|
From: Oliver N. <dig...@gm...> - 2007-08-09 22:23:26
|
Hi, again! After a clean build today i tested the new iso - everything looked fine. But i found out that MASQUERADING doesn't work anymore. I didn't change anything, nat/masquerading-modules are all loaded. All i got is an "invalid argument" error. Could it be that the latest layer7 changes broke something? After searching for a while i found the following on the netfilter website: > 3.20 'iptables: Invalid argument' after kernel update (nat table) > > You have just upgraded your kernel and suddenly some of the commands (especially in the 'nat' table), and you experience something like: > > # iptables -A POSTROUTING -t nat -o ppp0 -j MASQUERADE > iptables: Invalid argument > > This happens when the structure size between kernel and userspace changes. > You will need to recompile the iptables userspace program using the include files of your new kernel. > This only happens if you (or the vendor of your kernel) has applied some patches either only to the old or only to the new kernel. > It is not supposed to happen between vanilla kernel.org kernels. If it does, please inform the netfilter-devel mailinglist. I'm a little bit lost here, maybe someone can help to check this? Thanks Oliver |
|
From: Serge L. <fi...@in...> - 2007-08-10 07:03:18
|
Hello Oliver, Oliver Niesner wrote: > Could it be that the latest layer7 changes broke something? ... > I'm a little bit lost here, maybe someone can help to check this? > I'll check and send the report by the end of my day. -- Sincerely Serge Leschinsky |
|
From: Serge L. <fi...@in...> - 2007-08-10 18:47:24
|
Hi Oliver, Oliver Niesner wrote: > Hi, again! > > After a clean build today i tested the new iso - everything looked fine. > But i found out that MASQUERADING doesn't work anymore. > I didn't change anything, nat/masquerading-modules are all loaded. > All i got is an "invalid argument" error. > > Could it be that the latest layer7 changes broke something? I've rebuilt ISO without l7 and got the same error. So, it's not l7. I guess the downgrade iptables from 1.3.8 to 1.3.7 should fix this problem but I consider it as a hot-fix. The proper way is to find what exactly brakes nat functionality (imq patch?). I'll try to fix it ASAP. -- Serge Leschinsky |
|
From: Heiko Z. <he...@zu...> - 2007-08-10 18:59:06
|
On Fri, August 10, 2007 13:46, Serge Leschinsky wrote: > Hi Oliver, > > > Oliver Niesner wrote: > >> Hi, again! >> >> >> After a clean build today i tested the new iso - everything looked >> fine. But i found out that MASQUERADING doesn't work anymore. >> I didn't change anything, nat/masquerading-modules are all loaded. >> All i got is an "invalid argument" error. >> >> >> Could it be that the latest layer7 changes broke something? >> > I've rebuilt ISO without l7 and got the same error. So, it's not l7. I > guess the downgrade iptables from 1.3.8 to 1.3.7 should fix this problem > but I consider it as a hot-fix. The proper way is to find what exactly > brakes nat functionality (imq patch?). > > > I'll try to fix it ASAP. I'm currently updating DL with kernel 2.4.35, that may help too. -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Oliver N. <dig...@gm...> - 2007-08-11 09:41:17
|
> >> I've rebuilt ISO without l7 and got the same error. So, it's not l7. I >> guess the downgrade iptables from 1.3.8 to 1.3.7 should fix this problem >> but I consider it as a hot-fix. The proper way is to find what exactly >> brakes nat functionality (imq patch?). >> >> >> I'll try to fix it ASAP. >> > > I'm currently updating DL with kernel 2.4.35, that may help too. > > Thanks, Serge for verifying this! I think the only problem is that iptables isn't compiled against the right kernel sources. I had no problems with layer7 and iptables-1.3.8 on a 2.6.22 kernel. But i have no experience with 2.4 so far. With a little luck the kernel update from Heiko will do the trick. Let me know if i can help out with testing etc. Oliver |
|
From: Serge L. <fi...@in...> - 2007-08-16 06:23:21
|
Hi, Oliver Niesner wrote: > With a little luck the kernel update from Heiko will do the trick. > Let me know if i can help out with testing etc. Unfortunately kernel update hasn't helped. I made series 'mrproper-build-install-test iso' and may say that the thing which breaks the iptables functionality is patch-o-matic. Now we have to make other series of experiments to find what module does it. I'd like to ask you (if it's possible) to check what group of p-o-m ( Netfilter updates patches Netfilter pending patches Netfilter base patches Netfilter extra patches ) contains 'the bad module'. Your help will be very appreciated! -- Serge Leschinsky |
|
From: Serge L. <fi...@in...> - 2007-08-23 19:26:34
|
Hi, Serge Leschinsky wrote: > Unfortunately kernel update hasn't helped. I made series > 'mrproper-build-install-test iso' and may say that the thing which breaks the > iptables functionality is patch-o-matic. the module which breaks iptables functionality is extra/pptp-conntrack-nat. Should we disable it or try to find update for the module? -- Serge Leschinsky |
|
From: Heiko Z. <he...@zu...> - 2007-08-23 20:33:34
|
On Thu, August 23, 2007 14:26, Serge Leschinsky wrote: > Hi, > > > Serge Leschinsky wrote: > > >> Unfortunately kernel update hasn't helped. I made series >> 'mrproper-build-install-test iso' and may say that the thing which >> breaks the iptables functionality is patch-o-matic. > > the module which breaks iptables functionality is > extra/pptp-conntrack-nat. Should we disable it or try to find update for > the module? Let's first try to find a newer version. -- Regards Heiko Zuerker http://www.devil-linux.org |