[Security-Discuss] 2007.0 shorewall & ifw problem (bug?)

Antonio <[email protected]> Wed, 3 Jan 2007 21:47:32 +0100
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Happy new year to the list!!!
So, here I am with mine first problem of the year :)
I recently installed a fresh mandriva 2007.0 on my old machine (was a mandr=
iva=20
2006), and I decided to setup on it a firewall with shorewall (in the past =
I=20
used guardog). So, I've read the docs and cooked out a working config, firs=
t=20
running drakfirewall (mainly to see how it setup the interactive firewall),=
=20
then manually editing the files to add things I need.
All seemed to be ok, and at every reboot shorewall came up fine, so I decid=
ed=20
to save the working config with "shorewall save". Then, at the following=20
reboot shorewall was not started, so to see what is happening I issued=20
manually a "shorewall -f start", and here it is the output:

# shorewall -f start
Restoring Shorewall...
Processing /etc/shorewall/params ...
iptables-restore v1.3.5: Set ifw_wl doesn't exist.
Error occurred at line: 86
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Shorewall restored from /var/lib/shorewall/restore

line 86,87 and 88 of /var/lib/shorewall/iptables-restore are related to the=
=20
interactive firewall:
#86 -A Ifw -m set --set ifw_wl src -j RETURN=20
#87 -A Ifw -m set --set ifw_bl src -j DROP=20
#88 -A Ifw -m state --state INVALID,NEW -m psd --psd-weight-threshold=20
10 --psd-delay-threshold 10000 --psd-lo-ports-weight 2 --psd-hi-ports-weigh=
t=20
1 -j IFWLOG --log-prefix "SCAN"

From what I can understand seem that, finding a problem related to the=20
interactive firewall, shorewall stopped processing the restore file,=20
resulting in a stopped state.
It is needed to underline that without saving a restore file, shorewall did=
n't=20
complain about any errors, however I noticed that the interactive firewall=
=20
seem not working at all in both cases.

Here I see 2 problems:
1)the interactive firewall seem not working, but I didn't modified the line=
s=20
that drakfirewall writed about the ifw, and packages mandi, mandi-ifw,=20
iptables, ipset and shorewall are installed and seem to be ok.

Output of "ipset --list" (may be useful):
Name: ifw_wl
Type: iptree
References: 1
Default binding:=20
Header:
Members:
Bindings:

Name: ifw_bl
Type: iptree
References: 1
Default binding:=20
Header: timeout: 3600
Members:
Bindings:


2)the other is related to shorewall: why shorewall behaves differently with=
=20
the same config (should not make differences if a config is saved in a=20
restore file or if it sits down in the files under /etc/shorewall): errors =
in=20
config should be reported in every case, and shorewall should stop (if not=
=20
one can miss them).

Thanks in advance,
Antonio.
____________________________________________________
Want to buy your Pack or Services from Mandriva?=20
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________