LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions
User Name
Password
Linux - Distributions This forum is for Distribution specific questions.
Red Hat, Slackware, Debian, Novell, LFS, Mandriva, Ubuntu, Fedora - the list goes on and on... Note: An (*) indicates there is no official participation from that distribution here at LQ.

Notices


Reply
  Search this Thread
Old 01-18-2003, 01:27 PM   #1
Loke
LQ Newbie
 
Registered: Oct 2002
Location: Norway
Distribution: Suse 8.0
Posts: 21

Rep: Reputation: 15
iptables on Suse 8.0


Beeing fairly new to Linux I am a bit pussled with iptables on Suse 8.0. I (think) I understand iptables alone; what confuses me is the SuSEfirewall and the personal-firewall. I have configures written a iptables-script and installed it thus:

# sh /root/firewall.conf

which gives no syntax errors, so I save the rules thus

# iptables-save

and then reboot.

When booting I get the following messages:

Starting Firewall Initialization (Phase 1 of 3)
.
.
Starting Firewall Initialization (Phase 2 of 3)
.
.
Starting Firewall Initialization (Phase 3 of 3)

which looks OK. Moreover, the firewall seems to be working as intended: it block what should be blocked and lets through what I want to let through. However, whan listing the rules, e.g:

# iptables -v -L INPUT

the output contaings warning messages that I do not have in my script. The warnings of the type:

LOG level warning tcp-options ip-otions prefix `SuSE-FW-DROP-ANTI_S......

What bothers me is that I do not know where (which script) those messages come from.

What is the relation between netfilet/iptables, the SuSEfirewall and personař-firewall?
Anyway, I managed to switch off personal firewall in Yast and the boot process shows that it isn't in use.
Could it be that SuSEfirewall is equivalent with iptables?
I would in any case sleep better if I knew the details.


The following files are located under /etc/init.d

/etc/init.d/SuSEfirewall2_init
/etc/init.d/SuSEfirewall2_setup
/etc/init.d/SuSEfirewall2_final

/etc/init.d/personal-firewall.initial
/etc/init.d/personal-firewall.final

Also, why are there two versions of the iptables files in /usr/sbin?

/usr/sbin/ip6tables
/usr/sbin/ip6tables-restore
/usr/sbin/ip6tables-save

/usr/sbin/iptables
/usr/sbin/iptables-restore
/usr/sbin/iptables-save

Regards
 
Old 01-18-2003, 04:03 PM   #2
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
I guess SUSEfirewall uses iptables. And ip6tables looks like IPv6 version of iptables.
 
Old 01-23-2003, 04:46 PM   #3
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
One of the common problems with using "many" scripts is identifying which one is doing which rule...

The good news is that you can ask each script to echo to the screen as it runs.
I'd guess that there are three scripts, each echoing as "Phase x of 3"
Have a look inside the scripts you have found for text like that...

There is a good reason for using consecutive scripts like this, but if you want to be the master of them, you will need to discover what is really happening before you make any manual changes...

The last script to run controls the rules...
So, if you have a script that starts by flushing and clearing the rulesets, it won't matter what comes before...

Have a look at this iptables tutorial
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Is anything beyond iptables v1.2.11 compatible with SuSE 9.2??? mikfig SUSE / openSUSE 1 11-02-2005 11:36 PM
Iptables in Suse Sles 9.0 Mishra100 Linux - Newbie 1 01-01-2005 09:22 AM
Suse 9.1 and iptables Osiris123d Linux - Networking 5 08-19-2004 02:21 PM
Suse 9.1 iptables CobaltFire Linux - Networking 0 07-13-2004 02:49 AM
iptables on Suse 8.0 Sigmund Gudvang Linux - Distributions 1 10-02-2002 01:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions

All times are GMT -5. The time now is 05:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration