Hello all expert Linux administrator, i am a beginner of Linux user. I using Fedora 7. My kernel version is 2.6.22.1-27.fc7.
I wonder my iptables is secure enough or not.
Therefore, i would like to add additional modules for iptables where i can check the ACN, SYN, RST tcp flags.
These are the files under directory /proc/sys/net/netfilter/nf_conntrack_
nf_conntrack_buckets
nf_conntrack_checksum
nf_conntrack_count
nf_conntrack_generic_timeout
nf_conntrack_icmp_timeout
nf_conntrack_log_invalid
nf_conntrack_max
nf_conntrack_tcp_be_liberal
nf_conntrack_tcp_loose
nf_conntrack_tcp_max_retrans
nf_conntrack_tcp_timeout_close
nf_conntrack_tcp_timeout_close_wait
nf_conntrack_tcp_timeout_established
nf_conntrack_tcp_timeout_fin_wait
nf_conntrack_tcp_timeout_last_ack
nf_conntrack_tcp_timeout_max_retrans
nf_conntrack_tcp_timeout_syn_recv
nf_conntrack_tcp_timeout_syn_sent
nf_conntrack_tcp_timeout_time_wait
nf_conntrack_udp_timeout
nf_conntrack_udp_timeout_stream
I wonder any missing modules.
I have downloaded some files from netfilter such as below.
libnfnetlink-0.0.25.tar.bz2
libnfnetlink_queue-0.0.10.tar.bz2
ipset-2.2.8-20051203.tar.bz2.
patch-o-matic-20031219.tar.bz2
I wonder how to install those files.
Below is my understanding of compile kernel.
Quote:
1. make xconfig
2. make dep
Builds the tree of interdependencies in the kernel sources
3. make clean
Clean any unwanted files
4. make bzImage
Compress kernel
5. make modules
6. cp /usr/Linux/src/arch/i386/boot/bzImage /boot/ newkernel
7. make modules_install
|
I don't understand step 6 and 7.
How to edit the grub bootloader and ready to boot new kernel?
Do unchecked any unnecessary features of kernel improve performance ?
Thanks for your help.
Your help is greatly appreciated by me and others.