Issues with Mandriva 2007, Shorewall, and iptables getting along
I want to thank anyone and exeryone for help ahead of time. I have brought this as far as I can myself, so now I am out here hoping someone can help me get this issue solved.
Here is the low down:
I am running Mandriva 2007 Power Pack on an Athlon XP 2600+ x86. Being on the Atlon I had Shorewall not runable out of the box. It seems the bug it has for the AMD 64's happen with my system eventhough it is 32bit. After an update this problem was solved. Shorewall fired up right off after updating the system. My first install on this system everything worked fine for the most part. I was able to use the app to share my Internet in the Control Center. Hell my second and third installs too. I will get into the reinstalls shortly. For future reference all were completely clean installs.
Shorewall configuration was set up correctly in these instances without an issue and iptables ran them without a hiccup. As I started to configure the rest of my network I would mess them up, even though I was just configuring the hardware at this point I would loose Internet connectivity behind this machine or all together. What seems to have happened each time, iptables stops running. From that point foward it won't either. No matter what I do.
At that point I chaulked it up to Mandriva 2007 Power Pack being buggy as all hell and went back to 2006 Power Pack. I figured it was going to be that easy, nope far fromt it. Mandriva 2006 was worse to deal with so I then wiped it out and went back to 2007. I couldn't even get connection sharing up, because iptables wouldn't run period.
After three more fresh installs of 2007 with iptables not wanting to run what so ever after configuring internet connection sharing to make its shorewall rules, I am at wits end.
This is my fourth install since I tried the down grade. I did use internet connection sharing just so I could use a system behind it for reaserch on what I am trying to set up, gave up, and decided to see if getting setup the rest of the network and hope iptables would cooperate after.
I installed webmin so I can get things done a little quicker on my end. I used it to manually enter my values for Shorewall, it made for quick checks of values to be so simple.
Here is what I am trying to get done on my end. I have this system here which acts as my networks' gateway, firewall, router. Originally it was just for my wired network, but now I wanted to add wifi access point so I can use my new Cingular 8125 Windows Mobile phone on the cable modem and network as opposed to Cingular's much slower mobile Internet and not being able to Activie Sync via the network.
I configured Shorewall according to all the doccumentation for a three card interface and webmin checking my configuration says it checks out. Here is what it gave me as its output:
Checking...
Initializing...
Determining Zones...
IPv4 Zones: net loc wifi
Firewall Zone: fw
Validating interfaces file...
Validating hosts file...
Validating Policy file...
Determining Hosts in Zones...
net Zone: eth0:0.0.0.0/0
loc Zone: eth1:0.0.0.0/0
wifi Zone: ath0:0.0.0.0/0
Pre-processing Actions...
Pre-processing /usr/share/shorewall/action.Drop...
Pre-processing /usr/share/shorewall/action.Reject...
Pre-processing /usr/share/shorewall/action.Limit...
Deleting user chains...
Checking /etc/shorewall/routestopped ...
Checking Accounting...
Creating Interface Chains...
Checking Proxy ARP
Checking NAT...
Checking NETMAP...
Checking Common Rules
Compiling IP Forwarding...
Checking IPSEC...
Checking /etc/shorewall/rules...
Checking /etc/shorewall/tunnels...
Checking Actions...
Checking /usr/share/shorewall/action.Drop for Chain Drop...
Checking /usr/share/shorewall/action.Reject for Chain Reject...
Checking /etc/shorewall/policy...
Checking Masquerading/SNAT
Checking /etc/shorewall/tos...
Checking /etc/shorewall/ecn...
Checking Traffic Control Rules...
Validating /etc/shorewall/tcdevices...
Validating /etc/shorewall/tcclasses...
Checking Rule Activation...
Compiling Refresh of Black List...
Compiling Refresh of /etc/shorewall/ecn...
Validating /etc/shorewall/tcdevices...
Validating /etc/shorewall/tcclasses...
Shorewall configuration verified
.. your firewall configuration looks OK.
I don't understand why iptables is not wanting to start up. When I try to start it up in the Mandriva Control Center, after pressing start there is no output window showing the verbose output, like why it is failing to initialize.
Here is my configuration of the network. I will use my naming conventions so it is easier to reference. It is all based on Red Dwarf Brittish Sci-Fi comedy,so no pokes. My network was and still is so much like thier world so to speak.
Here is a little back story. When I first setup this home network. The original topology consisted of two computers that fit the the personas they were named for and has continued to grow that way.
This system: Holly
A collection of out of date or on its way there hardware grouped together from other systems' upgrades and hand me downs.
It is running two 10/100 ethernet cards both configured and running correctly according to ifconfig and Mandriva GUI.
For wifi I purchased a Belkin wifi pci card, Wireless G ver 5100. Which is fully supported by madwifi.org atheros driver modules. I have tried to get it running in access point mode as well and been having problems. I can get it up and running with a ipv4 address along with its ipv6 even though I don't want that ipv6 address. When I try to set it from managed to master or to anything actually it errors bringing up the interface at boot. I then can manually reconfigure and bring it up myself. Any help on this note too please. I try to set access point mode and get.
[root@mydomain ~]# wlanconfig ath0 create wlandev wifi0 wlanmode ap
wlanconfig: ioctl: Input/output error
This is very frustrating and I am at wits end. Please help me get this working, I am not a noob here and I thought I would have this up and running by now, we are talking going on a week.
Update:
Now for some reason the dhcpd isn't running. I am wondering if that is due to my configuring the three interface rules with shorewall.
All help is appreciated
Last edited by jchance; 11-09-2006 at 06:45 PM.
|