From: Maarten Vanraes <maarten@ba.be>
To: netfilter@vger.kernel.org
Cc: Bob Miller <bob@computerisms.ca>
Subject: Re: xtables-addons ACCOUNT
Date: Wed, 20 Oct 2010 10:25:55 +0200 [thread overview]
Message-ID: <201010201025.55825.maarten@ba.be> (raw)
In-Reply-To: <1287506749.13167.1042.camel@laplaplian>
Op dinsdag 19 oktober 2010 18:45:49 schreef Bob Miller:
> Hi
>
> > where exactly should i use the ACCOUNT module? does that matter?
>
> Assuming you mean in your iptables rule set, yes, it matters, and you
> should put it where you want it to count. Based on my my understanding,
> limited though it is; in theory, for the 0/0 subnet, the mangle
> table/prerouting chain will catch all traffic between you and the ISP
> that has tcp/ip qualities (ie address and netmask). If you are trying
> to count data used to the ISP by computers on a LAN, then placing the
> rule in the filter table/forward chain should count that traffic.
>
> > error message when trying to use it now:
> >
> >
> > ACCOUNT: Table publicnet found, but IP/netmask mismatch. IP/netmask
> > found: 194.0.234.0/255.255.255.0
> > ACCOUNT: Table insert problem. Aborting
>
> Seems your configuration doesn't match your situation? without knowing
> more about your environment and how you configured this box, it is hard
> to say, maybe your interface address is not in 194.0.234.0/24 or
> something?
> Jan's response might seem to indicate this is an issue of the way you
> built this up or a software mismatch of some sort. Given the fun I had
> making this work before it all came out in debian packages with debian
> methods of building it, I would not be one bit surprised if that is the
> case.
this error message is due to a previous publicnet rule, and it can't seem to
find the matching network. even though it is the same one. (i suspect it is due
to network being 194.0.234.0/24 and the matcher is checking
194.0.234.0/255.255.255.0 ). also i suspect there is a another bug when
removing the rule that the matcher can't find the correct one (also due to
different netmask notations?) and thus not everything is removed which means
that i can't reinsert that one.
Well, i looked at the distromap, seen which versions of what packages work
well and put those working ones on this lenny: for instance; this lenny has
pretty much all relevant packages from the squeeze (which is green in that
map)
furthermore, i don't have any problem with the module; it loads fine
> > when trying to remove the rule with iptables:
> >
> >
> > ACCOUNT: Table publicnet not found for destroy
> >
> >
> > "iptaccount -a" does show the nets fine; but the -l publicnet always
> > gives:
> >
> >
> > Showing table: publicnet
> > Run #0 - 0 items found
> > Finished.
>
> If the other two nets are working as expected, I would think that means
> your software is working, but I dont' know why you would have this
> problem on the one net.
no, i am testing manually with iptables and this is after the first entry
(there is only one tname here.
but no amount of traffic is having any effect here.
i mean; where do i get all the results? it always says 0.
Kind regards,
Maarten
next prev parent reply other threads:[~2010-10-20 8:25 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-10-18 15:12 xtables-addons ACCOUNT Maarten Vanraes
2010-10-18 16:18 ` Bob Miller
2010-10-18 16:32 ` Bob Miller
2010-10-19 8:09 ` Maarten Vanraes
2010-10-19 9:38 ` Jan Engelhardt
2010-10-19 10:00 ` Maarten Vanraes
2010-10-19 16:45 ` Bob Miller
2010-10-20 8:25 ` Maarten Vanraes [this message]
2010-10-20 9:16 ` Jan Engelhardt
2010-10-20 13:03 ` Maarten Vanraes
2010-10-20 17:36 ` Jan Engelhardt
2010-10-21 11:31 ` Maarten Vanraes
2010-10-27 20:28 ` Jan Engelhardt
2010-10-28 7:32 ` Maarten Vanraes
2010-10-28 22:20 ` Jan Engelhardt
2010-10-29 7:31 ` Maarten Vanraes
-- strict thread matches above, loose matches on Subject: below --
2010-10-25 7:35 Maarten Vanraes
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=201010201025.55825.maarten@ba.be \
--to=maarten@ba.be \
--cc=bob@computerisms.ca \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.