LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > antiX / MX Linux
User Name
Password
antiX / MX Linux This forum is for the discussion of antiX and MX Linux.

Notices


Reply
  Search this Thread
Old 10-30-2019, 02:54 AM   #1
walker
Member
 
Registered: Nov 2003
Distribution: antiX-17.4.1_x64 base Custom
Posts: 193

Rep: Reputation: 38
[SOLVED] UFW doesn't work - antiX-19


To say the plain truth it's not an antiX nor UFW related problem as I discovered.

UFW is wrritten around iptables, libip4tc0, libip6tc0, libiptc0, libxtables12 version 1.6.

Following no longer tested Debian fake stable Buster, antiX uses version 1.8 of aforementioned libraries which have broken retrocompatibility with their 1.6 version.

To have ufw working also on antiX-19 despite the installed kernel using a 17,4,1 live and grab

$ apt-get download iptables

and in the same way the other aforementioned needed libraries and save them on your antiX-19 installation.

Start antiX-19 and install downgrading from the installed 1.8 using dpkg -i the previous downloaded packages and set them to hold

# apt-mark hold iptables libip4tc0 aso

install or reinstall UFW and you are done.

Debian seems no longer well done and well tested as in the past better always check and don't trust too much in them. IMHO
 
Old 10-30-2019, 12:38 PM   #2
anticapitalista
antiX
 
Registered: May 2005
Location: Greece
Distribution: antiX using herbstluftwm, fluxbox, IceWM and jwm.
Posts: 631

Rep: Reputation: 190Reputation: 190
Thanks.
Just to add.
Others have reported to use a later kernel (eg 4.19) on antiX-19 than the one shipped (4.9).
 
Old 10-30-2019, 01:38 PM   #3
walker
Member
 
Registered: Nov 2003
Distribution: antiX-17.4.1_x64 base Custom
Posts: 193

Original Poster
Rep: Reputation: 38
Quote:
Originally Posted by anticapitalista View Post
Thanks.
Just to add.
Others have reported to use a later kernel (eg 4.19) on antiX-19 than the one shipped (4.9).
You are welcome!
And anyway I have to thank you for antiX.

The problem isn't kernel related, I've tried with 4.9.160 4.9.170 4.9.193 4.19.73 5.2.15

I've found also the evidence, a complete change in iptables 1.8
https://lwn.net/Articles/759184/

The weird thing is that with 4 kernel you are neither able to reach the net with 5 kernel (as also reported on your own forum by a user - sorry but due to captcha it impossible to me to create an user) net is reachable but ufw won't anyway run properly due to iptables issue.

Btw. We heard us some years ago per email but your old opera mail seems no longer active.

Have a nice evening!

Last edited by walker; 10-30-2019 at 02:53 PM.
 
Old 11-11-2019, 02:24 AM   #4
walker
Member
 
Registered: Nov 2003
Distribution: antiX-17.4.1_x64 base Custom
Posts: 193

Original Poster
Rep: Reputation: 38
Final solution which avoid the need of the suggested workaround.

Upgrade kernel 4.9.193-antix1 shipped with the iso images of antiX 19 with kernel 4.19.73-antix1

It's due to ufw developer statement that modules have to be compiled in kernel (built-in) to make ufw working with iptables >= 1.8

Kernel 4.9.193-antix1 has af_packet (the mandatory module) but also loading it at boot before launching ufw doesn't work (bad code portability example IMHO).

Kernel 4.19.73-antix1 has af_packet compiled in kernel (built-in) so no troubles to make ufw working also with iptables >= 1.8

I tried also some 5 kernels especially 5.2.8-antix1 and 5.2.15-antix1

ufw doesn't work but in these cases due to lack of IPv6 stack in kernel it seems.

Who want to use ufw with antiX 19 should use the aforementioned kernel 4.19.73-antix1

The end

Last edited by walker; 11-11-2019 at 02:26 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] antiX 17.3.1 problem enabling ufw firewall RHTopics antiX / MX Linux 11 01-05-2019 06:07 PM
[not solved] UFW IP leak and allowing LAN connections IN/OUT postcd Linux - Networking 2 03-08-2018 06:53 AM
[SOLVED] Conky display gets corrupted since updating Antix-16 to Antix-17 hazel Linux - Distributions 3 12-18-2017 08:55 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > antiX / MX Linux

All times are GMT -5. The time now is 09:58 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration