RE: Updating dev package

"scan" <[email protected]> Tue, 18 Feb 2003 15:24:32 +0100
Newsgroups gmane.linux.redhat.release.guinness
Message-ID <[email protected]>
I recommend to update : load latest kernel from www.kernel.org + iptables
from www.iptables.org .
do not forget to install kernel-headers from base distribution before (makes
life easier)

here I wrote a procedure in past (after a protocol of iptables
installation) - maybe it helps you ....:

Protokoll eines Linux Updates

Notiz: kernel update auf einer Liunxconsole oder auch putty

Helpful links:

http://www.redhat.com/mirrors/LDP/HOWTO/Kernel-HOWTO.html

Base informations:

Distribution: Redhat 7.1
Version Notes: Linux localhost.localdomain 2.4.2-2smp #1 SMP Sun Apr 8
20:21:34 EDT 2001 i686 unknown
Installed Packages after Installation: (list from `rpm -qa|sort`)

<PackageList>
4Suite-0.10.1-1
a2ps-4.13b-13
abiword-0.7.13-2
adjtimex-1.11-4
alchemist-0.16-3
amanda-2.4.2p2-1
amanda-client-2.4.2p2-1
amanda-devel-2.4.2p2-1
amanda-server-2.4.2p2-1
anaconda-7.1-5
anaconda-runtime-7.1-5
anacron-2.3-16
anonftp-4.0-4
apache-1.3.19-5
apacheconf-0.7-2
apache-devel-1.3.19-5
apache-manual-1.3.19-5
apmd-3.0final-29
arpwatch-2.1a10-39
arts-2.1.1-5
ash-0.3.7-1
asp2php-0.75.11-1
asp2php-gtk-0.75.11-1
aspell-0.32.6-2
aspell-ca-0.1-7
aspell-da-1.4.9-1
aspell-de-0.1.1-7
aspell-devel-0.32.6-2
aspell-en-ca-0.32.6-2
aspell-en-gb-0.32.6-2
aspell-es-0.2-1
aspell-fr-0.3-6
aspell-it-0.1-6
aspell-nl-0.1-6
aspell-no-0.2-1
aspell-pt_BR-2.4-1
aspell-sv-0.2-1
at-3.1.8-16
audiofile-0.1.11-1
audiofile-devel-0.1.11-1
aumix-2.7-2
aumix-X11-2.7-2
authconfig-4.1.6-1
auth_ldap-1.4.7-2
autoconf-2.13-10
autofs-3.1.7-14
automake-1.4-8
autorun-2.65-1
awesfx-0.4.3a-7
balsa-1.1.1-3
basesystem-7.0-2
bash-2.04-21
bash-doc-2.04-21
bc-1.06-2
bdflush-1.5-16
bind-9.1.0-10
bindconf-1.4-1
bind-devel-9.1.0-10
bind-utils-9.1.0-10
binutils-2.10.91.0.2-3
bison-1.28-5
blas-3.0-9
blas-man-3.0-9
blt-2.4u-4
bug-buddy-1.2-3
byacc-1.9-18
bzip2-1.0.1-3
bzip2-devel-1.0.1-3
Canna-devel-3.5b2-40
Canna-libs-3.5b2-40
cdda2wav-1.9-6
cdecl-2.5-17
cdp-0.33-20
cdparanoia-alpha9.7-7
cdparanoia-devel-alpha9.7-7
cdrecord-1.9-6
cdrecord-devel-1.9-6
chkconfig-1.2.22-1
chkfontpath-1.9.5-1
cleanfeed-0.95.7b-10
compat-egcs-6.2-1.1.2.14
compat-egcs-c++-6.2-1.1.2.14
compat-egcs-g77-6.2-1.1.2.14
compat-egcs-objc-6.2-1.1.2.14
compat-glibc-6.2-2.1.3.2
compat-libs-6.2-3
compat-libstdc++-6.2-2.9.0.14
console-tools-19990829-34
control-center-1.2.2-8
control-center-devel-1.2.2-8
control-panel-3.18-4
cpio-2.4.2-20
cpp-2.96-81
cproto-4.6-7
cracklib-2.7-8
cracklib-dicts-2.7-8
crontabs-1.9-2
ctags-4.0.3-1
cvs-1.11-3
cyrus-sasl-1.5.24-17
cyrus-sasl-devel-1.5.24-17
cyrus-sasl-gssapi-1.5.24-17
db1-1.85-5
db1-devel-1.85-5
db2-2.4.14-5
db2-devel-2.4.14-5
db3-3.1.17-7
db3-devel-3.1.17-7
db3-utils-3.1.17-7
dbskkd-cdb-1.01-8
ddskk-11.3.20010225-5
ddskk-el-11.3.20010225-5
desktop-backgrounds-1.1-4
dev-3.1.0-14
dev86-0.15.0-5
devfsd-2.4.2-2
dhcpcd-1.3.18pl8-10
dia-0.86-4
dialog-0.9a-4
diffstat-1.27-5
diffutils-2.7-21
dip-3.3.7o-22
Distutils-1.0.1-3
dmalloc-4.8.1-3
docbook-dtd30-sgml-1.0-10
docbook-dtd31-sgml-1.0-10
docbook-dtd40-sgml-1.0-11
docbook-dtd41-sgml-1.0-10
docbook-dtd41-xml-1.0-7
docbook-style-dsssl-1.59-10
docbook-utils-0.6-13
docbook-utils-pdf-0.6-13
dos2unix-3.1-6
dosfstools-2.2-8
doxygen-1.2.6-1
dump-0.4b21-3
dump-static-0.4b21-3
e2fsprogs-1.19-4
e2fsprogs-devel-1.19-4
ed-0.2-19
ee-0.3.12-3
efax-0.9-8
eject-2.0.2-7
ElectricFence-2.2.2-7
elm-2.5.3-11
emacs-20.7-34
emacs-el-20.7-34
emacs-leim-20.7-34
emacs-nox-20.7-34
emacs-X11-20.7-34
enscript-1.6.1-12
esound-0.2.22-1
esound-devel-0.2.22-1
exmh-2.2-9
expat-1.95.1-1
expat-devel-1.95.1-1
expect-5.31-53
ext2ed-0.1-23
extace-1.4.4-2
fbset-2.1-7
fetchmail-5.7.4-4
fetchmailconf-5.7.4-4
file-3.33-1
filesystem-2.0.7-1
fileutils-4.0.36-4
findutils-4.1.6-2
finger-0.17-7
finger-server-0.17-7
firewall-config-0.95-2
flex-2.5.4a-13
fnlib-0.5-4
fnlib-devel-0.5-4
fortune-mod-1.0-13
freecdb-0.62-3
freetype-2.0.1-4
freetype-devel-2.0.1-4
freetype-utils-2.0.1-4
FreeWnn-1.11-14
FreeWnn-common-1.11-14
FreeWnn-devel-1.11-14
FreeWnn-libs-1.11-14
ftp-0.17-7
ftpcopy-0.3.4-1
gaim-0.11.0pre4-2
gal-0.4.1-3
gal-devel-0.4.1-3
gawk-3.0.6-1
gcc-2.96-81
gcc-c++-2.96-81
gcc-chill-2.96-81
gcc-g77-2.96-81
gcc-java-2.96-81
gcc-objc-2.96-81
gd-1.8.3-7
gdb-5.0rh-5
gdbm-1.8.0-5
gdbm-devel-1.8.0-5
gd-devel-1.8.3-7
gdk-pixbuf-0.8.0-7
gdk-pixbuf-devel-0.8.0-7
gd-progs-1.8.3-7
gedit-0.9.4-3
genromfs-0.3-7
gettext-0.10.35-31
gftp-2.0.7b-3
ghostscript-5.50-17
ghostscript-fonts-5.50-3
giftrans-1.12.2-8
gimp-1.2.1-5
gimp-data-extras-1.2.0-1
gimp-devel-1.2.1-5
gimp-perl-1.2.1-5
gkermit-1.0-8
glade-0.5.9-5
glib10-1.0.6-9
glib-1.2.9-1
glibc-2.2.2-10
glibc-common-2.2.2-10
glibc-devel-2.2.2-10
glibc-profile-2.2.2-10
glib-devel-1.2.9-1
glib-gtkbeta-1.3.2-2
glib-gtkbeta-devel-1.3.2-2
gmp-3.1.1-3
gmp-devel-3.1.1-3
gnome-audio-1.0.0-12
gnome-audio-extra-1.0.0-12
gnome-core-1.2.4-16
gnome-core-devel-1.2.4-16
gnome-games-1.2.0-10
gnome-games-devel-1.2.0-10
gnome-libs-1.2.8-11
gnome-libs-devel-1.2.8-11
gnome-linuxconf-0.64-1
gnome-lokkit-0.43-6
gnome-media-1.2.0-12
gnome-objc-1.0.2-11
gnome-objc-devel-1.0.2-11
gnome-pim-1.2.0-9
gnome-pim-devel-1.2.0-9
gnome-print-0.25-9
gnome-print-devel-0.25-9
gnome-users-guide-1.2-3
gnome-utils-1.2.1-5
gnorpm-0.96-1
gnumeric-0.61-9
gnumeric-devel-0.61-9
gnupg-1.0.4-11
gnuplot-3.7.1-12
gperf-2.7-9
gphoto-0.4.3-10
gpm-1.19.3-16
gpm-devel-1.19.3-16
gq-0.4.0-2
grep-2.4.2-5
groff-1.16.1-7
groff-gxditview-1.16.1-7
groff-perl-1.16.1-7
gsl-0.7-2
gsm-1.0.10-2
gsm-devel-1.0.10-2
gtk+10-1.0.6-9
gtk+-1.2.9-4
gtk+-devel-1.2.9-4
gtk-doc-0.4b1-3
gtk-engines-0.10-12
gtk+-gtkbeta-1.3.2-4
gtk+-gtkbeta-devel-1.3.2-4
gtop-1.0.11-3
guile-1.3.4-12
guile-devel-1.3.4-12
gv-3.5.8-11
gzip-1.3-12
hdparm-3.9-6
hotplug-2001_02_14-15
htdig-3.2.0-0.b3.4
htdig-web-3.2.0-0.b3.4
htmlview-1.1.0-2
ical-2.2-21
im-140-3
ImageMagick-5.2.7-2
ImageMagick-c++-5.2.7-2
ImageMagick-c++-devel-5.2.7-2
ImageMagick-devel-5.2.7-2
imap-devel-2000-9
imlib-1.9.8.1-2
imlib-cfgeditor-1.9.8.1-2
imlib-devel-1.9.8.1-2
indent-2.2.6-1
indexhtml-7.1-2
inews-2.3.1-2
info-4.0-20
initscripts-5.83-1
inn-2.3.1-2
inn-devel-2.3.1-2
internet-config-0.40-1
Inti-0.6preview-1
Inti-devel-0.6preview-1
ipchains-1.3.10-7
iproute-2.2.4-10
iptables-1.2.1a-1
iptables-ipv6-1.2.1a-1
iputils-20001110-1
ipxutils-2.2.0.18-3
ircii-4.4Z-4
irda-utils-0.9.13-7
isapnptools-1.22-2
isdn4k-utils-3.1-39
isicom-1.0-5
itcl-3.1.0-53
jadetex-3.3-1
jed-0.99.12-1
jed-common-0.99.12-1
jed-xjed-0.99.12-1
jikes-1.13-1
joe-2.8-44
kaffe-1.0.6-3
kakasi-2.3.2-2
kakasi-devel-2.3.2-2
kakasi-dict-2.3.2-2
kbdconfig-1.9.12-1
kdbg-1.2.0-3
kde1-compat-1.1.2-8
kde1-compat-devel-1.1.2-8
kdebase-2.1.1-8
kdebindings-devel-2.1.1-1
kdegraphics-2.1.1-1
kdelibs-2.1.1-5
kdelibs-devel-2.1.1-5
kdelibs-sound-2.1.1-5
kdelibs-sound-devel-2.1.1-5
kdemultimedia-2.1.1-1
kdenetwork-2.1.1-1
kdenetwork-ppp-2.1.1-1
kdepim-2.1.1-1
kdesdk-devel-2.1.1-1
kdesupport-2.1-3
kdesupport-devel-2.1-3
kdeutils-2.1.1-1
kdevelop-1.4.1-2
kdoc-2.1.1-1
kernel-2.4.2-2
kernel-doc-2.4.2-2
kernel-headers-2.4.2-2
kernel-smp-2.4.2-2
kernel-source-2.4.2-2
kpppload-1.04-23
krb5-devel-1.2.2-4
krb5-libs-1.2.2-4
krb5-workstation-1.2.2-4
krbafs-1.0.5-1
krbafs-utils-1.0.5-1
ksconfig-1.2-1
ksymoops-2.4.0-3
kudzu-0.98.10-1
kudzu-devel-0.98.10-1
lam-6.5.1-1
lapack-3.0-9
lapack-man-3.0-9
lclint-2.5q-3
less-358-16
libelf-0.6.4-7
libgal3-0.4.1-3
libgcj-2.96-24
libgcj-devel-2.96-24
libghttp-1.0.8-2
libghttp-devel-1.0.8-2
libglade-0.14-3
libglade-devel-0.14-3
libgnomeprint11-0.25-9
libgtop-1.0.10-3
libgtop-devel-1.0.10-3
libgtop-examples-1.0.10-3
libjpeg6a-6a-7
libjpeg-6b-15
libjpeg-devel-6b-15
libmng-1.0.0-2
libmng-devel-1.0.0-2
libmng-static-1.0.0-2
libodbc++-0.2.2pre4-12
libodbc++-devel-0.2.2pre4-12
libodbc++-qt-0.2.2pre4-12
libogg-1.0beta4-2
libogg-devel-1.0beta4-2
libole2-0.1.7-2
libole2-devel-0.1.7-2
libpcap-0.4-39
libpng-1.0.9-1
libpng-devel-1.0.9-1
libPropList-0.10.1-7
librep-0.13.3-1
librep-devel-0.13.3-1
libstdc++-2.96-81
libstdc++-devel-2.96-81
libtermcap-2.0.8-26
libtermcap-devel-2.0.8-26
libtiff-3.5.5-10
libtiff-devel-3.5.5-10
libtool-1.3.5-8
libtool-libs-1.3.5-8
libungif-4.1.0-7
libungif-devel-4.1.0-7
libungif-progs-4.1.0-7
libunicode-0.4-4
libunicode-devel-0.4-4
libxml10-1.0.0-6
libxml-1.8.10-1
libxml-devel-1.8.10-1
lilo-21.4.4-13
links-0.95-2
linuxconf-1.24r2-10
linuxconf-devel-1.24r2-10
lm_sensors-2.5.5-3
lm_sensors-devel-2.5.5-3
locale_config-0.2-4
lockdev-1.0.0-5
lockdev-devel-1.0.0-5
logrotate-3.5.4-1
lokkit-0.43-6
losetup-2.10r-5
lout-3.17-7
lout-doc-3.17-7
LPRng-3.7.4-22
lrzsz-0.12.20-7
lslk-1.25-4
lsof-4.51-1
ltrace-0.3.10-5
lv-4.49.4-1
lynx-2.8.4-9
m4-1.4.1-4
macutils-2.0b3-16
magicdev-0.3.5-3
mailcap-2.1.4-2
mailx-8.1.1-20
make-3.79.1-5
MAKEDEV-3.1.0-14
man-1.5h1-20
man-pages-1.35-5
man-pages-cs-0.14-2
man-pages-da-0.1.1-2
man-pages-de-0.2-7
man-pages-es-0.6a-7
man-pages-fr-0.9-3
man-pages-it-0.3.0-6
man-pages-pl-0.22-6
man-pages-ru-0.6-2
mawk-1.3.3-6
mc-4.5.51-32
memprof-0.4.1-3
Mesa-3.4-13
Mesa-demos-3.4-13
Mesa-devel-3.4-13
metamail-2.7-27
mikmod-3.1.6-10
mingetty-0.9.4-16
minicom-1.83.1-5
mkbootdisk-1.4.2-1
mkinitrd-3.0.10-1
mkisofs-1.9-6
mkkickstart-2.3-1
mktemp-1.5-8
mkxauth-1.7-15
mod_dav-1.0.2-4
modemtool-1.22-3
mod_perl-1.24_01-2
mod_ssl-2.8.1-5
modutils-2.4.2-5
mount-2.10r-5
mouseconfig-4.21-1
mozilla-0.7-15
mozilla-devel-0.7-15
mozilla-mail-0.7-15
mozilla-psm-0.7-15
mpage-2.5.1-5
mpg123-0.59r-10
mtools-3.9.7-4
mtr-0.42-8
mtr-gtk-0.42-8
mt-st-0.5b-10
mtx-1.2.10-1
multimedia-2.1-21
mutt-1.2.5i-9
mysql-3.23.36-1
mysqlclient9-3.23.22-4
mysql-devel-3.23.36-1
mysql-server-3.23.36-1
nasm-0.98-6
nasm-doc-0.98-6
nasm-rdoff-0.98-6
nc-1.10-10
ncftp-3.0.2-1
ncompress-4.2.4-21
ncpfs-2.2.0.18-3
ncurses4-5.0-2
ncurses-5.2-8
ncurses-devel-5.2-8
netcfg-2.36-3
netpbm-9.9-5
netpbm-devel-9.9-5
netpbm-progs-9.9-5
netscape-common-4.76-11
netscape-communicator-4.76-11
netscape-navigator-4.76-11
net-tools-1.57-6
newt-0.50.22-2
newt-devel-0.50.22-2
nfs-utils-0.3.1-5
njamd-0.8.0-3
nkf-1.92-4
nmh-1.0.4-8
nscd-2.2.2-10
nss_db-2.2-3
nss_db-compat-2.2-3
nss_ldap-149-1
ntsysv-1.2.22-1
nut-0.44.1-5
nut-cgi-0.44.1-5
nut-client-0.44.1-5
nvi-m17n-nocanna-1.79-19991117.6
octave-2.1.33-2
open-1.4-11
openjade-1.3-13
openldap12-1.2.11-4
openldap-2.0.7-14
openldap-clients-2.0.7-14
openldap-devel-2.0.7-14
openldap-servers-2.0.7-14
openssh-2.5.2p2-5
openssh-askpass-2.5.2p2-5
openssh-askpass-gnome-2.5.2p2-5
openssh-clients-2.5.2p2-5
openssh-server-2.5.2p2-5
openssl095a-0.9.5a-1
openssl-0.9.6-3
openssl-devel-0.9.6-3
openssl-perl-0.9.6-3
openssl-python-0.9.6-3
ORBit-0.5.7-3
ORBit-devel-0.5.7-3
p2c-1.22-8
p2c-devel-1.22-8
pam-0.74-22
pam-devel-0.74-22
pam_krb5-1.31-1
pan-0.9.5-1
pango-gtkbeta-0.13-4
pango-gtkbeta-devel-0.13-4
parted-1.4.7-2
parted-devel-1.4.7-2
passwd-0.64.1-4
patch-2.5.4-9
pciutils-2.1.8-19
pciutils-devel-2.1.8-19
pdksh-5.2.14-12
perl-5.6.0-12
perl-DBD-MySQL-1.2215-1
perl-DBD-Pg-0.95-1
perl-DBI-1.14-10
perl-Perl-RPM-0.291-2
perl-SGMLSpm-1.03ii-4
php-4.0.4pl1-9
php-devel-4.0.4pl1-9
php-imap-4.0.4pl1-9
php-ldap-4.0.4pl1-9
php-manual-4.0.4pl1-9
php-mysql-4.0.4pl1-9
php-pgsql-4.0.4pl1-9
pidentd-3.0.12-4
pilot-link-0.9.5-2
pilot-link-devel-0.9.5-2
pine-4.33-8
pinfo-0.6.0-4
pkgconfig-0.5.0-1
playmidi-2.4-12
playmidi-X11-2.4-12
plugger-3.2-9
pmake-1.45-1
pnm2ppa-1.04-1
popt-1.6.2-8
portmap-4.0-35
postgresql-7.0.3-8
postgresql-devel-7.0.3-8
postgresql-jdbc-7.0.3-8
postgresql-odbc-7.0.3-8
postgresql-perl-7.0.3-8
postgresql-python-7.0.3-8
postgresql-server-7.0.3-8
postgresql-tcl-7.0.3-8
postgresql-tk-7.0.3-8
ppp-2.4.0-2
printconf-0.2.12-1
printconf-gui-0.2.12-1
procinfo-17-10
procmail-3.14-6
procps-2.0.7-8
procps-X11-2.0.7-8
psacct-6.3.2-5
psgml-1.2.1-13
psmisc-19-4
pspell-0.11.2-2
pspell-devel-0.11.2-2
psutils-1.17-10
pump-0.8.11-1
pump-devel-0.8.11-1
pvm-3.4.3-27
pvm-gui-3.4.3-27
pwdb-0.61.1-1
pygnome-1.0.53-7
pygnome-applet-1.0.53-7
pygnome-capplet-1.0.53-7
pygnome-libglade-0.6.6-7
pygtk-0.6.6-7
pygtk-libglade-0.6.6-7
python-1.5.2-30
python-devel-1.5.2-30
python-docs-1.5.2-30
pythonlib-1.28-1
python-tools-1.5.2-30
python-xmlrpc-1.4-1
qt1x-1.45-12
qt1x-devel-1.45-12
qt1x-GL-1.45-12
qt-2.3.0-3
qt-designer-2.3.0-3
qt-devel-2.3.0-3
qt-static-2.3.0-3
qt-Xt-2.3.0-3
quota-3.00-4
raidtools-0.90-20
rcs-5.7-14
rdate-1.0-7
rdist-6.1.5-14
readline2.2.1-2.2.1-2
readline-4.1-9
readline-devel-4.1-9
redhat-logos-1.1.2-3
redhat-release-7.1-1
reiserfs-utils-3.x.0f-1
rep-gtk-0.15-3
rep-gtk-gnome-0.15-3
rep-gtk-libglade-0.15-3
rgrep-0.99.12-1
rhmask-1.0-9
rhn_register-1.3.1-1
rhn_register-gnome-1.3.1-1
rmt-0.4b21-3
rootfiles-7.0-4
rp3-1.1.10-1
rpm2html-1.5-4
rpm-4.0.2-8
rpm-build-4.0.2-8
rpmdb-redhat-7.1-0.20010408
rpm-devel-4.0.2-8
rpmfind-1.6-5
rpmlint-0.28-2
rpm-python-4.0.2-8
rp-pppoe-2.6-5
rsh-0.17-2.5
rsh-server-0.17-2.5
rsync-2.4.6-2
rusers-0.17-10
rusers-server-0.17-10
rwall-server-0.17-9
rwho-0.17-10
rxvt-2.7.5-15
samba-2.0.7-36
samba-client-2.0.7-36
samba-common-2.0.7-36
samba-swat-2.0.7-36
sane-1.0.3-10
sane-devel-1.0.3-10
sash-3.4-8
sawfish-0.36-7
screen-3.9.8-3
SDL-1.1.7-3
SDL-devel-1.1.7-3
SDL_image-1.1.0-1
SDL_image-devel-1.1.0-1
SDL_mixer-1.1.0-2
SDL_mixer-devel-1.1.0-2
sed-3.02-9
semi-1.13.7-9
sendmail-8.11.2-14
sendmail-cf-8.11.2-14
sendmail-doc-8.11.2-14
setserial-2.17-2
setup-2.4.7-1
setuptool-1.7-2
sgml-common-0.5-5
sgml-tools-1.0.9-9
shadow-utils-20000826-4
shapecfg-2.2.12-5
sharutils-4.2.1-7
sh-utils-2.0-13
skkdic-20010122-2
slang-1.4.2-2
slang-devel-1.4.2-2
slocate-2.5-5
slrn-0.9.6.4-2
slrn-pull-0.9.6.4-2
smpeg-0.4.2-2
smpeg-devel-0.4.2-2
smpeg-xmms-0.3.3-1
sndconfig-0.64.8-1
sox-12.17.1-2
sox-devel-12.17.1-2
stat-2.2-2
statserial-1.1-20
strace-4.2.20010119-3
stunnel-3.13-3
sudo-1.6.3p6-1
switchdesk-3.9.5-1
symlinks-1.2-11
sysctlconfig-0.13-1
sysklogd-1.4-7
syslinux-1.52-1
sysreport-1.2-1
sysstat-3.3.5-3
SysVinit-2.78-15
talk-0.17-9
talk-server-0.17-9
tamago-4.0.6-4
taper-6.9b-3
tar-1.13.19-4
tcl-8.3.1-53
tcllib-0.4-53
tclx-8.2.0-53
tcpdump-3.4-39
tcp_wrappers-7.6-18
tcsh-6.10-5
telnet-0.17-10
telnet-server-0.17-10
termcap-11.0.1-8
tetex-1.0.7-15
tetex-afm-1.0.7-15
tetex-doc-1.0.7-15
tetex-dvilj-1.0.7-15
tetex-dvips-1.0.7-15
tetex-fonts-1.0.7-15
tetex-latex-1.0.7-15
tetex-xdvi-1.0.7-15
texinfo-4.0-20
textutils-2.0.11-7
tftp-0.17-9
time-1.7-13
timeconfig-3.2-1
timetool-2.8-1
timidity++-2.10.3-0.a2.3
tix-4.1.0.6-53
tk-8.3.1-53
tkinter-1.5.2-30
tksysv-1.3-2
tmpwatch-2.7.1-1
traceroute-1.4a5-25
transfig-3.2.3c-2
tree-1.2-11
tripwire-2.3.0-58
tux-2.0.26-1
ucd-snmp-4.2-12
ucd-snmp-devel-4.2-12
ucd-snmp-utils-4.2-12
umb-scheme-3.2-18
unarj-2.43-6
units-1.55-9
unix2dos-2.2-11
unixODBC-1.8.13-2
unixODBC-devel-1.8.13-2
unixODBC-kde-1.8.13-2
unzip-5.41-3
up2date-2.5.2-1
up2date-gnome-2.5.2-1
urlview-0.9-2
urw-fonts-2.0-12
usbview-1.0-1
usermode-1.42-1
utempter-0.5.2-4
util-linux-2.10s-12
uucp-1.06.1-26
VFlib2-2.25.1-12
VFlib2-devel-2.25.1-12
VFlib2-VFjfm-2.25.1-12
vim-common-6.0-0.27
vim-enhanced-6.0-0.27
vim-minimal-6.0-0.27
vim-X11-6.0-0.27
vixie-cron-3.0.1-62
vlock-1.3-5
vorbis-1.0beta4-3
vorbis-devel-1.0beta4-3
w3c-libwww-5.2.8-6
w3c-libwww-apps-5.2.8-6
w3c-libwww-devel-5.2.8-6
watanabe-vf-1.0-5
wget-1.6-2
which-2.12-1
whois-1.0.6-1
WindowMaker-libs-0.64.0-2
wireless-tools-20-4
Wnn6-SDK-1.0-10
Wnn6-SDK-devel-1.0-10
words-2-16
wu-ftpd-2.6.1-16
wvdial-1.41-12
x3270-text-3.2.14-1
Xaw3d-1.5-9
Xaw3d-devel-1.5-9
xcdroast-0.98a8-2
xchat-1.6.3-4
Xconfigurator-4.9.27-1
xcpustate-2.5-9
xdelta-1.1.1-7
xdelta-devel-1.1.1-7
xemacs-21.1.14-10
xemacs-el-21.1.14-10
xemacs-info-21.1.14-10
xfig-3.2.3c-8
XFree86-100dpi-fonts-4.0.3-5
XFree86-4.0.3-5
XFree86-75dpi-fonts-4.0.3-5
XFree86-devel-4.0.3-5
XFree86-doc-4.0.3-5
XFree86-libs-4.0.3-5
XFree86-SVGA-3.3.6-35
XFree86-tools-4.0.3-5
XFree86-twm-4.0.3-5
XFree86-xdm-4.0.3-5
XFree86-xfs-4.0.3-5
xinetd-2.1.8.9pre14-6
xinitrc-3.6-1
xisdnload-1.38-39
xlispstat-3.52.18-2
xloadimage-4.1-16
xmailbox-2.5-12
xmms-1.2.4-13
xmms-devel-1.2.4-13
xmms-gnome-1.2.4-13
xosview-1.7.3-4
xpaint-2.6.1-1
xpdf-0.92-3
xrn-9.02-8
xsane-0.62-4
xsane-gimp-0.62-4
xscreensaver-3.29-3
xsri-1.0-8
xsysinfo-1.7-3
xtoolwait-1.2-5
xtt-fonts-0.19990222-9
ypbind-1.7-6
ypserv-1.3.11-13
yp-tools-2.4-7
ytalk-3.1.1-5
zip-2.3-8
zlib-1.1.3-22
zlib-devel-1.1.3-22
zsh-3.0.8-8
</PackageList>

<Filesystem>
  Filesystem Size Used Avail Use% Mounted on
  /dev/hda9 5.5G 99M 5.0G 2% /
  /dev/hda1 53M 7.8M 42M 16% /boot
  /dev/hda5 9.6G 92k 9.1G 1% /home
  /dev/hde1 19G 20k 17G 1% /opt
  /dev/hda11 486M 445k 460M 1% /tmp
  /dev/hda7 4.8G 2.0G 2.5G 44% /usr
  /dev/hda6 4.8G 96k 4.5G 1% /usr/local
  /dev/hda8 4.8G 49M 4.5G 2% /var
</Filesystem>

<ifconfig>
eth0      Link encap:Ethernet  HWaddr 00:E0:7D:9F:FE:CE
          inet addr:10.99.99.184  Bcast:10.255.255.255  Mask:255.0.0.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:203855 errors:2 dropped:0 overruns:0 frame:0
          TX packets:8560 errors:0 dropped:0 overruns:0 carrier:0
          collisions:101 txqueuelen:100
          Interrupt:11 Base address:0xaf00

lo        Link encap:Local Loopback
          inet addr:127.0.0.1  Mask:255.0.0.0
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:58 errors:0 dropped:0 overruns:0 frame:0
          TX packets:58 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
</ifconfig>

<route>
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use
Iface
10.0.0.0        0.0.0.0         255.0.0.0       U     0      0        0 eth0
127.0.0.0       0.0.0.0         255.0.0.0       U     0      0        0 lo
0.0.0.0         10.0.0.1        0.0.0.0         UG    0      0        0 eth0
</route>

In Principal:
Download latest update packages from redhat
Update Base Packages for kernel update
Download kernel source from www.kernel.org
Install or update required packeges (see Kernel Description)
Do:
extract kernal from tarball
mv linux linux.version
make oldconfig
make menuconfig
make dep
make
make modules
make modules_install
make install
vi /etc/lilo.conf
<BOF file="lilo.conf">
boot=/dev/hda
map=/boot/map
install=/boot/boot.b
prompt
timeout=5
message=/boot/message
linear
default=new

image=/boot/vmlinuz-2.4.12
label=new
read-only
root=/dev/hda1

image=/boot/vmlinuz-2.2.16-22
label=old
read-only
root=/dev/hda1
<EOF file="lilo.conf">
lilo
reboot
In Detail:
download full source of kernel from www.kernel.org using lynx

$ lynx http://www.kernel.org

extract to /home/root/update/linux-2.4.19:
$ tar xzvf linux-2.4.19.tar.gz # extracts to ./linux-2.4.19 itself; so no
move from ./linux to ./linux-2.4.19 :-)

read README and then Documentation/Changes !! - I mean it!!

download updatepackages from redhat:
$ cd ../i386; wget ftp://updates.redhat.com/7.1/en/os/i386/* # maybe we have
a updateset downloaded anywhere already?
$ cd ../i686; wget ftp://updates.redhat.com/7.1/en/os/i686/* # maybe we have
a updateset downloaded anywhere already?
$ cd ../noarch; wget ftp://updates.redhat.com/7.1/en/os/noarch/* # maybe we
have a updateset downloaded anywhere already?

## note: usualy I remove each package after installing; first I copy them
all anywhere to restore ...
## I do note protocol rm {packagename} here ...

## start to update noarch packages
cd ../noarch
[root@localhost /home/root/update/PACKS/redhat/noarch]# rpm -Uvh
filesystem-2.1.0-2.1.noarch.rpm
Preparing... ########################################### [100%]
1:filesystem ########################################### [100%]
error: cannot remove /var/lib/rpm - directory not empty
[root@localhost /home/root/update/PACKS/redhat/noarch]# rpm -Uvh
filesystem-2.1.0-2.1.noarch.rpm --force
Preparing... ########################################### [100%]
1:filesystem ########################################### [100%]

[root@localhost /home/root/update/PACKS/redhat/noarch]# rpm -Uvh
xinitrc-3.20-1.noarch.rpm docbook-* --force
Preparing... ########################################### [100%]
1:xinitrc ########################################### [ 25%]
2:docbook-style-dsssl ########################################### [ 50%]
3:docbook-utils ########################################### [ 75%]
4:docbook-utils-pdf ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/noarch]#


## update i386 packages

[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh
SysVinit-2.78-17.i386.rpm
Preparing... ########################################### [100%]
1:SysVinit ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh
initscripts-5.84.1-1.i386.rpm
Preparing... ########################################### [100%]
1:initscripts ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh
modutils-2.4.13-0.7.1.i386.rpm mkinitrd-3.2.6-1.i386.rpm
Preparing... ########################################### [100%]
1:modutils ########################################### [ 50%]
2:mkinitrd ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]#


## to update gcc first update from i686

[root@localhost /home/root/update/PACKS/redhat/i686]# rpm -Uvh
glibc-2.2.4-30.i686.rpm --force --nodeps
Preparing... ########################################### [100%]
1:glibc ########################################### [100%]


## and now the rest from i386

[root@localhost /home/root/update/PACKS/redhat/i386]# rm
glibc-2.2.4-30.i386.rpm
[root@localhost /home/root/update/PACKS/redhat/i386]# ls glibc-
glibc-common-2.2.4-30.i386.rpm glibc-devel-2.2.4-30.i386.rpm
glibc-profile-2.2.4-30.i386.rpm
[root@localhost /home/root/update/PACKS/redhat/i386]# rom -Uvh
glibc-* --nodeps --force
bash: rom: command not found
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh
glibc-* --nodeps --force
Preparing... ########################################### [100%]
1:glibc-common ########################################### [ 33%]
2:glibc-devel ########################################### [ 66%]
3:glibc-profile ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh
gcc-* --nodeps --force
Preparing... ########################################### [100%]
1:gcc ########################################### [ 16%]
2:gcc-c++ ########################################### [ 33%]
3:gcc-chill ########################################### [ 50%]
4:gcc-g77 ########################################### [ 66%]
5:gcc-java ########################################### [ 83%]
6:gcc-objc ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh
libstdc++-* --force --nodeps
Preparing... ########################################### [100%]
1:libstdc++ ########################################### [ 50%]
2:libstdc++-devel ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh
cpp-2.96-85.i386.rpm
Preparing... ########################################### [100%]
1:cpp ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh lib*
Preparing... ########################################### [100%]
1:libgcj ########################################### [ 20%]
2:libgcj-devel ########################################### [ 40%]
3:libpcap ########################################### [ 60%]
4:libpng ########################################### [ 80%]
5:libpng-devel ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh e2fsprogs-*
Preparing... ########################################### [100%]
1:e2fsprogs ########################################### [ 50%]
2:e2fsprogs-devel ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh
devfsd-2.4.3-12.i386.rpm diffutils-2.7-23.i386.rpm
dump-0.4b25-1.71.0.i386.rpm
Preparing... ########################################### [100%]
1:devfsd ########################################### [ 33%]
2:diffutils ########################################### [ 66%]
3:dump ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh
xinetd-2.3.3-1.i386.rpm
Preparing... ########################################### [100%]
1:xinetd ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh zlib-*
Preparing... ########################################### [100%]
1:zlib ########################################### [ 50%]
2:zlib-devel ########################################### [100%]
[root@localhost /home/root/update/PACKS/redhat/i386]# rpm -Uvh
mount-2.11b-3.i386.rpm
Preparing... ########################################### [100%]
1:mount ########################################### [100%]


### we are ready to check needed packages by kernel description
### see Documention/Changes

installed (

rpm -Uvh jfsutils-1.0.17-3.i386.rpm
rpm -Uvh reiserfsprogs-3.x.1b-1.i386.rpm
rpm -Uvh ksymoops-2.4.5-1.i386.rpm

) by check of versions without troubles

now lets compile the kernel ...

$ cd /home/root/update/linux-2.4.19

$ make mrproper

$ make oldconfig

$ make menuconfig (altered some switches; than exit with saving)
   to see your hardware make a dmesg 2>&1|less

$ make dep
(produces a lot of compile output)

$ make
(produces more compile output and ens with something like:

gcc -D__ASSEMBLY__ -D__KERNEL__ -I/home/root/update/linux-2.4.19/include -c
getuser.S -o getuser.o
gcc -D__KERNEL__ -I/home/root/update/linux-2.4.19/include -Wall -Wstrict-pro
totypes -Wno-trigraphs -O2 -fno-strict-aliasing -fno-common -fomit-frame-poi
nter -pipe -mpreferred-stack-boundary=2 -march=i686 -nostdinc -I
/usr/lib/gcc-lib/i386-redhat-linux/2.96/include -DKBUILD_BASENAME=memcpy -c 
-o memcpy.o memcpy.c
gcc -D__KERNEL__ -I/home/root/update/linux-2.4.19/include -Wall -Wstrict-pro
totypes -Wno-trigraphs -O2 -fno-strict-aliasing -fno-common -fomit-frame-poi
nter -pipe -mpreferred-stack-boundary=2 -march=i686 -nostdinc -I
/usr/lib/gcc-lib/i386-redhat-linux/2.96/include -DKBUILD_BASENAME=strstr -c 
-o strstr.o strstr.c
rm -f lib.a
ar rcs lib.a checksum.o old-checksum.o delay.o usercopy.o getuser.o memcpy.o
strstr.o
make[2]: Leaving directory `/home/root/update/linux-2.4.19/arch/i386/lib'
make[1]: Leaving directory `/home/root/update/linux-2.4.19/arch/i386/lib'
ld -m elf_i386 -T /home/root/update/linux-2.4.19/arch/i386/vmlinux.lds -e
stext arch/i386/kernel/head.o arch/i386/kernel/init_task.o init/main.o
init/version.o init/do_mounts.o \
--start-group \
arch/i386/kernel/kernel.o arch/i386/mm/mm.o kernel/kernel.o mm/mm.o fs/fs.o
ipc/ipc.o \
drivers/char/char.o drivers/block/block.o drivers/misc/misc.o
drivers/net/net.o drivers/media/media.o drivers/char/agp/agp.o
drivers/char/drm/drm.o drivers/ide/idedriver.o drivers/scsi/scsidrv.o
drivers/cdrom/driver.o drivers/pci/driver.o drivers/pnp/pnp.o
drivers/video/video.o drivers/usb/usbdrv.o \
net/network.o \
/home/root/update/linux-2.4.19/arch/i386/lib/lib.a
/home/root/update/linux-2.4.19/lib/lib.a
/home/root/update/linux-2.4.19/arch/i386/lib/lib.a \
--end-group \
-o vmlinux
nm vmlinux | grep -v '\(compiled\)\|\(\.o$\)\|\( [aUw]
\)\|\(\.\.ng$\)\|\(LASH[RL]DI\)' | sort > System.map


)

so next

$ make modules
(produces a lot of output again - do not care so much - ends with something
like

make[1]: Entering directory `/home/root/update/linux-2.4.19/arch/i386/lib'
make[1]: Nothing to be done for `modules'.
make[1]: Leaving directory `/home/root/update/linux-2.4.19/arch/i386/lib'
)

$ make modules_install
(with output again ..)

$ make install
(... to get a lot of output ending with something like:

gcc -Wall -Wstrict-prototypes -O2 -fomit-frame-pointer -o tools/build
tools/build.c -I/home/root/update/linux-2.4.19/include
objcopy -O binary -R .note -R .comment -S compressed/bvmlinux
compressed/bvmlinux.out
tools/build -b bbootsect bsetup compressed/bvmlinux.out CURRENT > bzImage
Root device is (3, 9)
Boot sector 512 bytes.
Setup is 2536 bytes.
System is 1304 kB
warning: kernel is too big for standalone boot from floppy
sh -x ./install.sh 2.4.19 bzImage /home/root/update/linux-2.4.19/System.map
""
+ '[' -x /root/bin/installkernel ']'
+ '[' -x /sbin/installkernel ']'
+ exec /sbin/installkernel 2.4.19 bzImage
/home/root/update/linux-2.4.19/System.map ''
Added linux *
Added linux-up
make[1]: Leaving directory `/home/root/update/linux-2.4.19/arch/i386/boot'
)

==================
edit /etc/lilo.conf
==================

<file name="/etc/lilo.conf" version="old">

boot=/dev/hda
map=/boot/map
install=/boot/boot.b
prompt
timeout=50
message=/boot/message
linear
default=linux

image=/boot/vmlinuz-2.4.2-2smp
                   label=linux
                   initrd=/boot/initrd-2.4.2-2smp.img
                   read-only
                   root=/dev/hda9

image=/boot/vmlinuz-2.4.2-2
                   label=linux-up
                   initrd=/boot/initrd-2.4.2-2.img
                   read-only
                   root=/dev/hda9


</file>
<file name="/etc/lilo.conf" version="new">

boot=/dev/hda
map=/boot/map
install=/boot/boot.b
prompt
timeout=50
message=/boot/message
linear
default=2_4_19

image=/boot/vmlinuz-2.4.19
                   label=2_4_19
                   read-only
                   root=/dev/hda9

image=/boot/vmlinuz-2.4.2-2smp
                   label=2_4_2
                   initrd=/boot/initrd-2.4.2-2smp.img
                   read-only
                   root=/dev/hda9

image=/boot/vmlinuz-2.4.2-2
                   label=linux-up
                   initrd=/boot/initrd-2.4.2-2.img
                   read-only
                   root=/dev/hda9


</file>

and final:

$ lilo -v -v
(to get as a output e.g:

LILO version 21.4-4, Copyright (C) 1992-1998 Werner Almesberger
'lba32' extensions Copyright (C) 1999,2000 John Coffman

Reading boot sector from /dev/hda
Merging with /boot/boot.b
Secondary loader: 11 sectors.
Mapping message file /boot/message
Message: 46 sectors.
Boot image: /boot/vmlinuz-2.4.19
Setup length is 5 sectors.
Mapped 2618 sectors.
Added 2_4_19 *
Boot image: /boot/vmlinuz-2.4.2-2smp
Setup length is 10 sectors.
Mapped 1645 sectors.
Mapping RAM disk /boot/initrd-2.4.2-2smp.img
RAM disk: 723 sectors.
Added 2_4_2
Boot image: /boot/vmlinuz-2.4.2-2
Setup length is 10 sectors.
Mapped 1529 sectors.
Mapping RAM disk /boot/initrd-2.4.2-2.img
RAM disk: 720 sectors.
Added linux-up
/boot/boot.0300 exists - no backup copy made.
Map file size: 44544 bytes.
Writing boot sector.


)
$ reboot

*** oh yes - that worked!! running kernel is now: 2.4.19

next step - upgrade iptables

=================================
IPTABLES
=================================

Protocol eines iptables updates

Usefuls Links:

http://www.iptables.org

Base informations

Let's start

first download the package. I prefer to look with a browser for the download
link on my workstation and than doing:

[root@devprak other]# wget
http://www.iptables.org/files/iptables-1.2.7a.tar.bz2
   --16:30:14-- http://www.iptables.org/files/iptables-1.2.7a.tar.bz2
   => `iptables-1.2.7a.tar.bz2'
   Connecting to www.iptables.org:80... connected!
   HTTP request sent, awaiting response... 200 OK
   Length: 118,127 [application/x-tar]
 0K -> .......... .......... .......... .......... .......... [ 43%]
   50K -> .......... .......... .......... .......... .......... [ 86%]
   100K -> .......... ..... [100%]
16:30:15 (354.95 KB/s) - `iptables-1.2.7a.tar.bz2' saved [118127/118127]

oh, a bz2 package :) .. make a normal tar package:

[root@devprak iptables-1.2.7a]# bzip2 -d ../other/iptables-1.2.7a.tar.bz2

and untar it:

[root@devprak PACKS]# tar xvf other/iptables-1.2.7a.tar
[root@devprak PACKS]# cd iptables-1.2.7a/
[root@devprak iptables-1.2.7a]# vi INSTALL # READ IT!! - I mean it!


its easy - the only thing to do is to set the KERNEL_DIR in the Makefile and
do a make
but - uups first patch the kernel; so download the patch from
ftp://ftp.netfilter.org/pub/patch-o-matic/

so login should work always with user anonymous and your email-adress as a
apssword

[root@devprak iptables-1.2.7a]# ftp ftp.netfilter.org
Connected to ftp.netfilter.org.
220 ProFTPD 1.2.5rc1 Server (netfilter/iptables FTP site) [kashyyyk]
504 AUTH GSSAPI unsupported
504 AUTH KERBEROS_V4 unsupported
KERBEROS_V4 rejected as an authentication type
Name (ftp.netfilter.org:root): anonymous
331 Anonymous login ok, send your complete email address as your password.
Password:
230 Anonymous access granted, restrictions apply.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> cd /pub
250 CWD command successful.
ftp> cd patch-o-matic
250 CWD command successful.
ftp> ls
227 Entering Passive Mode (62,128,28,62,198,172).
150 Opening ASCII mode data connection for file list
drwxr-xr-x 2 ftpuser ftpgroup 4096 Aug 26 12:33 broken
-rw-r--r-- 1 ftpuser ftpgroup 207501 Aug 26 12:33
patch-o-matic-20020825.tar.bz2
-rw-r--r-- 1 ftpuser ftpgroup 65 Aug 26 12:34
patch-o-matic-20020825.tar.bz2.md5sum
-rw-r--r-- 1 ftpuser ftpgroup 65 Aug 26 12:33
patch-o-matic-20020825.tar.bz2.sig
drwxr-xr-x 2 ftpuser ftpgroup 8192 Oct 8 21:55 snapshot
226-Transfer complete.
226 Quotas off
ftp> prompt
Interactive mode off.
ftp> mget patch*
local: patch-o-matic-20020825.tar.bz2 remote: patch-o-matic-20020825.tar.bz2
227 Entering Passive Mode (62,128,28,62,199,241).
150 Opening BINARY mode data connection for patch-o-matic-20020825.tar.bz2
(207501 bytes).
226 Transfer complete.
207501 bytes received in 0.58 seconds (3.5e+02 Kbytes/s)
local: patch-o-matic-20020825.tar.bz2.md5sum remote:
patch-o-matic-20020825.tar.bz2.md5sum
227 Entering Passive Mode (62,128,28,62,199,252).
150 Opening BINARY mode data connection for
patch-o-matic-20020825.tar.bz2.md5sum (65 bytes).
226 Transfer complete.
65 bytes received in 0.014 seconds (4.5 Kbytes/s)
local: patch-o-matic-20020825.tar.bz2.sig remote:
patch-o-matic-20020825.tar.bz2.sig
227 Entering Passive Mode (62,128,28,62,199,254).
150 Opening BINARY mode data connection for
patch-o-matic-20020825.tar.bz2.sig (65 bytes).
226 Transfer complete.
65 bytes received in 0.0011 seconds (59 Kbytes/s)
ftp> bye
221 Goodbye.
[root@devprak iptables-1.2.7a]#
[root@devprak iptables-1.2.7a]# mkdir PATCH-O-MATIC
[root@devprak iptables-1.2.7a]# mv patch-o-ma* PATCH-O-MATIC/.
[root@devprak iptables-1.2.7a]# cd PATCH-O-MATIC/
[root@devprak PATCH-O-MATIC]#

and decompress the package:

[root@devprak PATCH-O-MATIC]# cat patch-o-matic-20020825.tar.bz2 | bzip2 -d
| tar -xvf -

[root@devprak PATCH-O-MATIC]# cd patch-o-matic-20020825 # and read the
README file !!

[root@devprak patch-o-matic-20020825]# ./runme pending
KERNEL_DIR=/home/root/update/linux-2.4.19

hoops there is bug - ./runme won't accept KERNEL_DIR as a parameter. after
looking into runme let's do:

[root@devprak patch-o-matic-20020825]# export
KERNEL_DIR=/home/root/update/linux-2.4.19
[root@devprak patch-o-matic-20020825]# ./runme pending

... and that works now.
I only can advise you: read every question carefully. Take care of your
current kernel version to decide wether you want take a patch or not. always
test a patch before apply to see if it works. Enter '?' for the first time
to see your possibilities.
I prefere to apply only with status "pending for inclusion" or similiar
ones. I ommit those with status "works for me". However, always read the
status of a patch. so before pressnig 'y' meaning yes to apply simple press
't' meaning test. you MUST get "applied cleanly" by testing.
Good luck! (its difficult to fail ...*g*)

Last answere is Q to quit after all patches are applied.

And lets recompile the kernel. To do so, first do a

$ make menuconfig

and see into the "Networking options --->" to enable new options in submenue
Netfilter Configuration
ok, new are: ECN, DSCP, ... however, I enable them all.

Lets order the rest on one line:

[root@devprak linux-2.4.19]# make dep; make; make modules; make
modules_install; make install; lilo -v -v; reboot


### so have a little time to taka a coffee or work anything else .... and
return half an hour later.

welcome back! now before doing anything else, you must deinstall old
versions of iptables and ipchains (the installed rpm's)
there is one trick: you must save the current /etc/init.d/iptables script
before deinstalling rpm-packages, because it's important to have:

[root@devprak iptables-1.2.7a]# cd /etc/init.d/
[root@devprak init.d]# ls
anacron gpm isdn mysqld postgresql rwalld tux
apmd halt kdcrotate named pppoe rwhod ups
arpwatch httpd keytable netfs random sendmail xfs
atd identd killall network rawdevices single xinetd
autofs innd kudzu nfs reconfig smb ypbind
crond ipchains ldap nfslock rhnsd snmpd yppasswdd
FreeWnn iptables linuxconf nscd rstatd sshd ypserv
functions irda lpd portmap rusersd syslog
[root@devprak init.d]# cp ip[TAB][TAB]
ipchains iptables
[root@devprak init.d]# cp iptables ~/.
[root@devprak init.d]# rpm -qa | grep iptables
iptables-1.2.1a-1
iptables-ipv6-1.2.1a-1
[root@devprak init.d]# rpm -qa | grep ipchains
ipchains-1.3.10-7
[root@devprak init.d]# rpm -e iptables-1.2.1a-1 iptables-ipv6-1.2.1a-1
ipchains-1.3.10-7
error: removing these packages would break dependencies:
ipchains is needed by lokkit-0.43-6
ipchains is needed by firewall-config-0.95-2
ipchains is needed by gnome-lokkit-0.43-6
[root@devprak init.d]# rpm -e iptables-1.2.1a-1 iptables-ipv6-1.2.1a-1
ipchains-1.3.10-7 lokkit-0.43-6 firewall-config-0.95-2 gnome-lokkit-0.43-6
error: cannot remove /lib/iptables - directory not empty
[root@devprak init.d]# rpm -e iptables-1.2.1a-1 iptables-ipv6-1.2.1a-1
ipchains-1.3.10-7 lokkit-0.43-6 firewall-config-0.95-2
gnome-lokkit-0.43-6 --force
rpm: only installation, upgrading, rmsource and rmspec may be forced
[root@devprak init.d]# cd /home/root/update/iptables-1.2.7a/
[root@devprak init.d]# vi INSTALL
[root@devprak init.d]# export KERNEL_DIR=/home/root/update/linux-2.4.19 #
take a look into the Makefile :)
[root@devprak iptables-1.2.7a]# make
[root@devprak iptables-1.2.7a]# make install
### we have a testmashine; make a:
[root@devprak iptables-1.2.7a]# make install-devel
### well - let's test !
[root@devprak iptables-1.2.7a]# which iptables
/usr/local/sbin/iptables
[root@devprak iptables-1.2.7a]# iptables -L -n -x -v
Chain INPUT (policy ACCEPT 1573 packets, 118493 bytes)
pkts bytes target prot opt in out source destination

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination

Chain OUTPUT (policy ACCEPT 1028 packets, 106511 bytes)
pkts bytes target prot opt in out source destination


############ looks fne - so done! ... But ...

############ now bring it up as a service, and let's write a simple
firewall-script


[root@devprak iptables-1.2.7a]# cd /etc/init.d
[root@devprak init.d]# cp ~/iptables .
[root@devprak init.d]# vi iptables

### why edit the script. simple: because we have compiled from source and so
everything resides in /usr/local/sbin instead /sbin
### i paste the original and the modified shell script here:
### (to do that I say $cat iptables | mail [email protected] ... which is
working without doing anything *g*)

<file name="/etc/init.d/iptables status="original">

#!/bin/sh## Startup script to implement /etc/sysconfig/iptables pre-defined
rules.## chkconfig: 2345 08 92## description: Automates a packet filtering
firewall with iptables.## by [email protected], based on the ipchains script:#
Script Author:	Joshua Jensen <[email protected]>#   -- hacked up by gafton
with help from notting# modified by Anton Altaparmakov <[email protected]>:#
modified by Nils Philippsen <[email protected]>## config:
/etc/sysconfig/iptables
# Source 'em up
. /etc/init.d/functions

IPTABLES_CONFIG=/etc/sysconfig/iptables

if [ ! -x /sbin/iptables ]; then
exit 0
fi

KERNELMAJ=`uname -r | sed -e 's,\..*,,'`
KERNELMIN=`uname -r | sed -e 's,[^\.]*\.,,' -e 's,\..*,,'`

if [ "$KERNELMAJ" -lt 2 ] ; then
exit 0
fi
if [ "$KERNELMAJ" -eq 2 -a "$KERNELMIN" -lt 3 ] ; then
exit 0
fi


if /sbin/lsmod 2>/dev/null |grep -q ipchains ; then
# Don't do both
exit 0
fi

start() {
# don't do squat if we don't have the config file
if [ -f $IPTABLES_CONFIG ]; then
# If we don't clear these first, we might be adding to
# pre-existing rules.
action $"Flushing all current rules and user defined chains:" iptables -F
action $"Clearing all current rules and user defined chains:" iptables -X
chains=`cat /proc/net/ip_tables_names 2>/dev/null`
for i in $chains; do iptables -t $i -F; done && \
success $"Flushing all current rules and user defined chains:" || \
failure $"Flushing all current rules and user defined chains:"
for i in $chains; do iptables -t $i -X; done && \
success $"Clearing all current rules and user defined chains:" || \
failure $"Clearing all current rules and user defined chains:"

for i in $chains; do iptables -t $i -Z; done

echo $"Applying iptables firewall rules: "
grep -v "^[[:space:]]*#" $IPTABLES_CONFIG | grep -v '^[[:space:]]*$' |
/sbin/iptables-restore -c && \
success $"Applying iptables firewall rules" || \
failure $"Applying iptables firewall rules"
echo
touch /var/lock/subsys/iptables
fi
}

stop() {
chains=`cat /proc/net/ip_tables_names 2>/dev/null`
for i in $chains; do iptables -t $i -F; done && \
success $"Flushing all chains:" || \
failure $"Flushing all chains:"
for i in $chains; do iptables -t $i -X; done && \
success $"Removing user defined chains:" || \
failure $"Removing user defined chains:"
echo -n $"Resetting built-in chains to the default ACCEPT policy:"
iptables -P INPUT ACCEPT && \
iptables -P OUTPUT ACCEPT && \
iptables -P FORWARD ACCEPT && \
iptables -t nat -P PREROUTING ACCEPT && \
iptables -t nat -P POSTROUTING ACCEPT && \
iptables -t nat -P OUTPUT ACCEPT && \
iptables -t mangle -P PREROUTING ACCEPT && \
iptables -t mangle -P OUTPUT ACCEPT && \
success $"Resetting built-in chains to the default ACCEPT policy" || \
failure $"Resetting built-in chains to the default ACCEPT policy"
echo
rm -f /var/lock/subsys/iptables
}

case "$1" in
start)
start
;;

stop)
stop
;;

restart)
# "restart" is really just "start" as this isn't a daemon,
# and "start" clears any pre-defined rules anyway.
# This is really only here to make those who expect it happy
start
;;

condrestart)
[ -e /var/lock/subsys/iptables ] && start
;;

status)
echo $"Table: filter"
iptables --list
echo $"Table: nat"
iptables -t nat --list
echo $"Table: mangle"
iptables -t mangle --list
;;

panic)
echo -n $"Changing target policies to DROP: "
iptables -P INPUT DROP && \
iptables -P FORWARD DROP && \
iptables -P OUTPUT DROP && \
iptables -t nat -P PREROUTING DROP && \
iptables -t nat -P POSTROUTING DROP && \
iptables -t nat -P OUTPUT DROP && \
iptables -t mangle -P PREROUTING DROP && \
iptables -t mangle -P OUTPUT DROP && \
success $"Changing target policies to DROP" || \
failure $"Changing target policies to DROP"
echo
iptables -F INPUT && \
iptables -F FORWARD && \
iptables -F OUTPUT && \
iptables -t nat -F PREROUTING && \
iptables -t nat -F POSTROUTING && \
iptables -t nat -F OUTPUT && \
iptables -t mangle -F PREROUTING && \
iptables -t mangle -F OUTPUT && \
success $"Flushing all chains:" || \
failure $"Flushing all chains:"
iptables -X INPUT && \
iptables -X FORWARD && \
iptables -X OUTPUT && \
iptables -t nat -X PREROUTING && \
iptables -t nat -X POSTROUTING && \
iptables -t nat -X OUTPUT && \
iptables -t mangle -X PREROUTING && \
iptables -t mangle -X OUTPUT && \
success $"Removing user defined chains:" || \
failure $"Removing user defined chains:"
;;

save)
echo -n $"Saving current rules to $IPTABLES_CONFIG: "
touch $IPTABLES_CONFIG
chmod 600 $IPTABLES_CONFIG
/sbin/iptables-save -c > $IPTABLES_CONFIG 2>/dev/null && \
success $"Saving current rules to $IPTABLES_CONFIG" || \
failure $"Saving current rules to $IPTABLES_CONFIG"
echo
;;

*)
echo $"Usage: $0 {start|stop|restart|condrestart|status|panic|save}"
exit 1
esac

exit 0


</file>

<file name="/etc/init.d/iptables status="modified">

#!/bin/sh## Startup script to implement /etc/sysconfig/iptables pre-defined
rules.## chkconfig: 2345 08 92## description: Automates a packet filtering
firewall with iptables.## by [email protected], based on the ipchains script:#
Script Author:	Joshua Jensen <[email protected]>#   -- hacked up by gafton
with help from notting# modified by Anton Altaparmakov <[email protected]>:#
modified by Nils Philippsen <[email protected]>## config:
/etc/sysconfig/iptables
# history:
# who date comment / sign
# ----------------------------------------------------------------------
# scan 20021009 modified for self-compiled iptables / scan2002100901

# Source 'em up
. /etc/init.d/functions

# scan2002100901
IPT=/usr/local/sbin/iptables
IPTSAVE=/usr/local/sbin/iptables-save
IPTREST=/usr/local/sbin/iptables-restore
# /scan2002100901

IPTABLES_CONFIG=/etc/sysconfig/iptables

# scan2002100901 from:
# if [ ! -x /sbin/iptables ]; then
# to:
if [ ! -x ${IPT} ]; then
exit 0
fi

KERNELMAJ=`uname -r | sed -e 's,\..*,,'`
KERNELMIN=`uname -r | sed -e 's,[^\.]*\.,,' -e 's,\..*,,'`

if [ "$KERNELMAJ" -lt 2 ] ; then
exit 0
fi
if [ "$KERNELMAJ" -eq 2 -a "$KERNELMIN" -lt 3 ] ; then
exit 0
fi


if /sbin/lsmod 2>/dev/null |grep -q ipchains ; then
# Don't do both
exit 0
fi

start() {
# don't do squat if we don't have the config file
if [ -f $IPTABLES_CONFIG ]; then
# If we don't clear these first, we might be adding to
# pre-existing rules.
# scan2002100901 from:
# action $"Flushing all current rules and user defined chains:" iptables -F
# to:
action $"Flushing all current rules and user defined chains:" ${IPT} -F
# /scan2002100901
# scan2002100901 from:
# action $"Clearing all current rules and user defined chains:" iptables -X
# to:
action $"Clearing all current rules and user defined chains:" ${IPT} -X
# /scan2002100901
chains=`cat /proc/net/ip_tables_names 2>/dev/null`
# scan2002100901 from:
# for i in $chains; do iptables -t $i -F; done && \
# success $"Flushing all current rules and user defined chains:" || \
# failure $"Flushing all current rules and user defined chains:"
# to:
for i in $chains; do ${IPT} -t $i -F; done && \
success $"Flushing all current rules and user defined chains:" || \
failure $"Flushing all current rules and user defined chains:"
# /scan2002100901
# scan2002100901 from:
# for i in $chains; do iptables -t $i -X; done && \
# success $"Clearing all current rules and user defined chains:" || \
# failure $"Clearing all current rules and user defined chains:"
# to:
for i in $chains; do ${IPT} -t $i -X; done && \
success $"Clearing all current rules and user defined chains:" || \
failure $"Clearing all current rules and user defined chains:"
# /scan2002100901

# scan2002100901 from:
# for i in $chains; do iptables -t $i -Z; done
# to:
for i in $chains; do ${IPT} -t $i -Z; done
# /scan2002100901

echo $"Applying iptables firewall rules: "
# scan2002100901 from:
# grep -v "^[[:space:]]*#" $IPTABLES_CONFIG | grep -v '^[[:space:]]*$' |
/sbin/iptables-restore -c && \
# success $"Applying iptables firewall rules" || \
# failure $"Applying iptables firewall rules"
# to:
grep -v "^[[:space:]]*#" $IPTABLES_CONFIG | grep -v '^[[:space:]]*$' |
${IPTREST} -c && \
success $"Applying iptables firewall rules" || \
failure $"Applying iptables firewall rules"
# /scan2002100901
echo
touch /var/lock/subsys/iptables
fi
}

stop() {
chains=`cat /proc/net/ip_tables_names 2>/dev/null`
# scan2002100901 from:
# for i in $chains; do iptables -t $i -F; done && \
# success $"Flushing all chains:" || \
# failure $"Flushing all chains:"
# to:
for i in $chains; do ${IPT} -t $i -F; done && \
success $"Flushing all chains:" || \
failure $"Flushing all chains:"
# /scan2002100901
# scan2002100901 from:
# for i in $chains; do iptables -t $i -X; done && \
# success $"Removing user defined chains:" || \
# failure $"Removing user defined chains:"
# to:
for i in $chains; do ${IPT} -t $i -X; done && \
success $"Removing user defined chains:" || \
failure $"Removing user defined chains:"
# /scan2002100901
echo -n $"Resetting built-in chains to the default ACCEPT policy:"
# scan2002100901 from:
# iptables -P INPUT ACCEPT && \
# iptables -P OUTPUT ACCEPT && \
# iptables -P FORWARD ACCEPT && \
# iptables -t nat -P PREROUTING ACCEPT && \
# iptables -t nat -P POSTROUTING ACCEPT && \
# iptables -t nat -P OUTPUT ACCEPT && \
# iptables -t mangle -P PREROUTING ACCEPT && \
# iptables -t mangle -P OUTPUT ACCEPT && \
# success $"Resetting built-in chains to the default ACCEPT policy" || \
# failure $"Resetting built-in chains to the default ACCEPT policy"
# to:
${IPT} -P INPUT ACCEPT && \
${IPT} -P OUTPUT ACCEPT && \
${IPT} -P FORWARD ACCEPT && \
${IPT} -t nat -P PREROUTING ACCEPT && \
${IPT} -t nat -P POSTROUTING ACCEPT && \
${IPT} -t nat -P OUTPUT ACCEPT && \
${IPT} -t mangle -P PREROUTING ACCEPT && \
${IPT} -t mangle -P OUTPUT ACCEPT && \
success $"Resetting built-in chains to the default ACCEPT policy" || \
failure $"Resetting built-in chains to the default ACCEPT policy"
# /scan2002100901
echo
rm -f /var/lock/subsys/iptables
}

case "$1" in
start)
start
;;

stop)
stop
;;

restart)
# "restart" is really just "start" as this isn't a daemon,
# and "start" clears any pre-defined rules anyway.
# This is really only here to make those who expect it happy
start
;;

condrestart)
[ -e /var/lock/subsys/iptables ] && start
;;

status)
echo $"Table: filter"
# scan2002100901 from:
# iptables --list
# to:
${IPT} --list
# /scan2002100901
echo $"Table: nat"
# scan2002100901 from:
# iptables -t nat --list
# to:
${IPT} -t nat --list
# /scan2002100901
echo $"Table: mangle"
# scan2002100901 from:
# iptables -t mangle --list
# to:
${IPT} -t mangle --list
# /scan2002100901
;;

panic)
echo -n $"Changing target policies to DROP: "
# scan2002100901 from:
# iptables -P INPUT DROP && \
# iptables -P FORWARD DROP && \
# iptables -P OUTPUT DROP && \
# iptables -t nat -P PREROUTING DROP && \
# iptables -t nat -P POSTROUTING DROP && \
# iptables -t nat -P OUTPUT DROP && \
# iptables -t mangle -P PREROUTING DROP && \
# iptables -t mangle -P OUTPUT DROP && \
# success $"Changing target policies to DROP" || \
# failure $"Changing target policies to DROP"
# to:
${IPT} -P INPUT DROP && \
${IPT} -P FORWARD DROP && \
${IPT} -P OUTPUT DROP && \
${IPT} -t nat -P PREROUTING DROP && \
${IPT} -t nat -P POSTROUTING DROP && \
${IPT} -t nat -P OUTPUT DROP && \
${IPT} -t mangle -P PREROUTING DROP && \
${IPT} -t mangle -P OUTPUT DROP && \
success $"Changing target policies to DROP" || \
failure $"Changing target policies to DROP"
# /scan2002100901
echo
# scan2002100901 from:
# iptables -F INPUT && \
# iptables -F FORWARD && \
# iptables -F OUTPUT && \
# iptables -t nat -F PREROUTING && \
# iptables -t nat -F POSTROUTING && \
# iptables -t nat -F OUTPUT && \
# iptables -t mangle -F PREROUTING && \
# iptables -t mangle -F OUTPUT && \
# success $"Flushing all chains:" || \
# failure $"Flushing all chains:"
# to:
${IPT} -F INPUT && \
${IPT} -F FORWARD && \
${IPT} -F OUTPUT && \
${IPT} -t nat -F PREROUTING && \
${IPT} -t nat -F POSTROUTING && \
${IPT} -t nat -F OUTPUT && \
${IPT} -t mangle -F PREROUTING && \
${IPT} -t mangle -F OUTPUT && \
success $"Flushing all chains:" || \
failure $"Flushing all chains:"
# /scan2002100901
# scan2002100901 from:
# iptables -X INPUT && \
# iptables -X FORWARD && \
# iptables -X OUTPUT && \
# iptables -t nat -X PREROUTING && \
# iptables -t nat -X POSTROUTING && \
# iptables -t nat -X OUTPUT && \
# iptables -t mangle -X PREROUTING && \
# iptables -t mangle -X OUTPUT && \
# success $"Removing user defined chains:" || \
# failure $"Removing user defined chains:"
# to:
${IPT} -X INPUT && \
${IPT} -X FORWARD && \
${IPT} -X OUTPUT && \
${IPT} -t nat -X PREROUTING && \
${IPT} -t nat -X POSTROUTING && \
${IPT} -t nat -X OUTPUT && \
${IPT} -t mangle -X PREROUTING && \
${IPT} -t mangle -X OUTPUT && \
success $"Removing user defined chains:" || \
failure $"Removing user defined chains:"
# /scan2002100901
;;

save)
echo -n $"Saving current rules to $IPTABLES_CONFIG: "
touch $IPTABLES_CONFIG
chmod 600 $IPTABLES_CONFIG
# scan2002100901
# /sbin/iptables-save -c > $IPTABLES_CONFIG 2>/dev/null && \
# to:
${IPTSAVE} -c > $IPTABLES_CONFIG 2>/dev/null && \
# /scan2002100901
success $"Saving current rules to $IPTABLES_CONFIG" || \
failure $"Saving current rules to $IPTABLES_CONFIG"
echo
;;

*)
echo $"Usage: $0 {start|stop|restart|condrestart|status|panic|save}"
exit 1
esac

exit 0


</file>

[root@devprak init.d]# chkconfig --level 2345 iptables on

### lets test a little bit

[root@devprak init.d]# ./iptables
Usage: ./iptables {start|stop|restart|condrestart|status|panic|save}
[root@devprak init.d]# ./iptables status
Table: filter
Chain INPUT (policy ACCEPT)
target prot opt source destination

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Table: nat
Chain PREROUTING (policy ACCEPT)
target prot opt source destination

Chain POSTROUTING (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Table: mangle
Chain PREROUTING (policy ACCEPT)
target prot opt source destination

Chain INPUT (policy ACCEPT)
target prot opt source destination

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

Chain POSTROUTING (policy ACCEPT)
target prot opt source destination
[root@devprak init.d]# ./iptables restart
[root@devprak init.d]# ./iptables stop
Resetting built-in chains to the default ACCEPT policy: [ OK ]
[root@devprak init.d]# ./iptables start
[root@devprak init.d]# ./iptables save
Saving current rules to /etc/sysconfig/iptables: [ OK ]
[root@devprak init.d]# cat /etc/sysconfig/iptables
# Generated by iptables-save v1.2.7a on Wed Sep 25 18:19:25 2002
*nat
:PREROUTING ACCEPT [4:760]
:POSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
COMMIT
# Completed on Wed Sep 25 18:19:25 2002
# Generated by iptables-save v1.2.7a on Wed Sep 25 18:19:25 2002
*mangle
:PREROUTING ACCEPT [42:3836]
:INPUT ACCEPT [9195:636338]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [22:1568]
:POSTROUTING ACCEPT [6435:636312]
COMMIT
# Completed on Wed Sep 25 18:19:25 2002
# Generated by iptables-save v1.2.7a on Wed Sep 25 18:19:25 2002
*filter
:INPUT ACCEPT [42:3836]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [22:1568]
COMMIT
# Completed on Wed Sep 25 18:19:25 2002
[root@devprak init.d]#


############## looks fine :)

no let's write a small firewall script not whery tricky:

[root@devprak init.d]# vi iptables.sh

<firewallscript location="~root/bin" name="firewall.sh">

#iptables firewall script ipt=/usr/local/sbin/iptables$ipt -X$ipt -Z$ipt -F#
$ipt -F -t nat# $ipt -F -t mangle
$ipt -P INPUT DROP
$ipt -P OUTPUT ACCEPT
$ipt -P FORWARD ACCEPT

# $ipt -A INPUT -i eth0 -p icmp --icmp-type echo-request -j LOG --log-level
info --log-prefix " ICMP_ER "
$ipt -A INPUT -i eth0 \
-p icmp --icmp-type echo-request \
-m limit --limit 1/s \
-j ACCEPT

$ipt -A INPUT -i eth0 \
-p icmp --icmp-type echo-reply \
-j ACCEPT

$ipt -A INPUT -i eth0 \
-p icmp --icmp-type destination-unreachable \
-j ACCEPT

$ipt -A INPUT -i eth0 \
-p icmp --icmp-type source-quench \
-j ACCEPT

$ipt -A INPUT -i eth0 \
-p icmp --icmp-type time-exceeded \
-j ACCEPT

$ipt -A INPUT -i eth0 \
-p icmp --icmp-type parameter-problem \
-j ACCEPT

$ipt -A INPUT -i eth0 \
-p icmp \
-j DROP

#allow local packages
$ipt -A INPUT -s 127.0.0.0/8 -j ACCEPT
$ipt -A INPUT -s 10.0.0.0/8 -j ACCEPT
# $ipt -A INPUT -s 172.16.1.0/24 -j ACCEPT # if we stand in the DMZ
# $ipt -A INPUT -s 172.16.2.0/24 -j ACCEPT # if we stand in the DMZ
$ipt -A INPUT -s 195.230.37.161/27 -j ACCEPT

# scan : allow ssh from known hosts
# note: see apache conf for allow from / deny from
for ip in 62.178.170.119 212.186.7.42 80.109.233.102 213.47.174.108
212.17.94.24 62.178.154.126 212.88.174.18 194.112.195.254
do
for dport in 22 25 80 88 110
do
iptables -A INPUT -p tcp -s $ip --dport $dport -j ACCEPT
done
done
# /scan

#allow established and related
$ipt -A INPUT -p tcp --dport 1024: -m state --state ESTABLISHED,RELATED -j
ACCEPT
$ipt -A INPUT -p udp --dport 1024: -m state --state ESTABLISHED,RELATED -j
ACCEPT

#mail
$ipt -A INPUT -s 10.0.0.0/8 -p tcp --sport 1024: --dport 25 -j ACCEPT
$ipt -A INPUT -s 195.230.37.160/27 -p tcp --sport 1024: --dport 25 -j ACCEPT
# $ipt -A INPUT -s 127.16.1.0/24 -p tcp --sport 1024: --dport 25 -j ACCEPT
# $ipt -A INPUT -s 127.16.2.0/24 -p tcp --sport 1024: --dport 25 -j ACCEPT

#dns
# $ipt -A INPUT -i eth0 -p tcp --dport 53 -j LOG --log-level
info --log-prefix " TCP_DNS_ER "
# $ipt -A INPUT -i eth0 -p udp --dport 53 -j LOG --log-level
info --log-prefix " UDP_DNS_ER "
$ipt -A INPUT -p tcp --dport 53 -j ACCEPT
$ipt -A INPUT -p tcp --sport 53 --dport 1024: -j ACCEPT
$ipt -A INPUT -p udp --sport 1024: --dport 53 -j ACCEPT
$ipt -A INPUT -p udp --sport 53 --dport 53 -j ACCEPT
$ipt -A INPUT -p udp --sport 68 --dport 67 -j ACCEPT

# log the rest
$ipt -A INPUT -m limit --limit 5/minute -j LOG --log-level info --log-prefix
" INPUT_DROPED "
# and policy is DROP ... by by packet ...


</firewallscript>

[root@devprak bin]# chmod 700 ./iptables.sh

[root@devprak bin]# ./iptables.sh
[root@devprak bin]# iptables -L -n -v -x
## produces as output: (

Chain INPUT (policy DROP 0 packets, 0 bytes)
    pkts      bytes target     prot opt in     out     source
destination
       0        0 ACCEPT     icmp --  eth0   *       0.0.0.0/0
0.0.0.0/0          icmp type 8 limit: avg 1/sec burst 5
       0        0 ACCEPT     icmp --  eth0   *       0.0.0.0/0
0.0.0.0/0          icmp type 0
       0        0 ACCEPT     icmp --  eth0   *       0.0.0.0/0
0.0.0.0/0          icmp type 3
       0        0 ACCEPT     icmp --  eth0   *       0.0.0.0/0
0.0.0.0/0          icmp type 4
       0        0 ACCEPT     icmp --  eth0   *       0.0.0.0/0
0.0.0.0/0          icmp type 11
       0        0 ACCEPT     icmp --  eth0   *       0.0.0.0/0
0.0.0.0/0          icmp type 12
       0        0 DROP       icmp --  eth0   *       0.0.0.0/0
0.0.0.0/0
       0        0 ACCEPT     all  --  *      *       127.0.0.0/8
0.0.0.0/0
      89     7541 ACCEPT     all  --  *      *       10.0.0.0/8
0.0.0.0/0
       0        0 ACCEPT     all  --  *      *       195.230.37.160/27
0.0.0.0/0
       0        0 ACCEPT     tcp  --  *      *       62.178.170.119
0.0.0.0/0          tcp dpt:22
       0        0 ACCEPT     tcp  --  *      *       62.178.170.119
0.0.0.0/0          tcp dpt:25
       0        0 ACCEPT     tcp  --  *      *       62.178.170.119
0.0.0.0/0          tcp dpt:80
       0        0 ACCEPT     tcp  --  *      *       62.178.170.119
0.0.0.0/0          tcp dpt:88
       0        0 ACCEPT     tcp  --  *      *       62.178.170.119
0.0.0.0/0          tcp dpt:110
       0        0 ACCEPT     tcp  --  *      *       212.186.7.42
0.0.0.0/0          tcp dpt:22
       0        0 ACCEPT     tcp  --  *      *       212.186.7.42
0.0.0.0/0          tcp dpt:25
       0        0 ACCEPT     tcp  --  *      *       212.186.7.42
0.0.0.0/0          tcp dpt:80
       0        0 ACCEPT     tcp  --  *      *       212.186.7.42
0.0.0.0/0          tcp dpt:88
       0        0 ACCEPT     tcp  --  *      *       212.186.7.42         0.
0.0.0/0          tcp dpt:110
       0        0 ACCEPT     tcp  --  *      *       80.109.233.102
0.0.0.0/0          tcp dpt:22
       0        0 ACCEPT     tcp  --  *      *       80.109.233.102
0.0.0.0/0          tcp dpt:25
       0        0 ACCEPT     tcp  --  *      *       80.109.233.102
0.0.0.0/0          tcp dpt:80
       0        0 ACCEPT     tcp  --  *      *       80.109.233.102
0.0.0.0/0          tcp dpt:88
       0        0 ACCEPT     tcp  --  *      *       80.109.233.102
0.0.0.0/0          tcp dpt:110
       0        0 ACCEPT     tcp  --  *      *       213.47.174.108
0.0.0.0/0          tcp dpt:22
       0        0 ACCEPT     tcp  --  *      *       213.47.174.108
0.0.0.0/0          tcp dpt:25
       0        0 ACCEPT     tcp  --  *      *       213.47.174.108
0.0.0.0/0          tcp dpt:80
       0        0 ACCEPT     tcp  --  *      *       213.47.174.108
0.0.0.0/0          tcp dpt:88
       0        0 ACCEPT     tcp  --  *      *       213.47.174.108
0.0.0.0/0          tcp dpt:110
       0        0 ACCEPT     tcp  --  *      *       212.17.94.24
0.0.0.0/0          tcp dpt:22
       0        0 ACCEPT     tcp  --  *      *       212.17.94.24
0.0.0.0/0          tcp dpt:25
       0        0 ACCEPT     tcp  --  *      *       212.17.94.24
0.0.0.0/0          tcp dpt:80
       0        0 ACCEPT     tcp  --  *      *       212.17.94.24
0.0.0.0/0          tcp dpt:88
       0        0 ACCEPT     tcp  --  *      *       212.17.94.24
0.0.0.0/0          tcp dpt:110
       0        0 ACCEPT     tcp  --  *      *       62.178.154.126
0.0.0.0/0          tcp dpt:22
       0        0 ACCEPT     tcp  --  *      *       62.178.154.126
0.0.0.0/0          tcp dpt:25
       0        0 ACCEPT     tcp  --  *      *       62.178.154.126
0.0.0.0/0          tcp dpt:80
       0        0 ACCEPT     tcp  --  *      *       62.178.154.126
0.0.0.0/0          tcp dpt:88
       0        0 ACCEPT     tcp  --  *      *       62.178.154.126
0.0.0.0/0          tcp dpt:110
       0        0 ACCEPT     tcp  --  *      *       212.88.174.18
0.0.0.0/0          tcp dpt:22
       0        0 ACCEPT     tcp  --  *      *       212.88.174.18
0.0.0.0/0          tcp dpt:25
       0        0 ACCEPT     tcp  --  *      *       212.88.174.18
0.0.0.0/0          tcp dpt:80
       0        0 ACCEPT     tcp  --  *      *       212.88.174.18
0.0.0.0/0          tcp dpt:88
       0        0 ACCEPT     tcp  --  *      *       212.88.174.18
0.0.0.0/0          tcp dpt:110
       0        0 ACCEPT     tcp  --  *      *       194.112.195.254
0.0.0.0/0          tcp dpt:22
       0        0 ACCEPT     tcp  --  *      *       194.112.195.254
0.0.0.0/0          tcp dpt:25
       0        0 ACCEPT     tcp  --  *      *       194.112.195.254
0.0.0.0/0          tcp dpt:80
       0        0 ACCEPT     tcp  --  *      *       194.112.195.254
0.0.0.0/0          tcp dpt:88
       0        0 ACCEPT     tcp  --  *      *       194.112.195.254
0.0.0.0/0          tcp dpt:110
       0        0 ACCEPT     tcp  --  *      *       0.0.0.0/0
0.0.0.0/0          tcp dpts:1024:65535 state RELATED,ESTABLISHED
       0        0 ACCEPT     udp  --  *      *       0.0.0.0/0
0.0.0.0/0          udp dpts:1024:65535 state RELATED,ESTABLISHED
       0        0 ACCEPT     tcp  --  *      *       10.0.0.0/8
0.0.0.0/0          tcp spts:1024:65535 dpt:25
       0        0 ACCEPT     tcp  --  *      *       195.230.37.160/27
0.0.0.0/0          tcp spts:1024:65535 dpt:25
       0        0 ACCEPT     tcp  --  *      *       0.0.0.0/0
0.0.0.0/0          tcp dpt:53
       0        0 ACCEPT     tcp  --  *      *       0.0.0.0/0
0.0.0.0/0          tcp spt:53 dpts:1024:65535
       0        0 ACCEPT     udp  --  *      *       0.0.0.0/0
0.0.0.0/0          udp spts:1024:65535 dpt:53
       0        0 ACCEPT     udp  --  *      *       0.0.0.0/0
0.0.0.0/0          udp spt:53 dpt:53
       0        0 ACCEPT     udp  --  *      *       0.0.0.0/0
0.0.0.0/0          udp spt:68 dpt:67
       0        0 LOG        all  --  *      *       0.0.0.0/0
0.0.0.0/0          limit: avg 5/min burst 5 LOG flags 0 level 6 prefix `
INPUT_DROPED '

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
    pkts      bytes target     prot opt in     out     source
destination

Chain OUTPUT (policy ACCEPT 43 packets, 2908 bytes)
    pkts      bytes target     prot opt in     out     source
destination


)

## and save the rules:

[root@devprak bin]# iptables-save >/etc/sysconfig/iptables

### now last step: reboot to see success by starting up, which I could
ommit, but I want go sure :)

note beside: specific to this mashine for this extra reboot I removed the
SCSI support from the kernel configuration (remember: $ make menuconfig) and
recompiled the kernel with this multiple "make" - command on one line ; yes
the mashine starts much more faster now and :

### the iptables rules are all present after the reboot :)

*** READY ***

next: fix the redhat distribution (see trinity and present documentation),
upgrade perl and install teh latest apache. upgrade mysql as well.

===================00

> -----Original Message-----
> From: [email protected]
> [mailto:[email protected]]On Behalf Of Robert Pare
> Sent: Monday, February 17, 2003 7:03 PM
> To: [email protected]
> Subject: Updating dev package
>
>
>
> I am trying to update my system to the 2.4 kernel in order to use
> iptables.  When I try to run the update on the kernel I have a
> dependency problem with the dev package.  I can't seem to find a dev RPM
> on the RedHat site to upgrade to?  Does this mean that I can't really go
> to the 2.4 kernel with RedHat 7.0 or does this mean I am just not
> looking for the right file?
>
> I would have thought that the up2date program would do this upgrade for
> me but I can't seem to make it do the Kernel upgrade on it's own, it
> will only update the kernel within the same release.
>
> Robert Paré
> Network Administrator
> Compu-Quote Inc.
> 519.974.7283 Phone
> 519.974.7290 Fax
>
>
>
> _______________________________________________
> Guinness-list mailing list
> [email protected]
> https://listman.redhat.com/mailman/listinfo/guinness-list
>