store | blogs | forums | twitter | facebook | wiki | downloads | support portal
Atomic Secure Linux
It is currently Sun Dec 21, 2014 2:09 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 12 posts ] 
Author Message
 Post subject: iptables unload error
Unread postPosted: Tue Apr 12, 2011 12:11 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 350
I have noticed that when using ASL kernel during shutdown or when you stop the iptables firewall there is an error.
With the centos kernel such an error didn't come up. Is this serious ? Is there anyway if this is harmless to prevent from showing up ?

service iptables stop
iptables: Flushing firewall rules: [ OK ]
iptables: Setting chains to policy ACCEPT: mangle nat filte[ OK ]
iptables: Unloading modules: iptable_mangle iptable_nat [FAILED]

regards

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Tue Apr 12, 2011 1:35 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3680
Location: Chantilly, VA
Quote:
With the centos kernel such an error didn't come up. Is this serious ? Is there anyway if this is harmless to prevent from showing up ?



Its harmless and you can ignore it:

https://www.atomicorp.com/wiki/index.ph ... el_modules.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Tue Apr 12, 2011 5:11 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 350
I am planning to firewall this box using a firewall in front of it.

Do I need to run the iptables firewall in order asl countermeasures to work ?
Such as blocking from modevasive etc ?

Regards

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Tue Apr 12, 2011 5:15 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3680
Location: Chantilly, VA
Quote:
Do I need to run the iptables firewall in order asl countermeasures to work ?


For firewall shunning you need iptables installed, ASL includes this as a dependency. ASL will setup its own chains to handle this, you do not need to do anything.

Quote:
Such as blocking from modevasive etc ?


No, ASL takes care of this for you. You do not need to configure anything for ASLs countermeasures to work. We also do not recommend that you install other software to do the same thing.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Wed Apr 13, 2011 4:40 am 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 350
mikeshinn wrote:
Quote:
Do I need to run the iptables firewall in order asl countermeasures to work ?


For firewall shunning you need iptables installed, ASL includes this as a dependency. ASL will setup its own chains to handle this, you do not need to do anything.

Quote:
Such as blocking from modevasive etc ?


No, ASL takes care of this for you. You do not need to configure anything for ASLs countermeasures to work. We also do not recommend that you install other software to do the same thing.


Hi Mike,

No, what I meant is if when an attacker is found if ASL send a command to the iptables firewall in order to block him. Because if it doesn't use the iptables firewall I cant disable it as a service and win some ram since I have the external firewall ...

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Wed Apr 13, 2011 6:10 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3680
Location: Chantilly, VA
Quote:
No, what I meant is if when an attacker is found if ASL send a command to the iptables firewall in order to block him. Because if it doesn't use the iptables firewall I cant disable it as a service and win some ram since I have the external firewall ...


If I understand your question, yes if active reponse is enabled ASL will use Netfilter (iptables is just the command line tool to access the built in firewall in Linux called Netfilter) to block the source IP for a period of time.

ASL uses Netfilter as an additional means of blocking attackers when:

1) Longer term shuns are necessary
2) When a service itself does not provide an adequate means of blocking an attacker

We do not recommend you disable or remove iptables from your system.

As an aside, Netfilter is extremely lightweight and uses very little memory, so if you are trying to save memory Netfilter would be the absolutely last thing I would worry about. If your system is that low on memory that you believe you need to upload netfilter modules, I highly recommend you get more memory. You are unlikely to notice any difference on a modern system in terms of memory usage if you unload netfilter, and your system would be unlikely to do much if it needed the tiny little bit of memory the kernel uses for Netfilter.

I hope this answered your question.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Wed Apr 13, 2011 6:19 am 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 350
Definately asnwered my questions.
The apart from my external firewall I will leave iptables running with pass all in inbound traffic so that ASL can execute blocks of ip's in case of attacks.

It would have also been great in general if you could provide us with a template for firewalling webhosting machines using iptables in case people don't have an external firewall. It has been discussed in the past I know ... :)

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Wed Apr 13, 2011 8:36 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7964
Location: earth
If only someone had written a book about this!


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Wed Apr 13, 2011 9:45 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 780
Location: Sweden
Yeah, couldn't some please, do that. Use something fierce, dangerous, mayby posionous, on the front page, write about 19 chapters, with examples, some sense of houmor and real world examples. Come one, someone must do it! And then sell it through a big bookstore online so everyone is able to order it (oh wait, I got a two great ideas in one, both write the book and start an online bookstore. Wonder why noone else thought about this...?)


http://www.gotroot.com/Resources+for+Troubleshooting+Linux+Firewalls
or
http://www.amazon.com/Troubleshooting-Linux-Firewalls-Michael-Shinn/dp/0321227239


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Wed Apr 13, 2011 10:23 am 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 350
I jut got the book. When I have time and I read it I'll send you my comments :)

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Wed Apr 13, 2011 12:58 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7964
Location: earth
Im sure my editor is throwing you a parade right now.


Top
 Profile  
 
 Post subject: Re: iptables unload error
Unread postPosted: Wed Apr 13, 2011 6:30 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 350
scott wrote:
Im sure my editor is throwing you a parade right now.

hahahaha

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 12 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Bing [Bot] and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group