Linux Netfilter discussions
 help / color / mirror / Atom feed
* Problem with state match for ip6tables
@ 2006-02-02 12:38 Frederic Beck
  2006-02-04 10:20 ` Graham Murray
  0 siblings, 1 reply; 9+ messages in thread
From: Frederic Beck @ 2006-02-02 12:38 UTC (permalink / raw)
  To: netfilter

Hello

I'm trying to set up a firewalling script for IPv6 on my Debian, kernel 
2.6.15-1-686-smp, but i have a problem when using the state match.

When i try simply to match all packets with a state ESTABLISHED, i got
the followinf error

root@trunks:~/firewalling/iptables
% ip6tables -A FORWARD  -m state --state ESTABLISHED -j ACCEPT
ip6tables: Unknown error 4294967295

I'm using ip6tables version 1.3.5, i tried also to retrieve the svn
version, but i got the same behaviour.

I didn't see any patch to apply, and am clueless now. Am i missing
something ? Is it a bug ?

Thanks a lot
Fred


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: Problem with state match for ip6tables
  2006-02-02 12:38 Problem with state match for ip6tables Frederic Beck
@ 2006-02-04 10:20 ` Graham Murray
  2006-02-10 13:56   ` Frederic Beck
  0 siblings, 1 reply; 9+ messages in thread
From: Graham Murray @ 2006-02-04 10:20 UTC (permalink / raw)
  To: netfilter

Frederic Beck <frederic.beck@loria.fr> writes:

> root@trunks:~/firewalling/iptables
> % ip6tables -A FORWARD  -m state --state ESTABLISHED -j ACCEPT
> ip6tables: Unknown error 4294967295

I see the same problem with gentoo kernel 2.6.15-r2 and iptables
1.3.5, except that I also add the protocol 

# ip6tables -I INPUT 1 -p tcp -m state --state NEW,ESTABLISHED -j ACCEPT
ip6tables: Unknown error 4294967295

strace shows this prior to the error

socket(PF_INET6, SOCK_RAW, IPPROTO_RAW) = 3
getsockopt(3, SOL_IPV6, 0x40 /* IPV6_??? */, "filter\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., [84]) = 0
getsockopt(3, SOL_IPV6, 0x41 /* IPV6_??? */, "filter\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., [2328]) = 0
setsockopt(3, SOL_IPV6, 0x40 /* IPV6_??? */, "filter\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 2620) = -1 ENOENT (No such file or directory)
write(2, "ip6tables: Unknown error 4294967"..., 36ip6tables: Unknown error 4294967295
) = 36


I have connection tracking turned on in the kernel

CONFIG_NETFILTER_NETLINK=y
CONFIG_NETFILTER_NETLINK_QUEUE=y
CONFIG_NETFILTER_NETLINK_LOG=y
CONFIG_NF_CONNTRACK=y
# CONFIG_NF_CT_ACCT is not set
# CONFIG_NF_CONNTRACK_MARK is not set
CONFIG_NF_CONNTRACK_EVENTS=y
# CONFIG_NF_CT_PROTO_SCTP is not set
# CONFIG_NF_CONNTRACK_FTP is not set

CONFIG_NF_CONNTRACK_IPV6=y
# CONFIG_IP6_NF_QUEUE is not set
CONFIG_IP6_NF_IPTABLES=y
CONFIG_IP6_NF_MATCH_LIMIT=y
CONFIG_IP6_NF_MATCH_MAC=y
CONFIG_IP6_NF_MATCH_RT=y
CONFIG_IP6_NF_MATCH_OPTS=y
CONFIG_IP6_NF_MATCH_FRAG=y
CONFIG_IP6_NF_MATCH_HL=y
CONFIG_IP6_NF_MATCH_MULTIPORT=y
CONFIG_IP6_NF_MATCH_OWNER=y
CONFIG_IP6_NF_MATCH_MARK=y
CONFIG_IP6_NF_MATCH_IPV6HEADER=y
CONFIG_IP6_NF_MATCH_AHESP=y
CONFIG_IP6_NF_MATCH_LENGTH=y
CONFIG_IP6_NF_MATCH_EUI64=y
CONFIG_IP6_NF_FILTER=y
CONFIG_IP6_NF_TARGET_LOG=y
CONFIG_IP6_NF_TARGET_REJECT=y
CONFIG_IP6_NF_TARGET_NFQUEUE=y
CONFIG_IP6_NF_MANGLE=y
CONFIG_IP6_NF_TARGET_MARK=y
CONFIG_IP6_NF_TARGET_HL=y
CONFIG_IP6_NF_RAW=y


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: Problem with state match for ip6tables
  2006-02-04 10:20 ` Graham Murray
@ 2006-02-10 13:56   ` Frederic Beck
  2006-02-13  4:16     ` Yasuyuki KOZAKAI
  0 siblings, 1 reply; 9+ messages in thread
From: Frederic Beck @ 2006-02-10 13:56 UTC (permalink / raw)
  To: netfilter

> > root@trunks:~/firewalling/iptables
> > % ip6tables -A FORWARD  -m state --state ESTABLISHED -j ACCEPT
> > ip6tables: Unknown error 4294967295
> 
> I see the same problem with gentoo kernel 2.6.15-r2 and iptables
> 1.3.5, except that I also add the protocol 
> 
> # ip6tables -I INPUT 1 -p tcp -m state --state NEW,ESTABLISHED -j
> ACCEPT ip6tables: Unknown error 4294967295
> 
> strace shows this prior to the error
> 
> socket(PF_INET6, SOCK_RAW, IPPROTO_RAW) = 3
> getsockopt(3, SOL_IPV6, 0x40 /* IPV6_??? */,
> "filter\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., [84]) = 0
> getsockopt(3, SOL_IPV6, 0x41 /* IPV6_??? */,
> "filter\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., [2328]) =
> 0 setsockopt(3, SOL_IPV6, 0x40 /* IPV6_??? */,
> "filter\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 2620) =
> -1 ENOENT (No such file or directory) write(2, "ip6tables: Unknown
> error 4294967"..., 36ip6tables: Unknown error 4294967295 ) = 36

I tried on several distributions (debian, fedora) and kernel versions
(2.6.14, 2.6.8), but i get each time the same error.

Is this a known bug ?  I couldn't find it in netfilter's bugzilla

Fred


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: Problem with state match for ip6tables
  2006-02-10 13:56   ` Frederic Beck
@ 2006-02-13  4:16     ` Yasuyuki KOZAKAI
  2006-02-13  9:21       ` Graham Murray
  0 siblings, 1 reply; 9+ messages in thread
From: Yasuyuki KOZAKAI @ 2006-02-13  4:16 UTC (permalink / raw)
  To: frederic.beck; +Cc: netfilter


Hi, all,

From: Frederic Beck <frederic.beck@loria.fr>
Date: Fri, 10 Feb 2006 14:56:31 +0100

> > > root@trunks:~/firewalling/iptables
> > > % ip6tables -A FORWARD  -m state --state ESTABLISHED -j ACCEPT
> > > ip6tables: Unknown error 4294967295
> > 
> > I see the same problem with gentoo kernel 2.6.15-r2 and iptables
> > 1.3.5, except that I also add the protocol 
> > 
> > # ip6tables -I INPUT 1 -p tcp -m state --state NEW,ESTABLISHED -j
> > ACCEPT ip6tables: Unknown error 4294967295
> > 
> > strace shows this prior to the error
> > 
> > socket(PF_INET6, SOCK_RAW, IPPROTO_RAW) = 3
> > getsockopt(3, SOL_IPV6, 0x40 /* IPV6_??? */,
> > "filter\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., [84]) = 0
> > getsockopt(3, SOL_IPV6, 0x41 /* IPV6_??? */,
> > "filter\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., [2328]) =
> > 0 setsockopt(3, SOL_IPV6, 0x40 /* IPV6_??? */,
> > "filter\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 2620) =
> > -1 ENOENT (No such file or directory) write(2, "ip6tables: Unknown
> > error 4294967"..., 36ip6tables: Unknown error 4294967295 ) = 36
> 
> I tried on several distributions (debian, fedora) and kernel versions
> (2.6.14, 2.6.8), but i get each time the same error.
> 
> Is this a known bug ?  I couldn't find it in netfilter's bugzilla

The only kernel >= 2.6.15 supports IPv6 state match.
And kernel option CONFIG_NETFILTER_XTABLES and 
CONFIG_NETFILTER_XT_MATCH_STATE are required.

Please "make menuconfig" in kernel source, and go to the menu
"Network packet filtering (replaces ipchains)",
enable "Netfilter Xtables support (required for ip_tables)",
enable "state match support".

Regards,

-- Yasuyuki Kozakai


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: Problem with state match for ip6tables
  2006-02-13  4:16     ` Yasuyuki KOZAKAI
@ 2006-02-13  9:21       ` Graham Murray
  2006-02-13 10:56         ` Graham Murray
                           ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Graham Murray @ 2006-02-13  9:21 UTC (permalink / raw)
  To: netfilter

Yasuyuki KOZAKAI <yasuyuki.kozakai@toshiba.co.jp> writes:

> The only kernel >= 2.6.15 supports IPv6 state match.
> And kernel option CONFIG_NETFILTER_XTABLES and 
> CONFIG_NETFILTER_XT_MATCH_STATE are required.
>
> Please "make menuconfig" in kernel source, and go to the menu
> "Network packet filtering (replaces ipchains)",
> enable "Netfilter Xtables support (required for ip_tables)",
> enable "state match support".

I am using kernel 2.6.15 but I do not see these config options
anywhere. I have grep'd the kernel source and can find
CONFIG_IP_NF_MATCH_STATE (which is only used in the ipv4 makefile to
build ipt_state.o)


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: Problem with state match for ip6tables
  2006-02-13  9:21       ` Graham Murray
@ 2006-02-13 10:56         ` Graham Murray
  2006-02-13 15:30         ` Yasuyuki KOZAKAI
       [not found]         ` <200602131530.k1DFUhTI005947@toshiba.co.jp>
  2 siblings, 0 replies; 9+ messages in thread
From: Graham Murray @ 2006-02-13 10:56 UTC (permalink / raw)
  To: netfilter

Graham Murray <graham@gmurray.org.uk> writes:

> I am using kernel 2.6.15 but I do not see these config options
> anywhere. I have grep'd the kernel source and can find
> CONFIG_IP_NF_MATCH_STATE (which is only used in the ipv4 makefile to
> build ipt_state.o)

Also connection tracking for ipv6 is working as I see ipv6 sessions in
/proc/net/nf_conntrack


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: Problem with state match for ip6tables
  2006-02-13  9:21       ` Graham Murray
  2006-02-13 10:56         ` Graham Murray
@ 2006-02-13 15:30         ` Yasuyuki KOZAKAI
  2006-02-15 11:01           ` Frederic Beck
       [not found]         ` <200602131530.k1DFUhTI005947@toshiba.co.jp>
  2 siblings, 1 reply; 9+ messages in thread
From: Yasuyuki KOZAKAI @ 2006-02-13 15:30 UTC (permalink / raw)
  To: graham; +Cc: netfilter

From: Graham Murray <graham@gmurray.org.uk>
Date: Mon, 13 Feb 2006 09:21:26 +0000

> Yasuyuki KOZAKAI <yasuyuki.kozakai@toshiba.co.jp> writes:
> 
> > The only kernel >= 2.6.15 supports IPv6 state match.
> > And kernel option CONFIG_NETFILTER_XTABLES and 
> > CONFIG_NETFILTER_XT_MATCH_STATE are required.
> >
> > Please "make menuconfig" in kernel source, and go to the menu
> > "Network packet filtering (replaces ipchains)",
> > enable "Netfilter Xtables support (required for ip_tables)",
> > enable "state match support".
> 
> I am using kernel 2.6.15 but I do not see these config options
> anywhere. I have grep'd the kernel source and can find
> CONFIG_IP_NF_MATCH_STATE (which is only used in the ipv4 makefile to
> build ipt_state.o)

Sorry, I was wrong. nf_conntrack lives in kernel >= 2.6.15,
but only kernel >= 2.6.16 supports IPv6 state match.

-- Yasuyuki Kozakai


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: Problem with state match for ip6tables
       [not found]         ` <200602131530.k1DFUhTI005947@toshiba.co.jp>
@ 2006-02-13 18:23           ` Graham Murray
  0 siblings, 0 replies; 9+ messages in thread
From: Graham Murray @ 2006-02-13 18:23 UTC (permalink / raw)
  To: netfilter

Yasuyuki KOZAKAI <yasuyuki.kozakai@toshiba.co.jp> writes:

> Sorry, I was wrong. nf_conntrack lives in kernel >= 2.6.15,
> but only kernel >= 2.6.16 supports IPv6 state match.

Thanks. I thought it was in 2.6.15, that is why I asked.


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: Problem with state match for ip6tables
  2006-02-13 15:30         ` Yasuyuki KOZAKAI
@ 2006-02-15 11:01           ` Frederic Beck
  0 siblings, 0 replies; 9+ messages in thread
From: Frederic Beck @ 2006-02-15 11:01 UTC (permalink / raw)
  To: netfilter

> Sorry, I was wrong. nf_conntrack lives in kernel >= 2.6.15,
> but only kernel >= 2.6.16 supports IPv6 state match.

Ok great, i'll wait for that version to become stable and play with it !

Thanks
Fred


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2006-02-15 11:01 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-02-02 12:38 Problem with state match for ip6tables Frederic Beck
2006-02-04 10:20 ` Graham Murray
2006-02-10 13:56   ` Frederic Beck
2006-02-13  4:16     ` Yasuyuki KOZAKAI
2006-02-13  9:21       ` Graham Murray
2006-02-13 10:56         ` Graham Murray
2006-02-13 15:30         ` Yasuyuki KOZAKAI
2006-02-15 11:01           ` Frederic Beck
     [not found]         ` <200602131530.k1DFUhTI005947@toshiba.co.jp>
2006-02-13 18:23           ` Graham Murray

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox