Displaying 20 results from an estimated 1000 matches similar to: "CONNMARK target and connmark match support in Ubuntu kernel"
2009 May 26
3
Tinyproxy and shorewall setup
Hello I''m trying to setup tinyproxy and shorewall on a LEAF Bering firewall. What I''d like to do is block all HTTP connections to the internet on port 80 and 8080 and force users to use port 8888.
So in shorewall/rules I have
ACCEPT loc fw tcp 8888
DROP loc fw tcp 80,8080
The ACCEPT works fine but the DROP does not seem to work. If I
2009 May 15
3
Allowing traffic within same zone on multi-subnet interface
Hi list,
I''m struggling with this problem for a long time, hopefully someone
can explain me what I''m doing wrong:
I have a shorewall installation with
interfaces
net eth0
- eth1
hosts
loc 10.0.10.0/24
loc 10.0.20.0/24
+some other zones and subnets
there are aliases on eth1 for gateways for the two loc subnets
eth1:1 10.0.10.1
eth1:2 10.0.20.1
Everything works fine, loc
2009 May 23
0
Shorewall 4.3.11
Shorewall 4.3.11 is now available for testing.
Much of what is in this release is below the surface. Many of the
modules have been reorganized to provide for more readable code and to
eliminate a lot of parameter passing.
----------------------------------------------------------------------------
P R O B L E M S C O R R E C T E D I N 4 . 3 . 11
2004 Sep 24
2
CONNMARK problem
Hello everybody.
i have the folowing problem:
i have this in the top of PREROUTING chain in mangle table
iptables -t mangle -A PREROUTING -j CONNMARK --set-mark 0 # rule 1
iptables -t mangle -A PREROUTING -m connmark --mark 5 # rule 2
iptables -t mangle -A PREROUTING -m connmark --mark 6 # rule 3
i think when packet is passing trough my POSTROUTING in mangle table
2005 Nov 24
1
ftp connmark
I saw this snippet from
Daniel Chemko dchemko@smgtec.com
Mon, 31 May 2004 09:30:43 -0700
# Egress marking (mostly for QOS operations)
iptables -t mangle -A POSTROUTING -j CONNMARK --restore-mark
iptables -t mangle -A POSTROUTING -m mark ! --mark 0 -j ACCEPT
iptables -t mangle -A POSTROUTING -o ${if_inet} --dport 21 -j MARK
--set-mark 0x111
iptables -t mangle -A POSTROUTING -j CONNMARK
2003 Jun 16
3
Questions regarding CONNMARK
Hi there, i have some questions regarding CONNMARK and STRING modules for
netfilter.
I have a stateful firewall doing contraking, because i have two dsl
connections doing load balancing. I have found a way to discriminate KaZaA
traffic flowing via port 80 from normal HTTP traffic using the string match.
I want to mark a kazaa connection and filter ir to a specific qdisc.
I have been looking
2005 Dec 05
1
Connmark question
I am trying to get IPP2P working on my router. Thus far I can see
connections being marked (see below), but they don''t seem to get saved
or something. When looking at /proc/net/ip_conntrack, nothing has
anything other than 0 for mark. The iptables commands for this are:
iptables -t mangle -A PREROUTING -j CONNMARK --restore-mark
iptables -t mangle -A PREROUTING -m mark ! --mark 0 -j
2006 Mar 25
2
Multiple uplink problems
I''ve installed Shorewall 3.0.5 on a Debian Sarge box, and I''m
attempting to route internet traffic through a couple of ISPs, and I''ve
come up against some problems.
The first is that one of my links is a pppoe connection to a wireless
modem, and I can''t configure it to have a static IP address...
therefore I can''t see how I can set up the two
2007 May 09
10
Load balancing using connmark
Hi,
I''ve been implementing a load balancing solution using CONNMARK, based
on solution described by Luciano Ruete at [1]. Gracias por el post y por
apuntar en la dirección correcta Luciano!
Once implemented, I''ve found that due to some reason packets aren''t
properly marked (or improperly remarked) and sent out using the wrong
interface.
My topo setup is:
2017 Mar 10
4
[Bug 1128] New: ip6_tables connmark or connlabel never matches
https://bugzilla.netfilter.org/show_bug.cgi?id=1128
Bug ID: 1128
Summary: ip6_tables connmark or connlabel never matches
Product: netfilter/iptables
Version: unspecified
Hardware: x86_64
OS: SuSE Linux
Status: NEW
Severity: normal
Priority: P5
Component: ip6_tables (kernel)
2004 Jul 07
1
connmark+connbytes
Hello!
Maybe someone needs connmark and connbytes working together?
See attached file compatible with pom-ng-20040621 (I called it
connmarkbytes :)).
Kind Regards,
Tomasz Chilinski
2007 Aug 04
3
CONNMARK and CentOS4
Hi All,
It''s an old problem and still isn''t fixed :( I need the connection
marking support to enable the triplet of ISP''s we use. However, I
downloaded the latest 2.6.22.1 kernel, made an RPM and installed it. I
see the following kernel modules (which looks promising):
/lib/modules/2.6.22.1/kernel/net/netfilter
xt_connmark.ko
xt_CONNMARK.ko
Which yields the
2004 Dec 05
13
Adding dynamically more than one host at once?
Hi,
it seems not to be possible to add more than one host at once to a zone.
So
shorewall add br0:eth0:192.168.2.10,eth0:192.168.2.11 work
fails, since "br0:eth0:192.168.2.10,eth0" is interpreted as one interface.
--snip --
iptables v1.2.9: interface name `eth0:192.168.2.10,eth0'' must be shorter
than IFNAMSIZ (15)
Try `iptables -h'' or ''iptables
2004 Nov 06
2
Upgrade from Hell
For those of you running SuSE 9.1, I do not recommend upgrading to 9.2
at this time.
Refer to http://shorewall.net/myfiles.htm for information on my
configuration:
a) On Ursa:
1) After the upgrade, both of the NICs were recognized as "configured"
in YAST yet neither of them would start; ifup claimed that no
configuration could be found for either interface. Only got them running
2004 Feb 13
6
Error: Rate Limiting only available with ACCEPT, DNAT[-], REDIRECT[-] and LOG
I think it would be nice to be able to rate limit an action, too..
suppose I have an action named Accept_good_source :
ACCEPT - - tcp - 1024:65535
ACCEPT - - udp - 1024:65535
and that i want to use it in an action called AllowCVS,
i can''t limit the cvs usage, but only the general use of
Accept_good_source...
same goes for userset...
as each rule will give one iptables command,
I
2007 May 10
0
FW: Load balancing using connmark
-----Original Message-----
From: Salim S I [mailto:salim.si@cipherium.com.tw]
Sent: Thursday, May 10, 2007 5:22 PM
To: ''Francis Brosnan Blazquez''
Subject: RE: [LARTC] Load balancing using connmark
"I think the main advantage of shorewall solution is that it applies
connmark to incoming packets from the wan as you point, leaving load
balancing to outgoing connections to the
2006 Sep 20
0
Ipp2p with connmark
Hi,
I want to classify with ipp2p packets that I''ve captured with tcpdump.
I send the packets with tcpreply.
I had to create a bridge interface in order to enable the listening
interface in promiscous mode
and to classify the traffic mirrored to that.
In this mode the traffic pass through the prerouting chain of the mangle
table (on bridge).
I want to used connmark for recognized flows,
2005 Dec 09
0
Use of CONNMARK in Multiple Internet Links
What are the pros and cons of using CONNMARK along with the Multiple ISP
Links and Load Balancing method as suggested in the HOWTO and with
Julian''s patches for Dead Gateway Detection ? I have been observing
excellent results without the CONNMARK rules. How is the performance
affected if CONNMARK is used ?
Thanks,
Manish
2008 Apr 11
0
Is iptables -j CONNMARK not available in CentOS4??
Hi,
I'm running CentOS 4 with most of the latest updates, but am having trouble
with iptables and the CONNMARK target. Is it available in the CentOS 4
kernel?
Running on i386:
kernel: 2.6.9-67.0.4.ELsmp
iptables: v1.2.11
# iptables -t mangle -A PREROUTING -j CONNMARK --set-mark 1
iptables: No chain/target/match by that name
I see I do have the CONNMARK lib in
2003 Jan 15
5
HTB. QoS and Shorewall
Group,
I am reading about tc (traffic control) and willing to get my feet wet. As requirement, there should be HTB compiled in the kernel. I grabbed a Mandrake 8.2 distro, and didn''t installed the kernel source.
Anyone knows if the HTB is compiled in Mandrake 8.2, or point a way to find that out? I tried to read the /usr/src/kernel.xxxxx/.config file, but it doesn''t exists.