From: Alistair Tonner <Alistair@nerdnet.ca>
To: netfilter@lists.netfilter.org
Subject: Re: Iptables and Kernel
Date: Sun, 18 Apr 2004 13:05:40 +0000 [thread overview]
Message-ID: <200404181305.40319.Alistair@nerdnet.ca> (raw)
In-Reply-To: <4082AC74.2070601@rd.arkonnetworks.com>
On April 18, 2004 04:27 pm, Norman Zhang wrote:
> >>I'm trying to compile p-o-m-ng with 2.6.5 now. It asks for iptables
> >>sources. I thought p-o-m-ng patches applies to the kernel only. Do I
> >>need to recompile iptables too? There are many patches in p-o-m-ng. I
> >>only need the h323 patch for Netmeeting to work correctly? The README
> >>from p-o-m-ng recommends the following command to patch the kernel,
> >>
> >># KERNEL_DIR=/usr/src/linux ./runme -pending
> >>
> >>Do I need to worry about rejects and offsets?
> >
> >Yes you need to apply some of the patches in pom-ng against the
> >iptables sources. Not only do we change the kernel code, but we have
> >to make some changes to the iptables tools as well to get some of
> >to work
>
> Thank you so much for your quick response. I've iptables RPM already
> installed with Mandrake. I guess I will need to remove that first before
> compiling the new iptables. I plan to use Shorewall to configure my
> firewall. Will removing iptables RPM break anything? I see iptables is
> included as startup option during boot under Mandrake. After recompiling
> iptables, do I need to reconfigure all those options?
I'm not a Mandrake user, so I'm no expert, but I would suspect that you might
need to check the paths involved in that startup script. I know that by
default Slackware installs iptables in /usr/local/ and I by my weird nature
want it in / ( I want that firewall up and running FIRST dammit)... so ..
go get all the required sources, (iptables, pom-ng and if you need it the
kernel bits) shutdown that internet connection, remove the RPM of iptables
(but keep the file for it handy) and go ahead .... best practice rules apply
in all processes like this -- make a backup of some sort FIRST. so you can
go back if need be.
Shorewall is well done, and well supported by others on this list.
I'm not so sure what options Drake offers for configuration, so ...
Alistair Tonner.
>
> >For the record, with both 2.6.3. and 2.6.5 from gentoo with the gaming
> >options, iptables 1.2.9 and pom-ng play nice for most things.
> >
> >If something doesn't apply against plain jane kernel code, there is
> >likely a need to holler at the maintainer of the patch.
>
> Regards,
> Norman
next prev parent reply other threads:[~2004-04-18 13:05 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-04-12 5:22 Iptables and Kernel Norman Zhang
2004-04-12 6:00 ` Unknown, Alistair Tonner
2004-04-12 6:27 ` Norman Zhang
2004-04-12 7:32 ` Unknown, Alistair Tonner
2004-04-12 17:05 ` Norman Zhang
2004-04-12 17:22 ` Antony Stone
2004-04-12 19:07 ` Norman Zhang
2004-04-12 20:16 ` Unknown, Alistair Tonner
2004-04-18 15:53 ` Norman Zhang
2004-04-18 12:06 ` Alistair Tonner
2004-04-18 16:27 ` Norman Zhang
2004-04-18 13:05 ` Alistair Tonner [this message]
2004-04-19 4:34 ` Norman Zhang
2004-04-19 8:48 ` Alistair Tonner
2004-04-19 14:58 ` Norman Zhang
2004-04-19 15:11 ` Geffrey Velasquez
2004-04-21 15:56 ` Norman Zhang
-- strict thread matches above, loose matches on Subject: below --
2004-04-12 5:17 Norman Zhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200404181305.40319.Alistair@nerdnet.ca \
--to=alistair@nerdnet.ca \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.