From: Ray Leach <raymondl@knowledgefactory.co.za>
To: 'netfilter' <netfilter@lists.netfilter.org>
Subject: Re: Problems with kernel 2.6.1 and iptables
Date: Mon, 16 Feb 2004 12:26:02 +0200 [thread overview]
Message-ID: <1076927162.2333.6.camel@raylinux.internal> (raw)
In-Reply-To: <005801c3f475$91a645d0$2d64a8c0@pcjka>
[-- Attachment #1: Type: text/plain, Size: 3493 bytes --]
On Mon, 2004-02-16 at 12:13, Jan Kaastrup wrote:
> Hi list
> I have search google for this error most of my weekend, and I cannot get
> the answer :(
> I have upgraded my kernel to 2.6.1 and made all the iptables stuff as
> modules.
> I can load all modules by hand perfectly, but still i get this error:
> #Iptables -L
> iptables v1.2.9: can't initialize iptables table `filter': Table does
> not exist (do you need to insmod?)
> Perhaps iptables or your kernel needs to be upgraded.
>
The 'filter' table does not exist by default, but the 'FILTER' table
does. Is this a user chain than you created?
> I have reinstalled iptables and done depmod -a
> I have installed module-init-tools-2.0-pre10
>
> It seems like it cannot mount modules automaticly, any ideas?
> Which modules should absolutly be loaded, to make iptables work?
> Could it be, that i am missing a
> iptables-need-to-be-installed-to-make-iptables-work-for-kernel-2.6.x-pac
> ket?
>
> Thanks a lot
>
>
>
> -----Original Message-----
> From: netfilter-admin@lists.netfilter.org
> [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Antony Stone
> Sent: 13. februar 2004 18:13
> To: netfilter
> Subject: Re: Routing problem
>
>
> On Friday 13 February 2004 4:30 pm, Carlos Fernandez Sanz wrote:
>
> > > > Before you ask: I can't connect this special computer to the same
> place
> > > > I connect the linux box (which would be the obvious solution)
> because
> > > > the carrier expects traffic to come from one WAN IP, owned by the
> linux
> > > > box.
> > >
> > > How do they expect you to use any of the other IPs in the pool they
> have
> > > given you?
> >
> > I do use them by redirecting traffic from the linux box to the
> destination
> > boxes (such as all trafic for public IP 2 goes to 192.168.21.2, for
> > example). This works fine, *except* in this particular case, where any
> > NATing is not an option. I need the computer behind the linux box to
> > actually own the public address, because it signs packets with it.
>
> I still don't understand. One of your above statements must be
> incorrect:
>
> - either the ISP requires all your outgoing traffic to come from a
> single
> public address,
>
> - or you can send traffic from IP1, IP2, IP3 etc as you wish.
>
> If the first is true (you have to send all traffic from just a single
> address)
> then I don't see how you can do NAT from IP2 to 192.168.21.2, because
> the
> reply packets going back out to the Internet are going to have the
> source
> address (after de-NATting) of IP2 - therefore you *are* being allowed to
> send
> from more than one public IP.
>
> If the second is true (you can send from IP1, IP2, IP3 etc as you wish)
> then
> as you said in the first place, you can connect the user who wants to
> use
> some nasty protocol which embeds OSI layer 3 information into OSI layer
> 7
> traffic to the same place as your existing Linux box and give them a
> real
> public IP of their own.
>
> What does your ISP claim will happen if you use more than one of your
> assigned
> pool of IP addresses for the source address of outgoing traffic?
>
> Antony.
--
--
Raymond Leach <raymondl@knowledgefactory.co.za>
Network Support Specialist
http://www.knowledgefactory.co.za
"lynx -source http://www.rchq.co.za/raymondl.asc | gpg --import"
Key fingerprint = 7209 A695 9EE0 E971 A9AD 00EE 8757 EE47 F06F FB28
--
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
next prev parent reply other threads:[~2004-02-16 10:26 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-02-13 15:39 Routing problem Carlos Fernandez Sanz
2004-02-13 15:50 ` Antony Stone
2004-02-13 16:30 ` Carlos Fernandez Sanz
2004-02-13 17:12 ` Antony Stone
2004-02-14 8:41 ` Carlos Fernandez Sanz
2004-02-14 9:09 ` Antony Stone
2004-02-14 15:15 ` Carlos Fernandez Sanz
2004-02-14 15:19 ` Carlos Fernandez Sanz
2004-02-14 15:38 ` Antony Stone
2004-02-16 10:13 ` Problems with kernel 2.6.1 and iptables Jan Kaastrup
2004-02-16 10:26 ` Ray Leach [this message]
2004-02-16 10:47 ` Antony Stone
2004-02-16 11:19 ` Ray Leach
2004-02-16 13:18 ` Alexis
2004-02-16 14:05 ` Jan Kaastrup
2004-02-13 17:16 ` Routing problem Scott MacKay
2004-02-14 8:47 ` Carlos Fernandez Sanz
2004-02-13 16:53 ` John A. Sullivan III
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1076927162.2333.6.camel@raylinux.internal \
--to=raymondl@knowledgefactory.co.za \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.