LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-29-2008, 11:21 AM   #1
jeffn
LQ Newbie
 
Registered: Sep 2004
Posts: 1

Rep: Reputation: 0
How do I create the netfilter ip-strings module for a linux linux-2.6.18.2-34 kernel?


Hi,

I'm trying to build a reasonable firewall.
"Trouble shooting linux firewalls" recommends using the ip_strings
module, which is not part of the kernel.

I found the string module in the patch-o-matic, but it does not want to build because my kernel version is greater than 2.6.0.

From the .../patch-o-matic.../stings.info
Author: Emmanuel Roger <winfield@freegates.be>
Status: Working, not with kernel 2.4.9
Repository: extra
Requires: linux < 2.6.0

What is the magic that will allow me to build the string (and other modules) for my kernel?

Thanks

Jeffrey
 
Old 01-30-2008, 06:39 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
While one of the functions of the Netfilter framework (for which iptables is "just" a humble front-end) is to provide security by modifying traffic and destinations your question is not about Linux Security but about configuring or installing software, which means this thread should be in the Software forum.
I'll move it there.


Quote:
Originally Posted by jeffn View Post
"Troubleshooting Linux Firewalls" recommends using the ip_strings
If your intention is to use convert Snort rulesets to make Netfilter behave like Snort(-inline), then you better use Snort. Both snorts matching methods and signatures are adjusted and more efficient compared to using ip_strings. What I'm trying to say is please don't use a module just because the HOWTO says so: investigate first.


If it does not want to build then you'll have to manually edit the source (kernel and iptables) and don't forget to include any rejects. If it still doesn't work, or you have trouble understanding what goes where, get the last supported vanilla kernel and iptables sources, patch those and read and compare (dirdiff?). If you still don't get it right post the steps you took and any output of make menu|g|x|config build logs etc, etc. Since that will be a load, you may want to tarball it up, upload to some free hosting provider and post a D/L URI instead.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
netfilter packet capturing-sample code for linux 2.6 kernel anandkj Linux - Networking 0 07-04-2007 04:37 AM
Linux kernel debugging and Linux kernel module programming Igor007 Programming 2 08-13-2005 05:12 AM
Linux kernel debugging and Linux kernel module programming Igor007 Linux - Enterprise 3 08-12-2005 02:47 PM
netfilter/iptables in kernel: module vs static -Nw- neX Linux - Security 5 03-25-2005 06:44 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration