From: Stewart Thompson <stewart.thompson@shaw.ca>
To: Tasha Smith <natasha3641@yahoo.com>, netfilter@lists.netfilter.org
Subject: RE: iptables: exe
Date: Sat, 21 Sep 2002 15:37:45 -0700 [thread overview]
Message-ID: <FLEKIPPLAEDMJMOOBBDPKEGOCPAA.stewart.thompson@shaw.ca> (raw)
In-Reply-To: <20020921211246.84065.qmail@web20302.mail.yahoo.com>
Hi Tasha:
The latest Kernel for Redhat 7.2 is 2.4.9-34.
I would recommend that you upgrade to it. Also,
Iptables 1.24 shipped with 7.2 not 1.23. Also.
1.25 is available on their site. The latest from Netfilter
is 1.27a, but unless you need one of the new features,
you don't require it. I am using 1.24 with great success.
The other thing is to make sure all your packages are up
to date, Iptables is just part of the security. Disable any
functions you don't need on the server.
Now to your problems. Redhat 7.2 shipped with
Ipchains set up as the firewall. Have you disabled it?
They can't both be active at the same time.
Try chown root:root firewall and chmod 775 firewall,
and see if it executes ok on startup. This is in addition
to the advice from Antony.
Hope that helps.
Stu......
-----Original Message-----
From: netfilter-admin@lists.netfilter.org
[mailto:netfilter-admin@lists.netfilter.org]On Behalf Of Tasha Smith
Sent: September 21, 2002 2:13 PM
To: netfilter@lists.netfilter.org
Subject: iptables: exe
Ok...i have my own iptables script trying to get it
going...here what i have soo far in it...just starting
SPECS:
RedHat 7.2
2.4.19 Kernel
iptables-1.2.3
#######################################
#!/bin/bash
echo 1 = > /proc/sys/net/ipv4//ip_forward
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
# Remove any existing rules from all chains.
iptables --flush
iptables -t nat --flush
# Unlimited access on the loopback interface
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUPUT -o lo -j ACCPET
# Set the fefault policy to Drop
iptables --policy INPUT DROP
#######################################
Now... to get this to run on start-up here is what i
did but it didnt start up it gave me an error.
chown root.root /etc/init.d/firewall
chmod u=rwx /etc/init.d /firewall
And when i restart I GET ERROR... which is
"iptables: execvp: Permission Denied
rc. Starting iptables: Failed"
I also have this line sh /etc/init.d/firewall at the
end of my "rc.local" file
HOW CAN I FIX THIS OR GET THEM TO START-UP PROPERLY?
EDIT: > OOPPPPPPSS guys i forgot to mention the
original iptables script that came installed already
on my system in the "/etc/init.d/" i moved that to
somewhere else.... was i suppose to do that or just
leave them there???
=====
Image by MackDaddy
__________________________________________________
Do you Yahoo!?
New DSL Internet Access from SBC & Yahoo!
http://sbc.yahoo.com
next prev parent reply other threads:[~2002-09-21 22:37 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-09-21 21:12 iptables: exe Tasha Smith
2002-09-21 21:28 ` Antony Stone
2002-09-21 22:11 ` Tasha Smith
2002-09-21 22:37 ` Stewart Thompson [this message]
2002-09-21 22:58 ` Tasha Smith
2002-09-21 23:13 ` Stewart Thompson
2002-09-21 22:58 ` Tasha Smith
2002-09-24 20:24 ` internal ftp/port forwarding problem skmail
[not found] <20020921220721.11083.qmail@web20303.mail.yahoo.com>
2002-09-21 22:19 ` iptables: exe Antony Stone
-- strict thread matches above, loose matches on Subject: below --
2002-09-22 1:36 Tasha Smith
2002-09-22 1:57 ` Stewart Thompson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=FLEKIPPLAEDMJMOOBBDPKEGOCPAA.stewart.thompson@shaw.ca \
--to=stewart.thompson@shaw.ca \
--cc=natasha3641@yahoo.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox