You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(59) |
Sep
(57) |
Oct
(5) |
Nov
(45) |
Dec
(21) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(13) |
Feb
(22) |
Mar
(14) |
Apr
(7) |
May
(33) |
Jun
(57) |
Jul
(25) |
Aug
(40) |
Sep
(53) |
Oct
(58) |
Nov
(75) |
Dec
(22) |
| 2003 |
Jan
(101) |
Feb
(101) |
Mar
(103) |
Apr
(125) |
May
(85) |
Jun
(57) |
Jul
(62) |
Aug
(42) |
Sep
(76) |
Oct
(214) |
Nov
(290) |
Dec
(274) |
| 2004 |
Jan
(187) |
Feb
(172) |
Mar
(313) |
Apr
(209) |
May
(169) |
Jun
(147) |
Jul
(118) |
Aug
(193) |
Sep
(227) |
Oct
(125) |
Nov
(246) |
Dec
(191) |
| 2005 |
Jan
(244) |
Feb
(175) |
Mar
(165) |
Apr
(130) |
May
(217) |
Jun
(122) |
Jul
(188) |
Aug
(235) |
Sep
(165) |
Oct
(133) |
Nov
(209) |
Dec
(88) |
| 2006 |
Jan
(66) |
Feb
(89) |
Mar
(108) |
Apr
(91) |
May
(29) |
Jun
(45) |
Jul
(64) |
Aug
(42) |
Sep
(44) |
Oct
(81) |
Nov
(64) |
Dec
(9) |
| 2007 |
Jan
(24) |
Feb
(122) |
Mar
(55) |
Apr
(50) |
May
(84) |
Jun
(13) |
Jul
(80) |
Aug
(70) |
Sep
(78) |
Oct
(45) |
Nov
(56) |
Dec
(42) |
| 2008 |
Jan
(65) |
Feb
(3) |
Mar
(51) |
Apr
(151) |
May
(54) |
Jun
(72) |
Jul
(73) |
Aug
(47) |
Sep
(55) |
Oct
(123) |
Nov
(16) |
Dec
(4) |
| 2009 |
Jan
(23) |
Feb
(39) |
Mar
(27) |
Apr
(36) |
May
(35) |
Jun
(51) |
Jul
(11) |
Aug
(14) |
Sep
(40) |
Oct
(67) |
Nov
(38) |
Dec
(13) |
| 2010 |
Jan
(15) |
Feb
(35) |
Mar
(40) |
Apr
(11) |
May
(26) |
Jun
(10) |
Jul
(5) |
Aug
(50) |
Sep
(86) |
Oct
(67) |
Nov
(36) |
Dec
(11) |
| 2011 |
Jan
(50) |
Feb
(6) |
Mar
(13) |
Apr
(13) |
May
(29) |
Jun
(27) |
Jul
(26) |
Aug
(27) |
Sep
(21) |
Oct
(7) |
Nov
(27) |
Dec
(4) |
| 2012 |
Jan
(11) |
Feb
(20) |
Mar
(48) |
Apr
(18) |
May
(8) |
Jun
(19) |
Jul
|
Aug
(15) |
Sep
(3) |
Oct
(4) |
Nov
(5) |
Dec
(1) |
| 2013 |
Jan
(13) |
Feb
(7) |
Mar
(4) |
Apr
(25) |
May
(2) |
Jun
(8) |
Jul
(4) |
Aug
(8) |
Sep
(7) |
Oct
|
Nov
(5) |
Dec
(10) |
| 2014 |
Jan
|
Feb
|
Mar
(6) |
Apr
(20) |
May
(5) |
Jun
|
Jul
(2) |
Aug
|
Sep
(8) |
Oct
(21) |
Nov
(4) |
Dec
(7) |
| 2015 |
Jan
(10) |
Feb
(9) |
Mar
(4) |
Apr
|
May
|
Jun
|
Jul
|
Aug
(5) |
Sep
(11) |
Oct
|
Nov
(17) |
Dec
(32) |
| 2016 |
Jan
(10) |
Feb
(15) |
Mar
(4) |
Apr
(7) |
May
(10) |
Jun
(11) |
Jul
(15) |
Aug
(26) |
Sep
(13) |
Oct
(10) |
Nov
(16) |
Dec
(6) |
| 2017 |
Jan
(9) |
Feb
(3) |
Mar
|
Apr
(2) |
May
(2) |
Jun
|
Jul
|
Aug
(3) |
Sep
(3) |
Oct
(6) |
Nov
(8) |
Dec
|
| 2018 |
Jan
(12) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Serge L. <fi...@in...> - 2007-08-06 06:11:28
|
Hi Dmitry, Dmitry Komarov wrote: > > Could you please also help me with an idea on how should I activate the > loop-AES module in 1.3.xx? Do you still need a help with loop-AES in 1.3? I did a small test and it seems to work now. -- Serge Leschinsky |
|
From: Mgr. M. J. <mai...@vc...> - 2007-08-02 08:48:16
|
Dood day. I am using testing version 1.2.14-2007-03-05 and all these files are presented. ls -l /etc/squid.conf /etc/mime.conf /etc/man.conf -rw-r--r-- 1 root root 4583 Jan 1 1980 /etc/man.conf -rw-r--r-- 1 root root 11651 Jan 1 1980 /etc/mime.conf -rw-r--r-- 1 root root 148542 Jan 1 1980 /etc/squid.conf Jiri Motycka Goldorak napsal(a): > Hello, > > I am using Devil-linux for 2 weeks now, I am still > busy configuring everything, and First I would like to > thank you all for this fine work :) > > I just notice 3 important files missing. > - a squid.conf (maybe it will be nice to add it in > /etc or in /usr/share/doc/ like for vsftpd.conf) > - for squid, its also missing the mine.conf > > - and a man.conf file in /etc. > > Hope It was a good idea to tell you about it. > > Kind Regards, > > > > > > > _____________________________________________________________________________ > Ne gardez plus qu'une seule adresse mail ! Copiez vos mails vers Yahoo! Mail > > ------------------------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. > Still grepping through log files to find problems? Stop. > Now Search log events and configuration files using AJAX and a browser. > Download your FREE copy of Splunk now >> http://get.splunk.com/ > _______________________________________________ > Devil-linux-discuss mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-discuss > > |
|
From: Goldorak <kol...@ya...> - 2007-08-02 00:16:50
|
Hello,
I am using Devil-linux for 2 weeks now, I am still
busy configuring everything, and First I would like to
thank you all for this fine work :)
I just notice 3 important files missing.
- a squid.conf (maybe it will be nice to add it in
/etc or in /usr/share/doc/ like for vsftpd.conf)
- for squid, its also missing the mine.conf
- and a man.conf file in /etc.
Hope It was a good idea to tell you about it.
Kind Regards,
_____________________________________________________________________________
Ne gardez plus qu'une seule adresse mail ! Copiez vos mails vers Yahoo! Mail
|
|
From: Serge L. <fi...@in...> - 2007-07-31 10:34:47
|
Hi, Mgr. Motycka Jiri wrote: ... > but my syslog started to fill up with some strange errors and packet > lists like this: > > Jul 30 14:19:27 aaa@Devil kernel: layer7: regexec positive: http! > Jul 30 14:19:27 aaa@Devil kernel: > Jul 30 14:19:27 aaa@Devil kernel: l7-filter gave up after 625 bytes (11 > packets): .... > Isn't here (in layer7 kernel module) swithed on some debuging? Yes, obviously layer7 kernel module is compiled with debug. I guess we have to disable this. > What does the message "l7-filter gave up after XXX bytes (YY packets)" > means? > Does anybody knows ? It means that filter was able to classify traffic only after 11 packets ( 625 bytes) had been captured. Since l7-filter functionality is based on traffic inspection it's unable to classify one immediately - only after some preprocessing. So exactly this kernel module writes to log. -- Serge Leschinsky |
|
From: Jan H. P. <jh...@jh...> - 2007-07-31 10:33:49
|
Serge Leschinsky wrote:
Hi,
> Surely. It's a quite trivial 3-lines patch. But now I'm building the system to
> be sure nothing was broken ("make config" freeze for kernel, for example). This
> process takes a lot of time due to my build box performance.
> Actually I don't expect any problem, but the preliminary test should be done anyway.
>
> I can send you the diff if you are ready to check it by yourself.
>
>
You can sureley sent me the patch and the needed tarball, then I will
test it for you.
No problem.
That make config freezes is because it sees some extra options and wants
some input on that.
Instead of make oldconfig you could also just add the needed extra lines
to the .config file. That should do the trick.
Jan Hugo
|
|
From: Serge L. <fi...@in...> - 2007-07-31 10:15:03
|
Hi,
Jan Hugo Prins wrote:
> It should be relativly easy to fix by putting a tar file with the
> correct patches in it.
> It just fails to patch the kernel because the patch set that is in the
> tarball is for an older kernel.
>
Surely. It's a quite trivial 3-lines patch. But now I'm building the system to
be sure nothing was broken ("make config" freeze for kernel, for example). This
process takes a lot of time due to my build box performance.
Actually I don't expect any problem, but the preliminary test should be done anyway.
I can send you the diff if you are ready to check it by yourself.
--
Serge Leschinsky
|
|
From: Jan H. P. <jh...@jh...> - 2007-07-31 07:31:35
|
Serge Leschinsky wrote: > Hi, > > Fred Frigerio wrote: > > >> Yesterday evening I tried some rules on my firewall (DL 1.3.4) but I >> constantly get the following error: >> >> root@Devil:~ # iptables -t mangle -A POSTROUTING -m layer7 --l7proto >> http -j ACCEPT >> iptables: No chain/target/match by that name >> >> The l7 stuff is selected in make menuconfig and iptables seems to have >> the support for it, but I got the idea that there are some kernel >> modules missing or something. >> I expected some layer7 kernel modules but there is none in /lib/modules. >> > > Thank you for the report. I'm afraid l7 is broken in 1.3.4 because I've got the > same result. I've started custom build to check it and hopefully it will be > fixed and ready for download by Tuesday. > It should be relativly easy to fix by putting a tar file with the correct patches in it. It just fails to patch the kernel because the patch set that is in the tarball is for an older kernel. Jan Hugo |
|
From: Mgr. M. J. <mai...@vc...> - 2007-07-30 13:35:36
|
Thank you for your hint.
I tried this:
iptables -I FORWARD -m layer7 --l7proto http
ip_conntrack was loaded, part of lsmod:
ipt_layer7 10496 1 (autoclean)
iptable_nat 18014 1 (autoclean)
ipt_state 504 10 (autoclean)
ip_conntrack 21568 0 (autoclean) [ipt_layer7 iptable_nat
ipt_state]
iptable_filter 1644 1 (autoclean)
ipt_LOG 3512 18 (autoclean)
ipt_limit 920 18 (autoclean)
iptable_mangle 2072 1 (autoclean)
ip_tables 13088 9 [ipt_layer7 iptable_nat ipt_state
iptable_filter ipt_LOG ipt_limit iptable_mangle]
....
And this layer7 rule started to catch packets:
8070 6076607 0 -- * *
0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto http
but my syslog started to fill up with some strange errors and packet
lists like this:
Jul 30 14:19:27 aaa@Devil kernel: layer7: regexec positive: http!
Jul 30 14:19:27 aaa@Devil kernel:
Jul 30 14:19:27 aaa@Devil kernel: l7-filter gave up after 625 bytes (11
packets):
Jul 30 14:19:27 aaa@Devil kernel: ..@.. edebfaenebfccacacacacacacacacaad
.. .......(oe`........(o.. ..l ...@.. edebfaenebfccacacacacacacacacaad
.. .......(o..@.. edebfaenebfccacacacacacacacacaad ..
.......(oe`g.......(o.. ..l ...@.. edebfaenebfccacacacacacacacacaad ..
.......(o..@.. edebfaenebfccacacacacacacacacaad ..
.......(oe`q.......(o.. ..l ...@.. edebfaenebfccacacacacacacacacaad ..
.......(o..@.. faeddbdbdadadhdidhddcacacacacaad .. .......(oe`....
...(o.. ..l....@.. faeddbdbdadadhdidhddcacacacacaad .. .......(o..@..
faeddbdbdadadhdidhddcacacacacaad .. .......(oe`........(o.. ..l....@..
faeddbdbdadadhdidhddcacacacacaad .. .......(o
Isn't here (in layer7 kernel module) swithed on some debuging?
What does the message "l7-filter gave up after XXX bytes (YY packets)"
means?
Does anybody knows ?
Jiri Motycka
Serge Leschinsky napsal(a):
> Hi,
>
> Mgr. Motycka Jiri wrote:
>
>
>> BTW: Has anybody any experiences with layer7 in DL?
>>
> Yes. I used it some time ago - with ver. 1.2.9
>
>
>> I made one simple firewall rule which should block rtsp protocol and
>> this rule blocks nothing and content of the packets sends to the syslog ?
>> Does anybody know why ?
>>
>> This is the rule:
>> $IPTABLES -t mangle -A POSTROUTING -m layer7 --l7proto rtsp -j DROP
>>
> One thing was unexpected for me - it's ip_conntrack module. It should be loaded.
>
> So, you can check the l7-filter functionality by executing the command
> iptables -A OUTPUT -m layer7 --l7proto http
> and checking the counters (iptables -nvL) after downloading. As I said before,
> don't omit ip_conntrack module loading please.
>
> --
> Serge Leschinsky
>
>
> -------------------------------------------------------------------------
> This SF.net email is sponsored by: Splunk Inc.
> Still grepping through log files to find problems? Stop.
> Now Search log events and configuration files using AJAX and a browser.
> Download your FREE copy of Splunk now >> http://get.splunk.com/
> _______________________________________________
> Devil-linux-discuss mailing list
> Dev...@li...
> https://lists.sourceforge.net/lists/listinfo/devil-linux-discuss
>
>
|
|
From: Heiko Z. <he...@zu...> - 2007-07-30 12:43:39
|
On Sat, July 28, 2007 17:01, Jan Hugo Prins wrote: > Heiko Zuerker wrote: > >> Make sure you load all the needed modules via modprobe. >> >> >> > I could do that if the modules were actually there. But the problem was > that the netfilter Layer7 patches that are in the 1.3.4 build don't match > the kernel version that is in this build. I am currently trying what > happens if I take the latest version of the kernel (2.6.22.1) with the > latest Layer7 patch set that matches this kernel. > >> There's no built in way to change the config, you'll have to hack >> something. Are the changes something other people would need too? If >> yes, then we can change it in CVS. >> >> > What I'm thinking about is creating a static kernel specific for my > system without module support. I don't think a lot of people will have > exactly the same system. > > But is the config that the kernel is build with somewhere in the build > tree, or is this config generated at build time? The kernel config is pieced together at build time from a couple files in build/scripts/config/2.6 You'll have to modify these files. -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Serge L. <fi...@in...> - 2007-07-30 10:57:28
|
Dmitry Komarov wrote: > Thank you very much! Just wasn't sure if I do the things the right way. > > Could you please also help me with an idea on how should I activate the > loop-AES module in 1.3.xx? > The best idea is to look at the script how the module is built, installed etc. Since I never used loop-AES i don't know how to check it. After I fix the l7 filter I'll try to study loop-AES features and be able to answer you in more detail. -- Serge Leschinsky |
|
From: Serge L. <fi...@in...> - 2007-07-30 10:55:38
|
Hi, Fred Frigerio wrote: > Yesterday evening I tried some rules on my firewall (DL 1.3.4) but I > constantly get the following error: > > root@Devil:~ # iptables -t mangle -A POSTROUTING -m layer7 --l7proto > http -j ACCEPT > iptables: No chain/target/match by that name > > The l7 stuff is selected in make menuconfig and iptables seems to have > the support for it, but I got the idea that there are some kernel > modules missing or something. > I expected some layer7 kernel modules but there is none in /lib/modules. Thank you for the report. I'm afraid l7 is broken in 1.3.4 because I've got the same result. I've started custom build to check it and hopefully it will be fixed and ready for download by Tuesday. -- Serge Leschinsky |
|
From: Serge L. <fi...@in...> - 2007-07-30 10:54:59
|
Hi, Mgr. Motycka Jiri wrote: > BTW: Has anybody any experiences with layer7 in DL? Yes. I used it some time ago - with ver. 1.2.9 > I made one simple firewall rule which should block rtsp protocol and > this rule blocks nothing and content of the packets sends to the syslog ? > Does anybody know why ? > > This is the rule: > $IPTABLES -t mangle -A POSTROUTING -m layer7 --l7proto rtsp -j DROP One thing was unexpected for me - it's ip_conntrack module. It should be loaded. So, you can check the l7-filter functionality by executing the command iptables -A OUTPUT -m layer7 --l7proto http and checking the counters (iptables -nvL) after downloading. As I said before, don't omit ip_conntrack module loading please. -- Serge Leschinsky |
|
From: Jan H. P. <jh...@jh...> - 2007-07-28 22:01:56
|
Heiko Zuerker wrote: > Make sure you load all the needed modules via modprobe. > > I could do that if the modules were actually there. But the problem was that the netfilter Layer7 patches that are in the 1.3.4 build don't match the kernel version that is in this build. I am currently trying what happens if I take the latest version of the kernel (2.6.22.1) with the latest Layer7 patch set that matches this kernel. > There's no built in way to change the config, you'll have to hack something. > Are the changes something other people would need too? If yes, then we can > change it in CVS. > > What I'm thinking about is creating a static kernel specific for my system without module support. I don't think a lot of people will have exactly the same system. But is the config that the kernel is build with somewhere in the build tree, or is this config generated at build time? Jan Hugo |
|
From: Fred F. <ffr...@lo...> - 2007-07-28 14:02:55
|
Filtering out Kazaa and friends while still allowing a permisive inside to outside firewall is something I like. On the other hand I should probably be running a proxy and blocking everything from the inside except what is allowed.=20 Fred Frigerio Locust USA =20 This electronic message transmission contains information from Locust USA which may be confidential or privileged. The information is intended to be for the use of the individual or entity named above. If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this information is prohibited. If you have received this electronic transmission in error, please notify us by telephone (305-889-5410) or by reply via electronic mail immediately. -----Original Message----- From: dev...@li... [mailto:dev...@li...] On Behalf Of Heiko Zuerker Sent: Saturday, July 28, 2007 9:55 AM To: dev...@li... Subject: Re: [Devil-Linux-discuss] P2p traffic filtering On Sat, July 28, 2007 05:34, Jan Hugo Prins wrote: > Mgr. Motycka Jiri wrote: > >> Hi. >> >> >> Try to download testing version 1.2.14. Some time before I already=20 >> announce this problem and Heiko solved it by making a new version=20 >> where these libraries was presented. You can downloaded it from here: >> ftp://ftp.devil-linux.org/pub/devel/testing/ >> >> >> (libipt_ipp2p.so and libipt_layer7.so are in directory >> /usr/lib/iptables) >> >> >> BTW: Has anybody any experiences with layer7 in DL? >> I made one simple firewall rule which should block rtsp protocol and=20 >> this rule blocks nothing and content of the packets sends to the=20 >> syslog ? >> Does anybody know why ? >> >> >> This is the rule: >> $IPTABLES -t mangle -A POSTROUTING -m layer7 --l7proto rtsp -j DROP >> >> >> Jiri Motycka >> >> >> >> > Yesterday evening I tried some rules on my firewall (DL 1.3.4) but I=20 > constantly get the following error: > > root@Devil:~ # iptables -t mangle -A POSTROUTING -m layer7 --l7proto=20 > http -j ACCEPT iptables: No chain/target/match by that name > > > The l7 stuff is selected in make menuconfig and iptables seems to have > the support for it, but I got the idea that there are some kernel=20 > modules missing or something. I expected some layer7 kernel modules=20 > but there is none in /lib/modules. Make sure you load all the needed modules via modprobe. > This is as far as I have come with this. > > > By the way, is it possible / easy to make a custom kernel config? What > are the steps that I should take to make this happen? I suppose that I > should take a kernel tree and do a make menuconfig and put the=20 > resulting config file in some special place or something? What patches > are by default patched into the kernel tree before starting the build? There's no built in way to change the config, you'll have to hack something. Are the changes something other people would need too? If yes, then we can change it in CVS. --=20 Regards Heiko Zuerker http://www.devil-linux.org ------------------------------------------------------------------------ - This SF.net email is sponsored by: Splunk Inc. Still grepping through log files to find problems? Stop. Now Search log events and configuration files using AJAX and a browser. Download your FREE copy of Splunk now >> http://get.splunk.com/ _______________________________________________ Devil-linux-discuss mailing list Dev...@li... https://lists.sourceforge.net/lists/listinfo/devil-linux-discuss |
|
From: Heiko Z. <he...@zu...> - 2007-07-28 13:55:14
|
On Sat, July 28, 2007 05:34, Jan Hugo Prins wrote: > Mgr. Motycka Jiri wrote: > >> Hi. >> >> >> Try to download testing version 1.2.14. Some time before I already >> announce this problem and Heiko solved it by making a new version where >> these libraries was presented. You can downloaded it from here: >> ftp://ftp.devil-linux.org/pub/devel/testing/ >> >> >> (libipt_ipp2p.so and libipt_layer7.so are in directory >> /usr/lib/iptables) >> >> >> BTW: Has anybody any experiences with layer7 in DL? >> I made one simple firewall rule which should block rtsp protocol and >> this rule blocks nothing and content of the packets sends to the syslog >> ? >> Does anybody know why ? >> >> >> This is the rule: >> $IPTABLES -t mangle -A POSTROUTING -m layer7 --l7proto rtsp -j DROP >> >> >> Jiri Motycka >> >> >> >> > Yesterday evening I tried some rules on my firewall (DL 1.3.4) but I > constantly get the following error: > > root@Devil:~ # iptables -t mangle -A POSTROUTING -m layer7 --l7proto > http -j ACCEPT iptables: No chain/target/match by that name > > > The l7 stuff is selected in make menuconfig and iptables seems to have > the support for it, but I got the idea that there are some kernel modules > missing or something. I expected some layer7 kernel modules but there is > none in /lib/modules. Make sure you load all the needed modules via modprobe. > This is as far as I have come with this. > > > By the way, is it possible / easy to make a custom kernel config? What > are the steps that I should take to make this happen? I suppose that I > should take a kernel tree and do a make menuconfig and put the resulting > config file in some special place or something? What patches are by > default patched into the kernel tree before starting the build? There's no built in way to change the config, you'll have to hack something. Are the changes something other people would need too? If yes, then we can change it in CVS. -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Fred F. <ffr...@lo...> - 2007-07-28 12:15:42
|
Did you download the newer version? Did you check un /usr/lib/iptables for the shared library file? I haven't had a chance to do that yet. The easiest way to check to see if things are there is to do iptables -m layer7 --help which should give you help if the module is there and a descriptive error of what is not working if it isn't. The kernel module is ipt_layer7 which is under kernel/net/netfilter (from memory so I may be missing something). > Hi. > > Try to download testing version 1.2.14. Some time before I already=20 > announce this problem and Heiko solved it by making a new version=20 > where these libraries was presented. You can downloaded it from here: > ftp://ftp.devil-linux.org/pub/devel/testing/ > > (libipt_ipp2p.so and libipt_layer7.so are in directory=20 > /usr/lib/iptables) > > BTW: Has anybody any experiences with layer7 in DL? > I made one simple firewall rule which should block rtsp protocol and=20 > this rule blocks nothing and content of the packets sends to the syslog ? > Does anybody know why ? > > This is the rule: > $IPTABLES -t mangle -A POSTROUTING -m layer7 --l7proto rtsp -j DROP > > Jiri Motycka > > > =20 Yesterday evening I tried some rules on my firewall (DL 1.3.4) but I constantly get the following error: root@Devil:~ # iptables -t mangle -A POSTROUTING -m layer7 --l7proto http -j ACCEPT iptables: No chain/target/match by that name The l7 stuff is selected in make menuconfig and iptables seems to have the support for it, but I got the idea that there are some kernel modules missing or something. I expected some layer7 kernel modules but there is none in /lib/modules. This is as far as I have come with this. By the way, is it possible / easy to make a custom kernel config? What are the steps that I should take to make this happen? I suppose that I should take a kernel tree and do a make menuconfig and put the resulting config file in some special place or something? What patches are by default patched into the kernel tree before starting the build? Greetings, Jan Hugo Prins ------------------------------------------------------------------------ - This SF.net email is sponsored by: Splunk Inc. Still grepping through log files to find problems? Stop. Now Search log events and configuration files using AJAX and a browser. Download your FREE copy of Splunk now >> http://get.splunk.com/ _______________________________________________ Devil-linux-discuss mailing list Dev...@li... https://lists.sourceforge.net/lists/listinfo/devil-linux-discuss |
|
From: Jan H. P. <jh...@jh...> - 2007-07-28 10:34:49
|
Mgr. Motycka Jiri wrote: > Hi. > > Try to download testing version 1.2.14. Some time before I already > announce this problem and Heiko solved it by making a new version where > these libraries was presented. You can downloaded it from here: > ftp://ftp.devil-linux.org/pub/devel/testing/ > > (libipt_ipp2p.so and libipt_layer7.so are in directory /usr/lib/iptables) > > BTW: Has anybody any experiences with layer7 in DL? > I made one simple firewall rule which should block rtsp protocol and > this rule blocks nothing and content of the packets sends to the syslog ? > Does anybody know why ? > > This is the rule: > $IPTABLES -t mangle -A POSTROUTING -m layer7 --l7proto rtsp -j DROP > > Jiri Motycka > > > Yesterday evening I tried some rules on my firewall (DL 1.3.4) but I constantly get the following error: root@Devil:~ # iptables -t mangle -A POSTROUTING -m layer7 --l7proto http -j ACCEPT iptables: No chain/target/match by that name The l7 stuff is selected in make menuconfig and iptables seems to have the support for it, but I got the idea that there are some kernel modules missing or something. I expected some layer7 kernel modules but there is none in /lib/modules. This is as far as I have come with this. By the way, is it possible / easy to make a custom kernel config? What are the steps that I should take to make this happen? I suppose that I should take a kernel tree and do a make menuconfig and put the resulting config file in some special place or something? What patches are by default patched into the kernel tree before starting the build? Greetings, Jan Hugo Prins |
|
From: Dmitry K. <dm...@dz...> - 2007-07-26 12:59:07
|
Thank you very much! Just wasn't sure if I do the things the right way. Could you please also help me with an idea on how should I activate the loop-AES module in 1.3.xx? The problem is that with DL 1.2.xx it was compiled in and activated by default. But with 1.3 I see that it was built, somehow installed (??) but I have no idea if it was really put to the compiled system, as I can't see it neither during bootup nor in modules dir. Thank you in advance! On Thursday 26 July 2007 15:45, Serge Leschinsky wrote: > Dmitry Komarov wrote: > > One more question. Suppose I have built a system. Then I want to enable > > some more packages via menuconfig. Is it enough to do it this way: > > > > make menuconfig > > make clean > > rm tmp/.done_build_packagename > > rm tmp/.done_install_packagename > > make prepare build install > > or just do the following: > > sh scripts/build.sh build opt=packagename > sh scripts/build.sh install opt=packagename > > The result should be the same to aforementioned. > > > Or I have to go through this long way - mrproper, unpack etc? > > It's a more right way. Actually I use it if I need to build production > system. In all other cases you can use the commands I sent and save a lot > of time. -- Best regards, Dmitry Komarov -- Best regards, Dmitry Komarov IT Project Manager SIA CITYNET 22/24 - 500 Katolu str. Riga, LV-1003 Latvia |
|
From: Serge L. <fi...@in...> - 2007-07-26 12:46:04
|
Dmitry Komarov wrote: > One more question. Suppose I have built a system. Then I want to enable some > more packages via menuconfig. Is it enough to do it this way: > > make menuconfig > make clean > rm tmp/.done_build_packagename > rm tmp/.done_install_packagename > make prepare build install or just do the following: sh scripts/build.sh build opt=packagename sh scripts/build.sh install opt=packagename The result should be the same to aforementioned. > > Or I have to go through this long way - mrproper, unpack etc? It's a more right way. Actually I use it if I need to build production system. In all other cases you can use the commands I sent and save a lot of time. -- Serge Leschinsky |
|
From: Dmitry K. <dm...@dz...> - 2007-07-26 11:46:56
|
Lots of thanx for the help! It was really usefull and saved me lots of time! I finally got it compiled and booting. Want to mention one little thing about parallel building. As it was already told it is not working as expected. But enabling this really speeds up compiling process almost twice if you have an SMP or dual core CPU. I just had to rerun "make build" when it crashed at some places. As far as I see the final system has no visible affect of this. One more question. Suppose I have built a system. Then I want to enable some more packages via menuconfig. Is it enough to do it this way: make menuconfig make clean rm tmp/.done_build_packagename rm tmp/.done_install_packagename make prepare build install Or I have to go through this long way - mrproper, unpack etc? On Thursday 26 July 2007 08:05, Serge Leschinsky wrote: > Hi, > > Dmitry Komarov wrote: > > What exactly do you mean by replacing syslinux with version .36? > > > > There is only syslinux-3.51 version on the site. Should I find an older > > syslinux-3.36 somewhere else? > > please get it from > http://www.kernel.org/pub/linux/utils/boot/syslinux/Old/syslinux-3.36.tar.b >z2 > > > And how exactly should I replace it? Rename to > > syslinux-3.51 and put in src folder and "make unpack" then? > > delete syslinux-3.51 tarball from src dir and then put 3.36. > > "make mrproper unpack prepare build" -- Best regards, Dmitry Komarov -- Best regards, Dmitry Komarov IT Project Manager SIA CITYNET 22/24 - 500 Katolu str. Riga, LV-1003 Latvia |
|
From: Mgr. M. J. <mai...@vc...> - 2007-07-26 06:08:53
|
Hi. Try to download testing version 1.2.14. Some time before I already announce this problem and Heiko solved it by making a new version where these libraries was presented. You can downloaded it from here: ftp://ftp.devil-linux.org/pub/devel/testing/ (libipt_ipp2p.so and libipt_layer7.so are in directory /usr/lib/iptables) BTW: Has anybody any experiences with layer7 in DL? I made one simple firewall rule which should block rtsp protocol and this rule blocks nothing and content of the packets sends to the syslog ? Does anybody know why ? This is the rule: $IPTABLES -t mangle -A POSTROUTING -m layer7 --l7proto rtsp -j DROP Jiri Motycka Fred Frigerio napsal(a): > OK, I think I know what the problem is but I am not sure how to fix it. > The iptables module ipp2p is there but it looks like the shared library > that needs to go in the /var/lib/iptables is missing. I was able to > modprobe for the ipt_ipp2p.o module ok but when I try iptables -m ipp2p > --help I get an error about a missing library. > > Looking at the ipp2p homepage, it seems that needs to be copied to the > /var/lib/iptables directory after compiling. > > http://www.ipp2p.org/docu_en.html > > > Fred Frigerio > Locust USA > > This electronic message transmission contains information from Locust > USA which may be confidential or privileged. The information is > intended to be for the use of the individual or entity named above. If > you are not the intended recipient, be aware that any disclosure, > copying, distribution or use of the contents of this information is > prohibited. If you have received this electronic transmission in error, > please notify us by telephone (305-889-5410) or by reply via electronic > mail immediately. > > -----Original Message----- > From: dev...@li... > [mailto:dev...@li...] On Behalf Of > Fred Frigerio > Sent: Wednesday, July 25, 2007 4:38 PM > To: dev...@li... > Subject: [Devil-Linux-discuss] P2p traffic filtering > > I am trying to filter p2p traffic at the firewall. Does DL contain any > iptables module that does that? If not has anyone done it? Would you > share your solution? > > I appreciate your help. > > Fred F. |
|
From: Serge L. <fi...@in...> - 2007-07-26 05:09:07
|
Arnaud, Looks like "listen-on-v6" is missed but you showed the config file and it's definitely present... from my system ( if "listen-on-v6" present) root@dl:~ # lsof -i6 -P | grep named named 9449 named 20u IPv6 69287 UDP *:53 named 9449 named 21u IPv6 69288 TCP *:53 (LISTEN) named 9449 named 25u IPv6 69293 UDP *:32783 if "listen-on-v6" is omitted root@dl:~ # lsof -i6 -P | grep named named 9633 named 27u IPv6 69629 UDP *:32785 Arnaud Gomes-do-Vale wrote: >> Could you please show the result of "lsof -i6" ? > > COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME > sshd 933 root 3u IPv6 5653 TCP *:ssh (LISTEN) > ntpd 1219 root 17u IPv6 6606 UDP *:ntp > ntpd 1219 root 18u IPv6 6608 UDP nenesse.ircam.fr:ntp > ntpd 1219 root 19u IPv6 6609 UDP [::1]:ntp > ntpd 1219 root 20u IPv6 6610 UDP [2001:660:3004:2:202:b3ff:fed2:7cb3]:ntp > ntpd 1219 root 21u IPv6 6611 UDP [fe80::202:b3ff:fed2:7cb3]:ntp > named 1495 named 25u IPv6 76012 UDP *:32773 > named 1496 named 25u IPv6 76012 UDP *:32773 > named 1497 named 25u IPv6 76012 UDP *:32773 > named 1498 named 25u IPv6 76012 UDP *:32773 > named 1499 named 25u IPv6 76012 UDP *:32773 > -- Serge Leschinsky |
|
From: Serge L. <fi...@in...> - 2007-07-26 05:05:52
|
Hi, Dmitry Komarov wrote: > What exactly do you mean by replacing syslinux with version .36? > > There is only syslinux-3.51 version on the site. Should I find an older > syslinux-3.36 somewhere else? please get it from http://www.kernel.org/pub/linux/utils/boot/syslinux/Old/syslinux-3.36.tar.bz2 > And how exactly should I replace it? Rename to > syslinux-3.51 and put in src folder and "make unpack" then? delete syslinux-3.51 tarball from src dir and then put 3.36. "make mrproper unpack prepare build" -- Serge Leschinsky |
|
From: Serge L. <fi...@in...> - 2007-07-26 04:26:51
|
Hi, Fred Frigerio wrote: > I am trying to filter p2p traffic at the firewall. Does DL contain any > iptables module that does that? If not has anyone done it? Would you > share your solution? DL contains l7-filter http://l7-filter.sourceforge.net/ -- Serge Leschinsky |
|
From: Fred F. <ffr...@lo...> - 2007-07-25 20:49:31
|
OK, I think I know what the problem is but I am not sure how to fix it. The iptables module ipp2p is there but it looks like the shared library that needs to go in the /var/lib/iptables is missing. I was able to modprobe for the ipt_ipp2p.o module ok but when I try iptables -m ipp2p --help I get an error about a missing library. Looking at the ipp2p homepage, it seems that needs to be copied to the /var/lib/iptables directory after compiling. http://www.ipp2p.org/docu_en.html Fred Frigerio Locust USA =20 This electronic message transmission contains information from Locust USA which may be confidential or privileged. The information is intended to be for the use of the individual or entity named above. If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this information is prohibited. If you have received this electronic transmission in error, please notify us by telephone (305-889-5410) or by reply via electronic mail immediately. -----Original Message----- From: dev...@li... [mailto:dev...@li...] On Behalf Of Fred Frigerio Sent: Wednesday, July 25, 2007 4:38 PM To: dev...@li... Subject: [Devil-Linux-discuss] P2p traffic filtering I am trying to filter p2p traffic at the firewall. Does DL contain any iptables module that does that? If not has anyone done it? Would you share your solution? I appreciate your help. Fred F. ------------------------------------------------------------------------ - This SF.net email is sponsored by: Splunk Inc. Still grepping through log files to find problems? Stop. Now Search log events and configuration files using AJAX and a browser. Download your FREE copy of Splunk now >> http://get.splunk.com/ _______________________________________________ Devil-linux-discuss mailing list Dev...@li... https://lists.sourceforge.net/lists/listinfo/devil-linux-discuss |