iptables-1.8.11 review
"Randy McMurchy" ([email protected] via blfs-support Mailing List) <[email protected]> Thu, 11 Sep 2025 23:14:31 -0500
| Newsgroups | gmane.linux.lfs.beyond.support |
|---|---|
| Message-ID | <[email protected]> |
Hi all, I was a bit surprised to see iptables still in the BLFS book. I tried to look back in the -dev archives to see why nftables is not in the book, but I really couldn't find anything other than 5 years ago Bruce could not get in touch with DJ so nftables (and its dependencies) were archived. There's really nothing useful in the -dev archives since then that I could find. But that's not what I'm writing about. I noticed there are many flaws in the iptables instructions. I will point them out, and if agreed that changes need to be made to the instructions, I can submit a patch. This has nothing to do with configuring a firewall, my aim is pointing out mistakes in the install instructions only. First, the Note at the beginning is not applicable any longer unless perhaps it is referring to the bpf-utils optional dependency which I did not install as it seems complicated and the package is unmaintained. Documentation on the netfilter.org web site and in the INSTALL file clearly states that using raw kernel headers is no longer required. Anything it needs now comes from /usr/include/linux. Second, and this could be because I deviated from the book (yes, I know, that's why I'm writing in -support instead of -dev). The configure command I used is as follows: ./configure --prefix=/usr --enable-libipq --enable-nfsynproxy \ --enable-bpf-compiler --sysconfdir=/etc Note the last sysconfdir entry. My installation installed /etc/ethertypes and if you don't specify the sysconfdir, the file ends up in /usr/etc/. Note that I also removed the --disable-nftables option. Third, the package now ships a fairly intensive test suite. It must be run by root, and the /etc/ethertypes file needs to be installed before the tests are run. The shipped ethertypes file is in the etc directory of the source tree. Here is some output from the tests using the command: grep -Ev ': OK|[OK]|^make' test.log ============================================================= Making check in libiptc Making check in libxtables Making check in include Making check in libipq Making check in utils Making check in extensions Making check in iptables ./extensions/generic.txlate: Fail ./extensions/generic.txlate: Fail ./extensions/generic.txlate: Fail ./extensions/generic.txlate: Fail 85 test files, 450 tests, 446 tests passed, 0 tests failed, 4 errors FAIL: xlate-test.py legacy: 123 test files, 1693 unit tests, 1691 passed nft: 144 test files, 2002 unit tests, 2000 passed total: 144 test files, 3695 unit tests, 3691 passed FAIL: iptables-test.py W: [FAILED] ././iptables/tests/shell/testcases/iptables/0008-unprivileged_0: expected 0 but got 131 W: [FAILED] ././iptables/tests/shell/testcases/iptables/0008-unprivileged_0: expected 0 but got 131 FAIL: iptables/tests/shell/run-tests.sh =================== 3 of 3 tests failed =================== ============================================================= Fourth, it probably wouldn't hurt to expand just a bit the --disable-nftables "Command Explanation". Maybe say something like "Remove this switch if you have installed nftables and desire the compatibility layer." -- Randy -- http://lists.linuxfromscratch.org/sympa/info/blfs-support Unsubscribe: See the above information page