Need help installing Trace to debug Iptables
hi, found an article online that use Trace to debug iptables. I try installing but it will give the error below. Wondering if anyone get this too and how do we solve them? Am using root on Ubuntu 20.04 LTS
Code:
echo ipt_LOG >/proc/sys/net/netfilter/nf_log/2 thank you, |
I guess that the number is your interface number. On my system, /proc/sys/net/netfilter/nf_log contains files 0, 1, 2, ..., though these numbers have nothing to do with the indices displayed by the ip link command.
Thus, my next guess is that you have two interfaces, loopback and your main interface, and therefore /proc/sys/net/netfilter/nf_log only contains files 0 and 1. TLDR: Try /proc/sys/net/netfilter/nf_log/1 instead. |
Quote:
The numbers are protocol numbers. Try modprobing something else, such as nf_log_ipv4. What do you get from Code:
ls /proc/sys/net/netfilter/nf_log |
Quote:
When i try run this- Code:
modprobe nf_log_ipv4 Code:
ls /proc/sys/net/netfilter/nf_log Code:
cat /proc/net/netfilter/nf_log |
I change the second line to
Code:
echo nf_log_ipv4 >/proc/sys/net/netfilter/nf_log/2 but how do i try them? i follow the guide on the page to Trace a port(OpenVPN) - Code:
iptables -t raw -I PREROUTING -p udp --dport 1194 -j TRACE Code:
dmesg | grep 'TRACE: raw:PREROUTING:policy' | head -1 Code:
dmesg | grep ID=40359 thank you. |
Sorry, iptables tracing is something I want to try but I have no experience so far. I was just curious about your original question (and totally missed the incorrect directory that you used).
|
Quote:
and do you know if we need to cleanup(the modprobe, echo nf thingy) after using? if yes, how? p/s - u hv any suggest reading for this topic? |
Quote:
Quote:
|
@berndbausch thanks a lot. hope someone will chip in with more info in future rgd this topic. cheers
|
All times are GMT -5. The time now is 03:52 AM. |