Iptables and Shorewall

This forum is for all other ARMv5 devices

Re: Iptables and Shorewall

Postby WarheadsSE » Thu Jun 09, 2011 5:47 pm

Ok, IP4/6?

Remember, they aren't marked by their end module name when I am doing the kernel config...
Core Developer
Remember: Arch Linux ARM is entirely community donation supported!
WarheadsSE
Developer
 
Posts: 6807
Joined: Mon Oct 18, 2010 2:12 pm

Re: Iptables and Shorewall

Postby wlightw » Thu Jun 09, 2011 6:19 pm

It's ipv4.

when I run shorewall now, it says

"Loading Modules...
ERROR: Your kernel/iptables do not include state match support. No version of Shorewall will run on this system
"
wlightw
 
Posts: 15
Joined: Thu May 26, 2011 4:54 am

Re: Iptables and Shorewall

Postby WarheadsSE » Thu Jun 09, 2011 6:39 pm

I think I dug it all up. I am compiling modules now. I will get back to you on which ones pop in.
Core Developer
Remember: Arch Linux ARM is entirely community donation supported!
WarheadsSE
Developer
 
Posts: 6807
Joined: Mon Oct 18, 2010 2:12 pm

Re: Iptables and Shorewall

Postby wlightw » Fri Jun 10, 2011 2:01 am

WarheadsSE: have you got a chance to complete the compiling? looks like there are some other modules missing, like nat. Below are the list of files from kernel version 2.6.38 folder.

$this->bbcode_second_pass_code('', '[root@Arch Linux ARM install netfilter]# ls
arp_tables.ko.gz ipt_addrtype.ko.gz nf_nat_ftp.ko.gz
arpt_mangle.ko.gz ipt_ah.ko.gz nf_nat_h323.ko.gz
arptable_filter.ko.gz ipt_ecn.ko.gz nf_nat_irc.ko.gz
ip_tables.ko iptable_filter.ko.gz nf_nat_pptp.ko.gz
ipt_ECN.ko.gz iptable_mangle.ko.gz nf_nat_proto_dccp.ko.gz
ipt_LOG.ko.gz iptable_nat.ko nf_nat_proto_gre.ko.gz
ipt_MASQUERADE.ko.gz iptable_raw.ko.gz nf_nat_proto_sctp.ko.gz
ipt_NETMAP.ko.gz nf_conntrack_ipv4.ko.gz nf_nat_proto_udplite.ko.gz
ipt_REDIRECT.ko.gz nf_defrag_ipv4.ko.gz nf_nat_sip.ko.gz
ipt_REJECT.ko.gz nf_nat.ko.gz nf_nat_snmp_basic.ko.gz
ipt_ULOG.ko.gz nf_nat_amanda.ko.gz nf_nat_tftp.ko.gz
')
wlightw
 
Posts: 15
Joined: Thu May 26, 2011 4:54 am

Re: Iptables and Shorewall

Postby tux » Fri Jun 10, 2011 7:43 am

Yep that worked. iptables is now running.

However moblock still doesn't work so looking to compile a new kernel. Following DePingus post viewtopic.php?f=16&t=120&start=10

have problems with the compile so post a new topic re it.

Thanks WarheadsSE.
tux
 
Posts: 21
Joined: Wed Jun 08, 2011 9:56 am
Location: Oxford UK

Re: Iptables and Shorewall

Postby wlightw » Mon Jun 13, 2011 12:44 pm

tux: I think current iptable kernel module is not complete. See my previous post from kernel 2.6.38. Some components like "nat" are still missing. I am trying to use shorewall as a firewall on my Pogo, but it won't start due to the missing kernel modules.

WarheadsSE: could you help to compile it again?
wlightw
 
Posts: 15
Joined: Thu May 26, 2011 4:54 am

Re: Iptables and Shorewall

Postby WarheadsSE » Mon Jun 13, 2011 1:12 pm

Yeah,

I believe NAT requires in-kernel changes that can't be simply modified.

Allow me to complete my work on kexecboot, and we'll have this whole problem sorted out, faster then.. well. A hell of a lot faster.
Core Developer
Remember: Arch Linux ARM is entirely community donation supported!
WarheadsSE
Developer
 
Posts: 6807
Joined: Mon Oct 18, 2010 2:12 pm

Re: Iptables and Shorewall

Postby wlightw » Mon Jun 13, 2011 1:39 pm

thanks much! You are a pro!
wlightw
 
Posts: 15
Joined: Thu May 26, 2011 4:54 am

Re: Iptables and Shorewall

Postby tux » Tue Jun 14, 2011 1:49 pm

$this->bbcode_second_pass_quote('wlightw', 't')ux: I think current iptable kernel module is not complete. See my previous post from kernel 2.6.38. Some components like "nat" are still missing. I am trying to use shorewall as a firewall on my Pogo, but it won't start due to the missing kernel modules.


Thanks. I worked out over the weekend that all I need to do to backup my OS is do a cp to another usb stick and because the loader is on the NAND it just works. So hopefully tonight I am going to run through compiling the kernel.

Or are you saying even a compile to a new kernel wont work?
tux
 
Posts: 21
Joined: Wed Jun 08, 2011 9:56 am
Location: Oxford UK

Re: Iptables and Shorewall

Postby WarheadsSE » Tue Jun 14, 2011 5:00 pm

No, it will work.

As for compiling the kernel, try it out with a zImage kernel and kexec, DO NOT just write to nand..
Core Developer
Remember: Arch Linux ARM is entirely community donation supported!
WarheadsSE
Developer
 
Posts: 6807
Joined: Mon Oct 18, 2010 2:12 pm

PreviousNext

Return to Community Supported

Who is online

Users browsing this forum: No registered users and 6 guests