[Security-Discuss] 2007.0 shorewall & ifw problem (bug?)
Antonio <[email protected]> Wed, 3 Jan 2007 21:47:32 +0100
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
Happy new year to the list!!! So, here I am with mine first problem of the year :) I recently installed a fresh mandriva 2007.0 on my old machine (was a mandr= iva=20 2006), and I decided to setup on it a firewall with shorewall (in the past = I=20 used guardog). So, I've read the docs and cooked out a working config, firs= t=20 running drakfirewall (mainly to see how it setup the interactive firewall),= =20 then manually editing the files to add things I need. All seemed to be ok, and at every reboot shorewall came up fine, so I decid= ed=20 to save the working config with "shorewall save". Then, at the following=20 reboot shorewall was not started, so to see what is happening I issued=20 manually a "shorewall -f start", and here it is the output: # shorewall -f start Restoring Shorewall... Processing /etc/shorewall/params ... iptables-restore v1.3.5: Set ifw_wl doesn't exist. Error occurred at line: 86 Try `iptables-restore -h' or 'iptables-restore --help' for more information. Shorewall restored from /var/lib/shorewall/restore line 86,87 and 88 of /var/lib/shorewall/iptables-restore are related to the= =20 interactive firewall: #86 -A Ifw -m set --set ifw_wl src -j RETURN=20 #87 -A Ifw -m set --set ifw_bl src -j DROP=20 #88 -A Ifw -m state --state INVALID,NEW -m psd --psd-weight-threshold=20 10 --psd-delay-threshold 10000 --psd-lo-ports-weight 2 --psd-hi-ports-weigh= t=20 1 -j IFWLOG --log-prefix "SCAN" From what I can understand seem that, finding a problem related to the=20 interactive firewall, shorewall stopped processing the restore file,=20 resulting in a stopped state. It is needed to underline that without saving a restore file, shorewall did= n't=20 complain about any errors, however I noticed that the interactive firewall= =20 seem not working at all in both cases. Here I see 2 problems: 1)the interactive firewall seem not working, but I didn't modified the line= s=20 that drakfirewall writed about the ifw, and packages mandi, mandi-ifw,=20 iptables, ipset and shorewall are installed and seem to be ok. Output of "ipset --list" (may be useful): Name: ifw_wl Type: iptree References: 1 Default binding:=20 Header: Members: Bindings: Name: ifw_bl Type: iptree References: 1 Default binding:=20 Header: timeout: 3600 Members: Bindings: 2)the other is related to shorewall: why shorewall behaves differently with= =20 the same config (should not make differences if a config is saved in a=20 restore file or if it sits down in the files under /etc/shorewall): errors = in=20 config should be reported in every case, and shorewall should stop (if not= =20 one can miss them). Thanks in advance, Antonio. ____________________________________________________ Want to buy your Pack or Services from Mandriva?=20 Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________