* layer 7 netfilter not working
@ 2004-07-09 20:56 FB
2004-07-09 21:18 ` Antony Stone
0 siblings, 1 reply; 2+ messages in thread
From: FB @ 2004-07-09 20:56 UTC (permalink / raw)
To: netfilter
Hello there!
I am trying to get traffic shaping working on my Linux router (debian
woody 3r02) and for some things I wanted to use the layer 7 packet
classifier, but I can't get it to work.
Here is what I did:
-downloaded the patches from http://l7-filter.sourceforge.net
-downloaded the kernel 2.6.7 source
-downloaded the iptables 1.2.11 source
-patched kernel (layer7 patch and some patch to get iptables 1.2.11
working with kernel 2.6.7)
-patched iptables
-compiled iptables
-activated layer 7 support in kernel-config (and a lot of other packet
classifing options)
-compiled and installed kernel
Now I tried to mark some packets with layer 7 so that I can shape them
with tc afterwards. But nothing changed, outgoing connection still
didn't changed. So I changed the line in the iptables-script to this:
$IPTABLES -t filter -A OUTPUT -m layer7 --l7dir /etc/l7-protocols
--l7proto ftp -j DROP
before it was:
$IPTABLES -t mangle -A POSTROUTING -m layer7 --l7proto ftp -j MARK
--set-mark 322
but nothing of them worked (I could still connect over ftp). The
/proc/net/layer7_numpackets is 08 (don't know which 8 packets got
identified there, but the number is not going any higher).
(BTW: when I use the setting from the NETFILTER HOWTO page:
iptables -t mangle -A POSTROUTING -m layer7 --l7proto http -j MARK
--set-mark 1
and change it (as written in the howto under "blocking") to:
iptables -t mangle -A POSTROUTING -m layer7 --l7proto http -j REJECT
I get an "iptables: Invalid Argument", same with DROP instead of REJECT,
when executing the script, how that? (I must admit that I am not that
iptable expert, so excuse some lack of knowledge of all the chains and
structures ;) )
Any help is really appreciated!
-FB
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: layer 7 netfilter not working
2004-07-09 20:56 layer 7 netfilter not working FB
@ 2004-07-09 21:18 ` Antony Stone
0 siblings, 0 replies; 2+ messages in thread
From: Antony Stone @ 2004-07-09 21:18 UTC (permalink / raw)
To: netfilter
On Friday 09 July 2004 9:56 pm, FB wrote:
> (BTW: when I use the setting from the NETFILTER HOWTO page:
>
> iptables -t mangle -A POSTROUTING -m layer7 --l7proto http -j MARK
> --set-mark 1
>
> and change it (as written in the howto under "blocking") to:
> iptables -t mangle -A POSTROUTING -m layer7 --l7proto http -j REJECT
I'm not too impressed with a HOWTO which recommends the REJECT target for a
rule in the mangle table...
REJECT should be done in the filter tables. mangle tables are for modifying
strange things about packets (such as MARKs).
Sorry I can't offer any specific help regarding the layer7 patch, but I've not
used it.
Maybe some LOGging rules would help you?
Regards,
Antony.
--
Wanted: telepath. You know where to apply.
Please reply to the list;
please don't CC me.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2004-07-09 21:18 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-07-09 20:56 layer 7 netfilter not working FB
2004-07-09 21:18 ` Antony Stone
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox