Bug 10392 - Interactive firewall not working at all
Summary: Interactive firewall not working at all
Status: RESOLVED DUPLICATE of bug 8225
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 3
Hardware: x86_64 Linux
Priority: Normal major
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-06-02 11:39 CEST by Pavel Kreuzt
Modified: 2013-06-06 22:01 CEST (History)
2 users (show)

See Also:
Source RPM:
CVE:
Status comment:


Attachments

Description Pavel Kreuzt 2013-06-02 11:39:23 CEST
With a network connection configured and enabled at boot, I try to enable a firewall through drakfirewall. It installs mandi, mandi-ifw, shorewall and shorewall6, then I choose NICs to be protected: eth0, wlan0 (the active one) and left unmarked tun0 (my VPN enabled in the wlan setup). After reboot, mandi seems enabled, but net_applet doesn't show its options, nor warnings on pings or scans.

# systemctl status mandi.service 
mandi.service - LSB: Network monitoring daemon
	  Loaded: loaded (/etc/rc.d/init.d/mandi)
	  Active: active (running) since Sun, 2013-06-02 11:11:36 CEST; 3s ago
	 Process: 6450 ExecStart=/etc/rc.d/init.d/mandi start (code=exited, status=0/SUCCESS)
	  CGroup: name=systemd:/system/mandi.service
		  รข 6459 /usr/sbin/mandi -d

Jun 02 11:11:36 Sirte systemd[1]: Starting LSB: Network monitoring daemon...
Jun 02 11:11:36 Sirte mandi[6450]: Starting mandi daemon: nl_create_socke...ed
Jun 02 11:11:36 Sirte mandi[6450]: unable to init netlink
Jun 02 11:11:36 Sirte mandi[6450]: unable to init "Interactive Firewall" plugin
Jun 02 11:11:36 Sirte mandi[6450]: [  OK  ]
Jun 02 11:11:36 Sirte systemd[1]: Started LSB: Network monitoring daemon.


Disabling the VPN setup and with wlan setup alone it has the same problems. It seems manually modprobing ipt_IFWLOG into the kernel solves the problem, but I'm not sure.

Versions: mandi-1.2-2.mga3, mandi-ifw-1.2-2.mga3
Comment 1 Pavel Kreuzt 2013-06-02 11:47:17 CEST
After "modprobe ipt_IFWLOG" I see drakids working and mandi doesn't complain about anything. net_applet shows interactive firewall options but it still doesn't show warnings on pings or scans.
Thierry Vignaud 2013-06-02 21:48:00 CEST

CC: (none) => mageia

Comment 2 Derek Jennings 2013-06-06 22:01:57 CEST
This is a duplicate of Bug 8225 which I am re-opening.

Log contains same "WARNING: The state match is obsolete. Use conntrack instead." messages as 8225

*** This bug has been marked as a duplicate of bug 8225 ***

Status: NEW => RESOLVED
CC: (none) => derekjenn
Resolution: (none) => DUPLICATE


Note You need to log in before you can comment on or make changes to this bug.