LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Mandriva
User Name
Password
Mandriva This Forum is for the discussion of Mandriva (Mandrake) Linux.

Notices

Reply
 
LinkBack Search this Thread
Old 11-09-2006, 05:13 PM   #1
jchance
Member
 
Registered: Sep 2003
Location: New Hampshire USA
Distribution: Mandriva 2006 & 2007 Power Pack Club
Posts: 178

Rep: Reputation: 30
Angry Issues with Mandriva 2007, Shorewall, and iptables getting along


I want to thank anyone and exeryone for help ahead of time. I have brought this as far as I can myself, so now I am out here hoping someone can help me get this issue solved.

Here is the low down:

I am running Mandriva 2007 Power Pack on an Athlon XP 2600+ x86. Being on the Atlon I had Shorewall not runable out of the box. It seems the bug it has for the AMD 64's happen with my system eventhough it is 32bit. After an update this problem was solved. Shorewall fired up right off after updating the system. My first install on this system everything worked fine for the most part. I was able to use the app to share my Internet in the Control Center. Hell my second and third installs too. I will get into the reinstalls shortly. For future reference all were completely clean installs.

Shorewall configuration was set up correctly in these instances without an issue and iptables ran them without a hiccup. As I started to configure the rest of my network I would mess them up, even though I was just configuring the hardware at this point I would loose Internet connectivity behind this machine or all together. What seems to have happened each time, iptables stops running. From that point foward it won't either. No matter what I do.

At that point I chaulked it up to Mandriva 2007 Power Pack being buggy as all hell and went back to 2006 Power Pack. I figured it was going to be that easy, nope far fromt it. Mandriva 2006 was worse to deal with so I then wiped it out and went back to 2007. I couldn't even get connection sharing up, because iptables wouldn't run period.

After three more fresh installs of 2007 with iptables not wanting to run what so ever after configuring internet connection sharing to make its shorewall rules, I am at wits end.

This is my fourth install since I tried the down grade. I did use internet connection sharing just so I could use a system behind it for reaserch on what I am trying to set up, gave up, and decided to see if getting setup the rest of the network and hope iptables would cooperate after.

I installed webmin so I can get things done a little quicker on my end. I used it to manually enter my values for Shorewall, it made for quick checks of values to be so simple.

Here is what I am trying to get done on my end. I have this system here which acts as my networks' gateway, firewall, router. Originally it was just for my wired network, but now I wanted to add wifi access point so I can use my new Cingular 8125 Windows Mobile phone on the cable modem and network as opposed to Cingular's much slower mobile Internet and not being able to Activie Sync via the network.

I configured Shorewall according to all the doccumentation for a three card interface and webmin checking my configuration says it checks out. Here is what it gave me as its output:

Checking...
Initializing...
Determining Zones...
IPv4 Zones: net loc wifi
Firewall Zone: fw
Validating interfaces file...
Validating hosts file...
Validating Policy file...
Determining Hosts in Zones...
net Zone: eth0:0.0.0.0/0
loc Zone: eth1:0.0.0.0/0
wifi Zone: ath0:0.0.0.0/0
Pre-processing Actions...
Pre-processing /usr/share/shorewall/action.Drop...
Pre-processing /usr/share/shorewall/action.Reject...
Pre-processing /usr/share/shorewall/action.Limit...
Deleting user chains...
Checking /etc/shorewall/routestopped ...
Checking Accounting...
Creating Interface Chains...
Checking Proxy ARP
Checking NAT...
Checking NETMAP...
Checking Common Rules
Compiling IP Forwarding...
Checking IPSEC...
Checking /etc/shorewall/rules...
Checking /etc/shorewall/tunnels...
Checking Actions...
Checking /usr/share/shorewall/action.Drop for Chain Drop...
Checking /usr/share/shorewall/action.Reject for Chain Reject...
Checking /etc/shorewall/policy...
Checking Masquerading/SNAT
Checking /etc/shorewall/tos...
Checking /etc/shorewall/ecn...
Checking Traffic Control Rules...
Validating /etc/shorewall/tcdevices...
Validating /etc/shorewall/tcclasses...
Checking Rule Activation...
Compiling Refresh of Black List...
Compiling Refresh of /etc/shorewall/ecn...
Validating /etc/shorewall/tcdevices...
Validating /etc/shorewall/tcclasses...
Shorewall configuration verified

.. your firewall configuration looks OK.

I don't understand why iptables is not wanting to start up. When I try to start it up in the Mandriva Control Center, after pressing start there is no output window showing the verbose output, like why it is failing to initialize.

Here is my configuration of the network. I will use my naming conventions so it is easier to reference. It is all based on Red Dwarf Brittish Sci-Fi comedy,so no pokes. My network was and still is so much like thier world so to speak.

Here is a little back story. When I first setup this home network. The original topology consisted of two computers that fit the the personas they were named for and has continued to grow that way.

This system: Holly
A collection of out of date or on its way there hardware grouped together from other systems' upgrades and hand me downs.

It is running two 10/100 ethernet cards both configured and running correctly according to ifconfig and Mandriva GUI.

For wifi I purchased a Belkin wifi pci card, Wireless G ver 5100. Which is fully supported by madwifi.org atheros driver modules. I have tried to get it running in access point mode as well and been having problems. I can get it up and running with a ipv4 address along with its ipv6 even though I don't want that ipv6 address. When I try to set it from managed to master or to anything actually it errors bringing up the interface at boot. I then can manually reconfigure and bring it up myself. Any help on this note too please. I try to set access point mode and get.

[root@mydomain ~]# wlanconfig ath0 create wlandev wifi0 wlanmode ap
wlanconfig: ioctl: Input/output error

This is very frustrating and I am at wits end. Please help me get this working, I am not a noob here and I thought I would have this up and running by now, we are talking going on a week.

Update:

Now for some reason the dhcpd isn't running. I am wondering if that is due to my configuring the three interface rules with shorewall.

All help is appreciated

Last edited by jchance; 11-09-2006 at 06:45 PM.
 
Old 11-09-2006, 09:36 PM   #2
jchance
Member
 
Registered: Sep 2003
Location: New Hampshire USA
Distribution: Mandriva 2006 & 2007 Power Pack Club
Posts: 178

Original Poster
Rep: Reputation: 30
Angry This sucks now mandriva overwrote my shorewall config

I didn't run any networking configuration, or use the internet connection sharing apps. It decided somehow to do it on its own. I am now very, very, upset. I have to figure out why it happened to stop my rules from getting rewritten.
 
Old 11-11-2006, 07:18 PM   #3
jchance
Member
 
Registered: Sep 2003
Location: New Hampshire USA
Distribution: Mandriva 2006 & 2007 Power Pack Club
Posts: 178

Original Poster
Rep: Reputation: 30
Smile

Well I now have The wifi card working as an access point. I recreated my rules useing shorewall configuration through webmin again. I added both my zones behind this machine to dhcpd.conf. The wifi zone works great with the dhcp. Start wifi on the phone, it logs right onto the network and optains an ip address. I can connect to all 3 interfaces of this machine via their ip addresses but not beyond this machine. The wired network is another story.

I know dhcpd is up and running on the wired network as well, but the connection won't come up on the network and obtain an ipaddress. Even if I manually set an interface on this network it is still the same old thing, no connectivity.

Here is my dhcpd.conf:

ddns-update-style none;
subnet 192.168.0.0 netmask 255.255.255.0 {
# default gateway
option routers 192.168.0.1;
option subnet-mask 255.255.255.0;

option domain-name "";
option domain-name-servers 192.168.1.2;
option domain-name-servers 68.87.71.226;
range dynamic-bootp 192.168.0.16 192.168.0.253;
default-lease-time 21600;
max-lease-time 432000;
}
subnet 192.168.1.0 netmask 255.255.255.0 {
# default gateway
option routers 192.168.1.1;
option subnet-mask 255.255.255.0;

option domain-name "";
option domain-name-servers 192.168.1.2;
option domain-name-servers 68.87.71.226;
range dynamic-bootp 192.168.1.16 192.168.1.253;
default-lease-time 21600;
max-lease-time 432000;
}

I don't understand why my wired connection won't have the clients connect and obtain an ip address. I can't even test the connection using a static ip address.

Now I am facing the fact iptables won't start as a service here on this machine. I know my shorewall firewall rules are correct. I quadruple checked them manually and also with webmin's rules checking.

I am sure once i get that iptables issue solved the rest will fall into place.

Please help me out and I will put al of it together and create a Mandriva as a wifi access point guide and multiple interface guide as well. This way no one eles using mandriva will have to go through what I am right now.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Mandriva 2007 is a DUD tytower Mandriva 44 01-18-2007 07:51 AM
Mandriva 2007 Rocks jolphil Mandriva 6 11-04-2006 09:19 PM
Mandriva 2007 and Slackware 11.0 Out! w3bd3vil Mandriva 14 10-06-2006 09:32 AM


All times are GMT -5. The time now is 08:30 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration