LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 10-12-2001, 07:44 PM   #1
teddie
LQ Newbie
 
Registered: Oct 2001
Location: Australia
Distribution: Redhat 7.1
Posts: 2

Rep: Reputation: 0
Help! ipchain & iptables not working


Hi guys
Fisrt post and a bit of a newbie so please bear with me.

I've Installed Redhat 7.1 chose 'medium' option for firewall. Setup samba and couldn't connect from win9x boxes but smbclient testing on server was all OK.
ipchains -F command and samba runs fully, well as I want it to :-)

at startup, ipchain -L gives
Chain input (policy ACCEPT):
target prot opt source destination ports
ACCEPT udp ------ BadBoy.AWLAN anywhere domain -> any
ACCEPT all ------ anywhere anywhere n/a
REJECT tcp -y---- anywhere anywhere any -> 0:1023
REJECT tcp -y---- anywhere anywhere any -> nfs
REJECT udp ------ anywhere anywhere any -> 0:1023
REJECT udp ------ anywhere anywhere any -> nfs
REJECT tcp -y---- anywhere anywhere any -> x11:6009
REJECT tcp -y---- anywhere anywhere any -> xfs
Chain forward (policy ACCEPT):
Chain output (policy ACCEPT):

and, iptables -L
/lib/modules/2.4.2-2/kernel/net/ipv4/netfilter/ip_tables.o: init_module:
Device or resource busy
Hint: insmod errors can be caused by incorrect module parameters,
including invalid IO or IRQ parameters
/lib/modules/2.4.2-2/kernel/net/ipv4/netfilter/ip_tables.o: insmod /lib/modules/2.4.2-2/kernel/net/ipv4/netfilter/ip_tables.o failed
/lib/modules/2.4.2-2/kernel/net/ipv4/netfilter/ip_tables.o: insmod ip_tables failed
iptables v1.2.1a: can't initialize iptables `filter': iptables who? (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded

OK so this is now all beyond me, module parameters ?
insmod ?
iptables or kernel upgrade ?
read what I could but it isn't making sense yet :-|

what have I done and how or what do I do to fix it so that I can set-up the firewall and start sharing the modem etc. ?


TIA
teddie
 
Old 10-14-2001, 03:27 PM   #2
adirotaru
Member
 
Registered: Sep 2001
Location: Romania, Timisoara
Distribution: Ubuntu 5.04
Posts: 49

Rep: Reputation: 15
kernel ...

I had that problem once and I upgraded my kernel.

I know that RH 7.1 comes with 2.4.2 kernel if I'm not wrong.
Try a new kernel maybe 2.4.5 or higer.

In 2.4.5 kernel ipchains don't work but iptables is ok and you can setup yuor firewall.


Regards.
 
Old 10-14-2001, 05:02 PM   #3
TimBeR
LQ Newbie
 
Registered: Oct 2001
Distribution: Redhat 7.1
Posts: 11

Rep: Reputation: 0
First of all you do not need to recompile your kernel in redhat 7.1 to use iptables by default on a normal install 7.1 will load ipchains and iptables the only thing is ipchains will over-rule iptables on boot because you can't run them both at the same time

shutdown ipchains by doing chkconfig --level 0123456 ipchains off
service ipchains stop

then do a chkconfig --level 235 iptables on

and reboot your system to remove the ipchains.o module and load the appropriate iptables module

then go here to read and learn about setting up your iptables to meet your needs.
http://www.linuxguruz.org/iptables/

I hope this helps
 
Old 10-14-2001, 05:21 PM   #4
teddie
LQ Newbie
 
Registered: Oct 2001
Location: Australia
Distribution: Redhat 7.1
Posts: 2

Original Poster
Rep: Reputation: 0
thanks

Thanks guys for the response,
from my further reading/searching I think I've got an idea of what's going on...... but It'll have to wait till the weekend for me to try it again....
thanks again

teddie
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to remove an old package 'ipchain' satimis Linux - Security 4 07-28-2004 06:58 AM
To erase Ipchain problem satimis Fedora 0 07-26-2004 12:07 PM
Ipchain ,iptable and ip Masquerading help!! hitesh_linux Linux - General 3 06-10-2003 10:47 AM
Ipchain pbrugada Linux - Software 0 03-12-2003 07:11 PM
Sample Working ipchain that allows http,ftp,ssh for internal and external network munisp Linux - Networking 1 11-09-2001 05:49 PM


All times are GMT -5. The time now is 12:00 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration