iptables missing libipt_connbytes.so?
So, I'm trying to use iptables on my Slackware 10.2 with
a 2.6.15-rc5 kernel with practically all the iptables modules built as modules. Why do I get this output? code: Code:
root@alakazam:~# iptables -m connbytes -h /usr/lib/iptables/libipt_connbytes.so? Is iptables package in need of update to work with 2.6.X kernels' available modules? I have iptables-1.3.3-i486-1, which is latest from <http://slackware.it/en/pb/search.php?v=current&t=2&q=libipt_*>. TIA, -bbeers |
i would do these things if i were you...
- download the latest kernel source code (2.6.15.1 at the time of this post)... - double-check that all the netfilter options are properly set and stuff... - recompile kernel... - recompile iptables using the latest source code (1.3.4 at the time of this post)... but having said that, i'm using iptables 1.3.4 and kernel 2.4.33-pre1 and i get the same result as you do, so i doubt it's a 2.6 issue: Code:
bash-3.00# iptables -m connbytes |
i've found a patch named connbytes in the patch-o-matic repository, so i'm thinking maybe you need to patch before you get the connbytes option??
http://netfilter.org/projects/patch-...xtra-connbytes |
Thanks for confirming my issue.
I think the libipt_* files are built from the iptables source not kernel source. I can modprobe ipt_connbytes kernel module, it is the library that is missing. I guess what I'd like to see is the latest iptables package from slackware include support for *all* the iptables kernel modules available in the recent vanilla kernels. I could compile iptables libraries myself, sure, but doesn't this seem like an oversight wrt the iptables package? How would one go about making this kind of request? An e-mail to PJV, himself? Does he read ths forum? Slackware.com still lists this as "our favorite Slackware questions forum". :) -- -bbeers |
Quote:
Quote:
Quote:
Quote:
Quote:
|
how'd it go with this, bbeers?? did you get it working?? i'm starting to think that if you already have the connbytes functionality in your kernel/modules then it's just a matter of recompiling iptables while running that kernel, cuz i couldn't find anything in the iptables installation that would enable such a thing, but i'm not sure of course... have you tried it?? make sure you try compiling iptables 1.3.4 cuz in the changelog they do mention an issue with connbytes and linux 2.6 which was fixed:
Quote:
|
Quote:
very busy at work. I did notice that iptables project has a lot of non-vanilla stuff -- which I guess will not be in a slackware iptables package since the kernel is built vanilla. I just looked at the kernel itptables modules available in the 'testing/packages/linux-2.6.14.6/kernel-modules-2.6.14.6-i486-1' and connbytes is not there. So I guess I added it when I compiled my own kernel 2.6.15-rc5. But, still, I think more iptables modules could be built with vanilla 2.6.X kernel, and so iptables needs to be built with all corresponding libs. |
All times are GMT -5. The time now is 11:47 AM. |