forked from extern/shorewall_code
338 lines
22 KiB
HTML
338 lines
22 KiB
HTML
|
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
|||
|
<html>
|
|||
|
<head>
|
|||
|
|
|||
|
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
|
|||
|
<title>Shorewall 1.3 Errata</title>
|
|||
|
|
|||
|
<meta name="GENERATOR" content="Microsoft FrontPage 5.0">
|
|||
|
|
|||
|
<meta name="ProgId" content="FrontPage.Editor.Document">
|
|||
|
|
|||
|
|
|||
|
<meta name="Microsoft Theme" content="radial 011">
|
|||
|
</head>
|
|||
|
<body background="_themes/radial/radbkgnd.gif" bgcolor="#FFFFFF" text="#000000" link="#6666FF" vlink="#993333" alink="#66CCCC"><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
<h1 align="center"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666">Shorewall Errata<!--mstheme--></font></h1>
|
|||
|
|
|||
|
<p align="center">
|
|||
|
<font face="Century Gothic, Arial, Helvetica">
|
|||
|
|
|||
|
<b><u>IMPORTANT</u></b></font></p>
|
|||
|
|
|||
|
<ol>
|
|||
|
<li>
|
|||
|
|
|||
|
<p align="left">
|
|||
|
|
|||
|
<b><u>I</u>f you use a Windows system to download a corrected script, be sure to
|
|||
|
run the script through <u>
|
|||
|
<a href="http://www.megaloman.com/%7Ehany/software/hd2u/" style="text-decoration: none">
|
|||
|
dos2unix</a></u>
|
|||
|
after you have moved it to your Linux system.</b></p>
|
|||
|
|
|||
|
</li>
|
|||
|
<li>
|
|||
|
|
|||
|
<p align="left">
|
|||
|
|
|||
|
<b>If you are installing Shorewall for the first time and plan to use the
|
|||
|
.tgz and install.sh script, you can untar the archive, replace the
|
|||
|
'firewall' script in the untarred directory with the one you downloaded
|
|||
|
below, and then run install.sh.</b></p>
|
|||
|
|
|||
|
</li>
|
|||
|
<li>
|
|||
|
|
|||
|
<p align="left">
|
|||
|
|
|||
|
<b>When the instructions say to install a corrected firewall script in
|
|||
|
/etc/shorewall/firewall or /var/lib/shorewall/firewall, use the 'cp' (or 'scp') utility to overwrite the
|
|||
|
existing file. DO NOT REMOVE OR RENAME THE OLD /etc/shorewall/firewall
|
|||
|
or /var/lib/shorewall/firewall before you do that. /etc/shorewall/firewall
|
|||
|
and /var/lib/shorewall/firewall are symbolic links that point
|
|||
|
to the 'shorewall' file used by your system initialization scripts to
|
|||
|
start Shorewall during boot. It is that file that must be overwritten
|
|||
|
with the corrected script. </b></p>
|
|||
|
|
|||
|
</li>
|
|||
|
</ol>
|
|||
|
|
|||
|
<p align="left">
|
|||
|
|
|||
|
<b> </b></p>
|
|||
|
|
|||
|
<!--mstheme--></font><!--msthemelist--><table border="0" cellpadding="0" cellspacing="0" width="100%">
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
|
|||
|
<b><font color="#660066">
|
|||
|
<a href="errata_1.htm">Problems in Version 1.1</a></font></b><!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
|
|||
|
<b><a href="errata_2.htm">Problems in Version 1.2</a></b><!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
|
|||
|
<b><a href="#V1.3">Problems in Version 1.3</a></b><!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
|
|||
|
<b><font color="#660066"><a href="#iptables">
|
|||
|
Problem with iptables version 1.2.3</a></font></b><!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
|
|||
|
<b><a href="#Debug">Problems with kernel 2.4.18 and
|
|||
|
RedHat iptables</a></b><!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica"><b><a href="#SuSE">Problems installing/upgrading RPM on SuSE SMP</a></b><!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--></table><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
<!--msthemeseparator--><p align="center"><img src="_themes/radial/aradrule.gif" width="614" height="7"></p>
|
|||
|
|
|||
|
<h2 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666"><a name="V1.3"></a>Problems in Version 1.3<!--mstheme--></font></h2>
|
|||
|
|
|||
|
<h3 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666">Versions >= 1.3.5<!--mstheme--></font></h3>
|
|||
|
|
|||
|
<p align="Left">Some forms of pre-1.3.0 rules file syntax are no
|
|||
|
longer supported. </p>
|
|||
|
|
|||
|
<p align="Left">Example 1:</p>
|
|||
|
|
|||
|
<div align="left">
|
|||
|
<!--mstheme--></font><pre> ACCEPT net loc:192.168.1.12:22 tcp 11111 - all</pre><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
</div>
|
|||
|
|
|||
|
<p align="Left">Must be replaced with:</p>
|
|||
|
|
|||
|
<div align="left">
|
|||
|
<!--mstheme--></font><pre> DNAT net loc:192.168.1.12:22 tcp 11111</pre><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
</div>
|
|||
|
<div align="left">
|
|||
|
<p align="left">Example 2:</div>
|
|||
|
<div align="left">
|
|||
|
<!--mstheme--></font><pre> ACCEPT loc fw::3128 tcp 80 - all</pre><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
</div>
|
|||
|
<div align="left">
|
|||
|
<p align="left">Must be replaced with:</div>
|
|||
|
<div align="left">
|
|||
|
<!--mstheme--></font><pre> REDIRECT loc 3128 tcp 80</pre><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
</div>
|
|||
|
|
|||
|
<h3 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666">Version 1.3.5-1.3.5b<!--mstheme--></font></h3>
|
|||
|
|
|||
|
<p align="Left">The new 'proxyarp' interface option doesn't work :-(
|
|||
|
This is fixed in
|
|||
|
<a href="http://www.shorewall.net/pub/shorewall/errata/1.3.5/firewall">
|
|||
|
this corrected firewall script</a> which must be installed in
|
|||
|
/var/lib/shorewall/ as described above.</p>
|
|||
|
|
|||
|
<h3 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666">Versions 1.3.4-1.3.5a<!--mstheme--></font></h3>
|
|||
|
|
|||
|
<p align="Left">Prior to version 1.3.4, host file entries such as the
|
|||
|
following were allowed:</p>
|
|||
|
|
|||
|
<div align="left">
|
|||
|
<!--mstheme--></font><pre> adm eth0:1.2.4.5,eth0:5.6.7.8</pre><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
</div>
|
|||
|
<div align="left">
|
|||
|
<p align="left">That capability was lost in version 1.3.4 so that it is only
|
|||
|
possible to include a single host specification on each line. This
|
|||
|
problem is corrected by
|
|||
|
<a href="http://www.shorewall.net/pub/shorewall/errata/1.3.5a/firewall">this
|
|||
|
modified 1.3.5a firewall script</a>. Install the script in /var/lib/pub/shorewall/firewall
|
|||
|
as instructed above.</div>
|
|||
|
|
|||
|
<div align="left">
|
|||
|
<p align="left">This problem is corrected in version 1.3.5b.</div>
|
|||
|
|
|||
|
<h3 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666">Version 1.3.5<!--mstheme--></font></h3>
|
|||
|
|
|||
|
<p align="Left">REDIRECT rules are broken in this version. Install
|
|||
|
<a href="http://www.shorewall.net/pub/shorewall/errata/1.3.5/firewall">
|
|||
|
this corrected firewall script</a> in /var/lib/pub/shorewall/firewall
|
|||
|
as instructed above. This problem is corrected in version 1.3.5a.</p>
|
|||
|
|
|||
|
<h3 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666">Version 1.3.n, n < 4<!--mstheme--></font></h3>
|
|||
|
|
|||
|
<p align="Left">The "shorewall start" and "shorewall restart" commands
|
|||
|
to not verify that the zones named in the /etc/shorewall/policy file
|
|||
|
have been previously defined in the /etc/shorewall/zones file. The
|
|||
|
"shorewall check" command does perform this verification so it's a
|
|||
|
good idea to run that command after you have made configuration
|
|||
|
changes.</p>
|
|||
|
|
|||
|
<h3 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666">Version 1.3.n, n < 3<!--mstheme--></font></h3>
|
|||
|
|
|||
|
<p align="Left">If you have upgraded from Shorewall 1.2 and after
|
|||
|
"Activating rules..." you see the message: "iptables: No
|
|||
|
chains/target/match by that name" then you probably have an entry in
|
|||
|
/etc/shorewall/hosts that specifies an interface that you didn't
|
|||
|
include in /etc/shorewall/interfaces. To correct this problem, you
|
|||
|
must add an entry to /etc/shorewall/interfaces. Shorewall 1.3.3 and
|
|||
|
later versions produce a clearer error message in this case.</p>
|
|||
|
|
|||
|
<h3 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666">Version 1.3.2<!--mstheme--></font></h3>
|
|||
|
|
|||
|
<p align="Left">Until approximately 2130 GMT on 17 June 2002, the
|
|||
|
download sites contained an incorrect version of the .lrp file. That
|
|||
|
file can be identified by its size (56284 bytes). The correct version
|
|||
|
has a size of 38126 bytes.</p>
|
|||
|
|
|||
|
<!--mstheme--></font><!--msthemelist--><table border="0" cellpadding="0" cellspacing="0" width="100%">
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">The code to detect a duplicate interface entry in
|
|||
|
/etc/shorewall/interfaces contained a typo that prevented it from
|
|||
|
working correctly. <!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">"NAT_BEFORE_RULES=No" was broken; it behaved just like "NAT_BEFORE_RULES=Yes".<!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--></table><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
|
|||
|
<p align="Left">Both problems are corrected in
|
|||
|
<a href="http://www.shorewall.net/pub/shorewall/errata/1.3.2/firewall">
|
|||
|
this script</a> which should be installed in <b><u>/var/lib/shorewall</u></b> as described above.</p>
|
|||
|
|
|||
|
<!--mstheme--></font><!--msthemelist--><table border="0" cellpadding="0" cellspacing="0" width="100%">
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
|
|||
|
<p align="Left">The IANA have just announced the allocation of subnet
|
|||
|
221.0.0.0/8. This
|
|||
|
<a href="http://www.shorewall.net/pub/shorewall/errata/1.3.2/rfc1918">
|
|||
|
updated rfc1918</a> file reflects that allocation.</p>
|
|||
|
|
|||
|
<!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--></table><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
|
|||
|
<h3 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666">Version 1.3.1<!--mstheme--></font></h3>
|
|||
|
|
|||
|
<!--mstheme--></font><!--msthemelist--><table border="0" cellpadding="0" cellspacing="0" width="100%">
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">TCP SYN packets may be double counted when
|
|||
|
LIMIT:BURST is included in a CONTINUE or ACCEPT policy (i.e., each
|
|||
|
packet is sent through the limit chain twice).<!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">An unnecessary jump to the policy chain is sometimes
|
|||
|
generated for a CONTINUE policy.<!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">When an option is given for more than one interface in
|
|||
|
/etc/shorewall/interfaces then depending on the option, Shorewall
|
|||
|
may ignore all but the first appearence of the option. For example:<br>
|
|||
|
<br>
|
|||
|
net eth0 dhcp<br>
|
|||
|
loc eth1 dhcp<br>
|
|||
|
<br>
|
|||
|
Shorewall will ignore the 'dhcp' on eth1.<!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">Update 17 June 2002 - The bug described in the prior bullet
|
|||
|
affects the following options: dhcp, dropunclean, logunclean,
|
|||
|
norfc1918, routefilter, multi, filterping and noping. An additional
|
|||
|
bug has been found that affects only the 'routestopped' option.<br>
|
|||
|
<br>
|
|||
|
Users who downloaded the corrected script prior to 1850 GMT today
|
|||
|
should download and install the corrected script again to ensure
|
|||
|
that this second problem is corrected.<!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--></table><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
|
|||
|
<p align="Left">These problems are corrected in
|
|||
|
<a href="http://www.shorewall.net/pub/shorewall/errata/1.3.1/firewall">
|
|||
|
this firewall script</a> which should be installed in
|
|||
|
/etc/shorewall/firewall as described above.</p>
|
|||
|
|
|||
|
<h3 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666">Version 1.3.0<!--mstheme--></font></h3>
|
|||
|
|
|||
|
<!--mstheme--></font><!--msthemelist--><table border="0" cellpadding="0" cellspacing="0" width="100%">
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">Folks who downloaded 1.3.0 from the links on the download page
|
|||
|
before 23:40 GMT, 29 May 2002 may have downloaded 1.2.13 rather than
|
|||
|
1.3.0. The "shorewall version" command will tell you which version
|
|||
|
that you have installed.<!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">The documentation NAT.htm file uses non-existent
|
|||
|
wallpaper and bullet graphic files. The
|
|||
|
<a href="http://www.shorewall.net/pub/shorewall/errata/1.3.0/NAT.htm">
|
|||
|
corrected version is here</a>.<!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--></table><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
<!--msthemeseparator--><p align="center"><img src="_themes/radial/aradrule.gif" width="614" height="7"></p>
|
|||
|
|
|||
|
<h3 align="Left"><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666"><a name="iptables"></a><font color="#660066">
|
|||
|
Problem with iptables version 1.2.3</font><!--mstheme--></font></h3>
|
|||
|
|
|||
|
<blockquote>
|
|||
|
|
|||
|
<p align="Left">There are a couple of serious bugs in iptables 1.2.3 that
|
|||
|
prevent it from working with Shorewall. Regrettably,
|
|||
|
RedHat released this buggy iptables in RedHat 7.2. </p>
|
|||
|
|
|||
|
<p align="Left"> I have built a <a href="ftp://ftp.shorewall.net/pub/shorewall/errata/iptables-1.2.3-3.i386.rpm">
|
|||
|
corrected 1.2.3 rpm which you can download here</a> and I have also built
|
|||
|
an <a href="ftp://ftp.shorewall.net/pub/shorewall/iptables-1.2.4-1.i386.rpm">
|
|||
|
iptables-1.2.4 rpm which you can download here</a>. If
|
|||
|
you are currently running RedHat 7.1, you can install either of these RPMs
|
|||
|
<b><u>before</u> </b>you upgrade to RedHat 7.2.</p>
|
|||
|
|
|||
|
<p align="Left"><font face="Century Gothic, Arial, Helvetica" color="#FF6633"><b>Update
|
|||
|
11/9/2001: </b></font>RedHat has
|
|||
|
released an iptables-1.2.4 RPM of their own which you can download from<font face="Century Gothic, Arial, Helvetica" color="#FF6633">
|
|||
|
<a href="http://www.redhat.com/support/errata/RHSA-2001-144.html">http://www.redhat.com/support/errata/RHSA-2001-144.html</a>.
|
|||
|
</font>I have installed this RPM
|
|||
|
on my firewall and it works fine.</p>
|
|||
|
|
|||
|
<p align="Left">If you
|
|||
|
would like to patch iptables 1.2.3 yourself, the patches are available
|
|||
|
for download. This <a href="ftp://ftp.shorewall.net/pub/shorewall/errata/iptables-1.2.3/loglevel.patch">patch</a>
|
|||
|
which corrects a problem with parsing of the --log-level specification while
|
|||
|
this <a href="ftp://ftp.shorewall.net/pub/shorewall/errata/iptables-1.2.3/tos.patch">patch</a>
|
|||
|
corrects a problem in handling the TOS target.</p>
|
|||
|
|
|||
|
<p align="Left">To install one of the above patches:</p>
|
|||
|
<!--mstheme--></font><!--msthemelist--><table border="0" cellpadding="0" cellspacing="0" width="100%">
|
|||
|
<!--msthemelist--><tr><td valign="top" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">cd iptables-1.2.3/extensions<!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--><tr><td valign="baseline" width="42"><img src="_themes/radial/aradbul1.gif" width="15" height="15" hspace="13" alt="bullet"></td><td valign="top" width="100%"><!--mstheme--><font face="arial, Arial, Helvetica">patch -p0 < <i>the-patch-file</i><!--mstheme--></font><!--msthemelist--></td></tr>
|
|||
|
<!--msthemelist--></table><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
|
|||
|
</blockquote>
|
|||
|
|
|||
|
<h3><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666"><a name="Debug"></a>Problems with kernel 2.4.18
|
|||
|
and RedHat iptables<!--mstheme--></font></h3>
|
|||
|
<blockquote>
|
|||
|
<p>Users who use RedHat iptables RPMs and who upgrade to kernel 2.4.18 may
|
|||
|
experience the following:</p>
|
|||
|
<blockquote>
|
|||
|
<!--mstheme--></font><pre># shorewall start
|
|||
|
Processing /etc/shorewall/shorewall.conf ...
|
|||
|
Processing /etc/shorewall/params ...
|
|||
|
Starting Shorewall...
|
|||
|
Loading Modules...
|
|||
|
Initializing...
|
|||
|
Determining Zones...
|
|||
|
Zones: net
|
|||
|
Validating interfaces file...
|
|||
|
Validating hosts file...
|
|||
|
Determining Hosts in Zones...
|
|||
|
Net Zone: eth0:0.0.0.0/0
|
|||
|
iptables: libiptc/libip4tc.c:380: do_check: Assertion
|
|||
|
`h->info.valid_hooks == (1 << 0 | 1 << 3)' failed.
|
|||
|
Aborted (core dumped)
|
|||
|
iptables: libiptc/libip4tc.c:380: do_check: Assertion
|
|||
|
`h->info.valid_hooks == (1 << 0 | 1 << 3)' failed.
|
|||
|
Aborted (core dumped)
|
|||
|
</pre><!--mstheme--><font face="arial, Arial, Helvetica">
|
|||
|
</blockquote>
|
|||
|
<p>The RedHat iptables RPM is compiled with debugging enabled but the
|
|||
|
user-space debugging code was not updated to reflect recent changes in the
|
|||
|
Netfilter 'mangle' table. You can correct the problem by installing
|
|||
|
<a href="http://www.shorewall.net/pub/shorewall/iptables-1.2.5-1.i386.rpm">
|
|||
|
this iptables RPM</a>. If you are already running a 1.2.5 version of
|
|||
|
iptables, you will need to specify the --oldpackage option to rpm (e.g.,
|
|||
|
"iptables -Uvh --oldpackage iptables-1.2.5-1.i386.rpm").</p>
|
|||
|
</blockquote>
|
|||
|
|
|||
|
<h3><!--mstheme--><font face="times new roman, Times New Roman, Times" color="#666666"><a name="SuSE"></a>Problems
|
|||
|
installing/upgrading RPM on SuSE SMP<!--mstheme--></font></h3>
|
|||
|
|
|||
|
<p>If you find that rpm complains about a conflict
|
|||
|
with kernel <= 2.2 yet you have a 2.4 kernel
|
|||
|
installed, simply use the "--nodeps" option to
|
|||
|
rpm.</p>
|
|||
|
|
|||
|
<p>Installing: rpm -ivh <i><shorewall rpm></i></p>
|
|||
|
|
|||
|
<p>Upgrading: rpm -Uvh <i><shorewall rpm></i></p>
|
|||
|
|
|||
|
<p><font face="Century Gothic, Arial, Helvetica"><font size="2">
|
|||
|
Last updated 8/4/2002 - </font><font size="2">
|
|||
|
<a href="support.htm">Tom Eastep</a></font>
|
|||
|
</font></p>
|
|||
|
|
|||
|
<p><font face="Trebuchet MS"><a href="copyright.htm"><font size="2">Copyright</font>
|
|||
|
<20> <font size="2">2001, 2002 Thomas M. Eastep.</font></a></font></p>
|
|||
|
|
|||
|
<!--mstheme--></font></body>
|
|||
|
</html>
|