop ...
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.9: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
IP Forwarding Enabled
Processing /etc/shorewall/stopped ...
Terminated


guess there is something wrong in the kernel?!!!!
Back to top
View user's profile Send private message
simonski
Tux's lil' helper
Tux's lil' helper


Joined: 15 Jul 2004
Posts: 98

PostPosted: Sun Jul 18, 2004 11:24 am    Post subject: Reply with quote

if i do modprobe ip_tables
i get this
Code:
bash-2.05b# modprobe ip_tables
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_unregister_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: unresolved symbol nf_register_sockopt
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.24/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed


where is my fault any idea
Back to top
View user's profile Send private message
simonski
Tux's lil' helper
Tux's lil' helper


Joined: 15 Jul 2004
Posts: 98

PostPosted: Sun Jul 18, 2004 7:11 pm    Post subject: Reply with quote

read something about make mrproper solved the problem
but i can t do it can you tell me more
thanks :wink:
Back to top
View user's profile Send private message
simonski
Tux's lil' helper
Tux's lil' helper


Joined: 15 Jul 2004
Posts: 98

PostPosted: Mon Jul 19, 2004 7:12 am    Post subject: Reply with quote

please help :D
Back to top
View user's profile Send private message
richard.scott
Veteran
Veteran


Joined: 19 May 2003
Posts: 1497
Location: Oxfordshire, UK

PostPosted: Wed Dec 08, 2004 4:24 pm    Post subject: Reply with quote

When compiling a kernel that doesn't quite go to plan or you ctrl+C out of it, runing a "make mproper" in the /usr/src/linux directory will remove any part compiled files and also your .config (so be make a backup of your .config file).

also, there is no need to load the required modules at boot time as shorewall will load them for you. Should you need to add/remove and modules required its best to do them from the /etc/shorewall/modules file as that is what its for.

Sometimes when loading modules in the wrong order you get errors like you have described as its looking for something that's not there.

Hope this helps.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum