From: Norman Zhang <norman.zhang@rd.arkonnetworks.com>
To: netfilter@lists.netfilter.org
Subject: Re: Iptables and Kernel
Date: Mon, 12 Apr 2004 10:05:04 -0700 [thread overview]
Message-ID: <407ACC40.4060503@rd.arkonnetworks.com> (raw)
In-Reply-To: <5554.68140305511$1081756198@news.gmane.org>
>>>>Is iptables still needed for kernel 2.6.x? I see a lot of iptables
>>>>patches go into the kernel, but not much updates on the
>>>>www.netfilter.org. The logo on netfilter says firewalling, NAT and
>>>>packet mangling for Linux 2.4. So I guess much of the code goes directly
>>>>into the kernel? Also does kernel 2.6.3 support Netmeeting and MSN
>>>>Instant Messengener, or I need the following plug-in,
>>>>http://www.kfki.hu/%7Ekadlec/sw/netfilter/newnat-suite/?
>>>
>>>1) iptables is the userspace component. Yes it is still needed in 2.6.x
>>>-- you still have to use it to setup and manage individual rules.
>>>
>>>2) 2.6.x indeed supports many components of netfilter out of the box,
>>>however there is still patch-o-matic-ng which can still add functionality
>>>not yet in the kernel or in userspace.
>>>
>>>3) No, you do not need patches from newnat-suite by default, you need
>>>ip_conntrack_h323 and ip_nat_h323, although you might need newnat if your
>>>iptables is really old.
>>
>>I'm using iptables-1.2.9-5mdk.i586.rpm on LM10.0. The latest on
>>www.netfilter.org is 1.2.9. I guess those 2 modules is included in 1.2.9?
>>
>>>Keep in mind that *support* of netmeeting in this case is a loose
>>>terminology -- I believe that several functionalities are not covered by
>>>the h323 patches.
>>
>>All I wanted is the ability to see video & audio for both incoming and
>>outgoing calls. Is that supported in iptables-1.2.9? Do I need to apply
>>pom-ng on top of iptables?
>
>Looking at my kernel tarball, the bare 2.6.3 kernel does NOT include the h323 modules.
>I would say you need patches in p-o-m -- I'm not sure if mandrake has a package for
>p-o-m or not, but yes you need to add h323 modules.
I just downloaded 2.6.5, may I ask where should I check to see if h323
modules are included? On www.netfilter.org, I see pom-20031219 and
pomng-20040302. Is it safe to assume, that pomng includes pom?
>IIRC, netmeeting should provide video/audio with conntrack and nat of h323 and relevant
>ESTABLISHED,RELATED rules. -- be aware that you may not be able to recieve
>calls inside the firewall unless you forward the inbound connection requests --
>the gnomemeeting website has some good rules on their faq pages that can help
>with netmeeting requests as well. Check out openh323.org for gatekeeper applications
>that can act as proxy for connection requests, thus mitigating functionality problems.
>MS netmeeting also uses UPNP -- this protocol has been discussed on this list previously,
>and you might want to read up on that as well.
Thank you so much. I will read up on them.
Regards,
Norman
next prev parent reply other threads:[~2004-04-12 17:05 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-04-12 5:22 Iptables and Kernel Norman Zhang
2004-04-12 6:00 ` Unknown, Alistair Tonner
2004-04-12 6:27 ` Norman Zhang
2004-04-12 7:32 ` Unknown, Alistair Tonner
2004-04-12 17:05 ` Norman Zhang [this message]
2004-04-12 17:22 ` Antony Stone
2004-04-12 19:07 ` Norman Zhang
2004-04-12 20:16 ` Unknown, Alistair Tonner
2004-04-18 15:53 ` Norman Zhang
2004-04-18 12:06 ` Alistair Tonner
2004-04-18 16:27 ` Norman Zhang
2004-04-18 13:05 ` Alistair Tonner
2004-04-19 4:34 ` Norman Zhang
2004-04-19 8:48 ` Alistair Tonner
2004-04-19 14:58 ` Norman Zhang
2004-04-19 15:11 ` Geffrey Velasquez
2004-04-21 15:56 ` Norman Zhang
-- strict thread matches above, loose matches on Subject: below --
2004-04-12 5:17 Norman Zhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=407ACC40.4060503@rd.arkonnetworks.com \
--to=norman.zhang@rd.arkonnetworks.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.