LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software > Linux - Kernel
User Name
Password
Linux - Kernel This forum is for all discussion relating to the Linux kernel.

Notices


Reply
  Search this Thread
Old 01-18-2007, 09:28 PM   #1
duhasst0
LQ Newbie
 
Registered: Jan 2004
Distribution: Gentoo 2006.1, Slackware
Posts: 29

Rep: Reputation: 15
Kernel Iptables problem


Well really I may just need some advice and I think its been posted before but as far as I can tell I did just about everything that was in those posts to fix the problem already but still no dice. Anyway here is my error message from iptabls -L

Code:
FATAL: Module ip_tables not found.
iptables v1.3.5: can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
also here is uname -a

Code:
Linux prototypex 2.6.18-gentoo-r6 #5 SMP Thu Jan 18 17:27:08 EST 2007 i686 AMD Athlon(tm) XP 3000+ AuthenticAMD GNU/Linux
If you think you may need any other info to help you out with helping me out let me know I will be checking back periodically. Also I know kodon has helped me out in the past so if you know him and can get ahold of him or if you are reading this dude HELP!!!! lol

John
 
Old 01-19-2007, 02:12 PM   #2
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
It looks like you have some of your netfilter stuff compiled as modules and need to do a modprobe modulename before it will work. Have a look in your kernel source's .config file to see which components you've compiled as modules. You should also be able to look in /lib/modules/`uname -r`/kernel/net/netfilter to the modules.
 
Old 01-19-2007, 03:37 PM   #3
duhasst0
LQ Newbie
 
Registered: Jan 2004
Distribution: Gentoo 2006.1, Slackware
Posts: 29

Original Poster
Rep: Reputation: 15
Alright will try. I am also seeing if updating the kernel will help at all as well so I now have 3 different kernels on the computer compiled. Just gotta get all the stuff I need to compile to get everything to work. Thanks for the help I sure will keep posting here till we can get this all fingered out. I have been coming to this forum for a few years and have learned a great deal and I know that sometimes when it comes to Linux its best to have a group thought process for the most part. So I will let you know what the stats are.

John
 
Old 01-19-2007, 03:52 PM   #4
duhasst0
LQ Newbie
 
Registered: Jan 2004
Distribution: Gentoo 2006.1, Slackware
Posts: 29

Original Poster
Rep: Reputation: 15
Well this is really weird I loaded up putty cause I don't sit next to this computer at all any more for the most part, but netfilter isn't in the /lib/modules/2.6/kernel/net at all. I know that when I did make menuconfig I added netfilter not as a module but built in. A friend of mine said that building it in instead of using as a module is better so I don't understand that at all. But I also check my 2.6.19 kernel directory and it was in there. I guess I am just gonna have to get that kernel working with my system bad thing is that when I did that the services I usually have running so that I can get in remotely like ssh weren't letting me in even when I flushed my iptables rules so. This is very confusing right now. But like I said I am grinding those gears trying what makes sense and falling back on what works if it doesn't work lol. Oh well back to the drawing board.


John
 
Old 01-19-2007, 03:54 PM   #5
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
If you have problems, it might be helpful to see the networking and netfilter sections of your kernel's .config file...

BTW in response to your email, I'm very impressed with Slackware 11 - I have it on several boxes at work and 2 at home. They're all stable and reliable. Here's the output of uptime on the box at home I'm using at the moment:
Code:
steve@fender:~$ uptime
 07:52:37 up 103 days, 11:37,  7 users,  load average: 0.31, 0.28, 0.25
 
Old 01-20-2007, 06:30 PM   #6
manwichmakesameal
Member
 
Registered: Aug 2006
Distribution: Slackware
Posts: 804

Rep: Reputation: 110Reputation: 110
Netfilter

When configuring your kernel, did you
Code:
Networking --> Networking Options --> Network Packet Filtering --> Core Netfilter Configuration --> [X] not[*] Netfilter Xtables support
There are some other options under those menus, but I'll let you pick those out.
 
Old 01-24-2007, 09:31 PM   #7
duhasst0
LQ Newbie
 
Registered: Jan 2004
Distribution: Gentoo 2006.1, Slackware
Posts: 29

Original Poster
Rep: Reputation: 15
well here it is my netfilter part of the .config file

Code:
#
# Core Netfilter Configuration
#
# CONFIG_NETFILTER_NETLINK is not set
CONFIG_NETFILTER_XTABLES=y
# CONFIG_NETFILTER_XT_TARGET_CLASSIFY is not set
# CONFIG_NETFILTER_XT_TARGET_MARK is not set
# CONFIG_NETFILTER_XT_TARGET_NFQUEUE is not set
# CONFIG_NETFILTER_XT_MATCH_COMMENT is not set
# CONFIG_NETFILTER_XT_MATCH_CONNTRACK is not set
# CONFIG_NETFILTER_XT_MATCH_DCCP is not set
# CONFIG_NETFILTER_XT_MATCH_ESP is not set
# CONFIG_NETFILTER_XT_MATCH_HELPER is not set
# CONFIG_NETFILTER_XT_MATCH_LENGTH is not set
# CONFIG_NETFILTER_XT_MATCH_LIMIT is not set
# CONFIG_NETFILTER_XT_MATCH_MAC is not set
# CONFIG_NETFILTER_XT_MATCH_MAC is not set
# CONFIG_NETFILTER_XT_MATCH_MARK is not set
# CONFIG_NETFILTER_XT_MATCH_POLICY is not set
# CONFIG_NETFILTER_XT_MATCH_MULTIPORT is not set
# CONFIG_NETFILTER_XT_MATCH_PKTTYPE is not set
# CONFIG_NETFILTER_XT_MATCH_QUOTA is not set
# CONFIG_NETFILTER_XT_MATCH_REALM is not set
# CONFIG_NETFILTER_XT_MATCH_SCTP is not set
# CONFIG_NETFILTER_XT_MATCH_STATE is not set
# CONFIG_NETFILTER_XT_MATCH_STATISTIC is not set
# CONFIG_NETFILTER_XT_MATCH_STRING is not set
# CONFIG_NETFILTER_XT_MATCH_TCPMSS is not set

#
# IP: Netfilter Configuration
#
CONFIG_IP_NF_CONNTRACK=y
# CONFIG_IP_NF_CT_ACCT is not set
# CONFIG_IP_NF_CONNTRACK_MARK is not set
# CONFIG_IP_NF_CONNTRACK_EVENTS is not set
# CONFIG_IP_NF_CT_PROTO_SCTP is not set
CONFIG_IP_NF_FTP=y
# CONFIG_IP_NF_IRC is not set
# CONFIG_IP_NF_NETBIOS_NS is not set
# CONFIG_IP_NF_TFTP is not set
# CONFIG_IP_NF_AMANDA is not set
# CONFIG_IP_NF_PPTP is not set
# CONFIG_IP_NF_H323 is not set
# CONFIG_IP_NF_SIP is not set
# CONFIG_IP_NF_QUEUE is not set
CONFIG_IP_NF_IPTABLES=y
# CONFIG_IP_NF_MATCH_IPRANGE is not set
# CONFIG_IP_NF_MATCH_TOS is not set
# CONFIG_IP_NF_MATCH_RECENT is not set
# CONFIG_IP_NF_MATCH_ECN is not set
# CONFIG_IP_NF_MATCH_DSCP is not set
# CONFIG_IP_NF_MATCH_AH is not set
# CONFIG_IP_NF_MATCH_TTL is not set
# CONFIG_IP_NF_MATCH_OWNER is not set
# CONFIG_IP_NF_MATCH_ADDRTYPE is not set
# CONFIG_IP_NF_MATCH_HASHLIMIT is not set
# CONFIG_IP_NF_FILTER is not set
CONFIG_IP_NF_TARGET_LOG=y
# CONFIG_IP_NF_TARGET_ULOG is not set
# CONFIG_IP_NF_TARGET_TCPMSS is not set
CONFIG_IP_NF_NAT=y
CONFIG_IP_NF_NAT_NEEDED=y
CONFIG_IP_NF_TARGET_MASQUERADE=y
# CONFIG_IP_NF_TARGET_REDIRECT is not set
# CONFIG_IP_NF_TARGET_NETMAP is not set
# CONFIG_IP_NF_TARGET_SAME is not set
# CONFIG_IP_NF_NAT_SNMP_BASIC is not set
CONFIG_IP_NF_NAT_FTP=y
# CONFIG_IP_NF_MANGLE is not set
# CONFIG_IP_NF_RAW is not set
# CONFIG_IP_NF_ARPTABLES is not set
Also I am working on a different server and need some advice for it. It will need to be able to server webpages for a web store. I am pretty unsure of what kinda of services I need and what software packs I should download and install. Also your opinion on what distro and kernel would be greatly appreciated. Well I hope I get some results some time soon. lol

Thanks guys
John
 
Old 01-24-2007, 10:51 PM   #8
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
I'd suggest setting CONFIG_IP_NF_FILTER and CONFIG_NETFILTER_NETLINK to 'y'. CONFIG_IP_NF_FILTER provides packet filtering and defines a table `filter', which your error message says you don't have. CONFIG_NETFILTER_NETLINK will include support for the new netfilter netlink interface which I think is necessary.
 
Old 01-31-2007, 10:46 PM   #9
duhasst0
LQ Newbie
 
Registered: Jan 2004
Distribution: Gentoo 2006.1, Slackware
Posts: 29

Original Poster
Rep: Reputation: 15
had a friend go into the box and take a look at my kernel here is the .config netfilter part. the error changed abit just now fatal error just this.

Code:
iptables v1.3.5: can't initialize iptables table `filter': Table does not exist                                              (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
i dont know what the hell is going wrong some one just smack me in the face i am such a stupid newb.

Code:
#
# Core Netfilter Configuration
#
CONFIG_NETFILTER_NETLINK=y
# CONFIG_NETFILTER_NETLINK_QUEUE is not set
# CONFIG_NETFILTER_NETLINK_LOG is not set
CONFIG_NETFILTER_XTABLES=y
CONFIG_NETFILTER_XT_TARGET_CLASSIFY=y
CONFIG_NETFILTER_XT_TARGET_MARK=y
CONFIG_NETFILTER_XT_TARGET_NFQUEUE=y
CONFIG_NETFILTER_XT_MATCH_COMMENT=y
CONFIG_NETFILTER_XT_MATCH_CONNBYTES=y
CONFIG_NETFILTER_XT_MATCH_CONNMARK=y
CONFIG_NETFILTER_XT_MATCH_CONNTRACK=y
CONFIG_NETFILTER_XT_MATCH_DCCP=y
CONFIG_NETFILTER_XT_MATCH_DSCP=y
CONFIG_NETFILTER_XT_MATCH_ESP=y
CONFIG_NETFILTER_XT_MATCH_HELPER=y
CONFIG_NETFILTER_XT_MATCH_LENGTH=y
CONFIG_NETFILTER_XT_MATCH_LIMIT=y
CONFIG_NETFILTER_XT_MATCH_MAC=y
CONFIG_NETFILTER_XT_MATCH_MARK=y
CONFIG_NETFILTER_XT_MATCH_POLICY=y
CONFIG_NETFILTER_XT_MATCH_MULTIPORT=y
CONFIG_NETFILTER_XT_MATCH_PKTTYPE=y
CONFIG_NETFILTER_XT_MATCH_QUOTA=y
CONFIG_NETFILTER_XT_MATCH_REALM=y
# CONFIG_NETFILTER_XT_MATCH_SCTP is not set
CONFIG_NETFILTER_XT_MATCH_STATE=y
CONFIG_NETFILTER_XT_MATCH_STATISTIC=y
CONFIG_NETFILTER_XT_MATCH_STRING=y
CONFIG_NETFILTER_XT_MATCH_TCPMSS=y

#
# IP: Netfilter Configuration
#
CONFIG_IP_NF_CONNTRACK=y
CONFIG_IP_NF_CT_ACCT=y
CONFIG_IP_NF_CONNTRACK_MARK=y
CONFIG_IP_NF_CONNTRACK_EVENTS=y
# CONFIG_IP_NF_CONNTRACK_NETLINK is not set
# CONFIG_IP_NF_CT_PROTO_SCTP is not set
CONFIG_IP_NF_FTP=y
CONFIG_IP_NF_IRC=y
# CONFIG_IP_NF_NETBIOS_NS is not set
CONFIG_IP_NF_TFTP=y
# CONFIG_IP_NF_AMANDA is not set
# CONFIG_IP_NF_PPTP is not set
# CONFIG_IP_NF_H323 is not set
# CONFIG_IP_NF_SIP is not set
# CONFIG_IP_NF_QUEUE is not set
# CONFIG_IP_NF_IPTABLES is not set
# CONFIG_IP_NF_ARPTABLES is not set

Last edited by duhasst0; 01-31-2007 at 10:52 PM.
 
Old 01-31-2007, 10:52 PM   #10
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
It looks like you still don't have CONFIG_IP_NF_FILTER set - can you check that?
 
Old 01-31-2007, 11:11 PM   #11
duhasst0
LQ Newbie
 
Registered: Jan 2004
Distribution: Gentoo 2006.1, Slackware
Posts: 29

Original Poster
Rep: Reputation: 15
That is interesting... i never saw an option like that in the make menuconfig at all... but that should get everything to work then?? well its worth a try
 
Old 02-01-2007, 12:13 AM   #12
duhasst0
LQ Newbie
 
Registered: Jan 2004
Distribution: Gentoo 2006.1, Slackware
Posts: 29

Original Poster
Rep: Reputation: 15
alright well got it up iptables is working. now its time to get a script for it working right and i will be completely in business. any popular tutorial you use or can recommend me to?
 
Old 02-01-2007, 02:34 AM   #13
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
I used the info at http://www.netfilter.org/documentation/index.html when I first set mine up. I've also seen people recommend http://freshmeat.net/projects/iptables-firewall/
 
  


Reply

Tags
iptables, kernel, netfilter


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
HELP! Iptables problem after kernel upgrade alfista Linux - Newbie 9 07-06-2007 06:58 AM
iptables kernel 2.6.16.19 pljvaldez Linux - Kernel 7 06-17-2006 01:12 PM
Problem updating iptables, with 2.6.16 kernel. RavenOfOdin Linux - Kernel 9 06-02-2006 04:01 PM
iptables v1.2.9: Unknown arg `/sbin/iptables' Try `iptables -h' or 'iptables --help' Niceman2005 Linux - Security 4 12-29-2005 08:20 PM
iptables problem with Debian 3.0r1 (Kernel 2.4.18) markus1982 Linux - Networking 3 08-21-2003 05:07 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software > Linux - Kernel

All times are GMT -5. The time now is 06:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration