PDA

View Full Version : APF Firewall


gig
02-09-2005, 21:59
I have a VDS I just got and I want to setup APF on it, I've had to solve serveral dep. in order to get this far and now I am stuck with this:

Development mode enabled!; firewall will flush every 5 minutes.
Opening /proc/modules: No such file or directory
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
Bad argument `22'
Try `iptables -h' or 'iptables --help' for more information.
Bad argument `venet0'
Try `iptables -h' or 'iptables --help' for more information.
Bad argument `venet0'
Try `iptables -h' or 'iptables --help' for more information.
Bad argument `venet0'
Try `iptables -h' or 'iptables --help' for more information.
Bad argument `venet0'
Try `iptables -h' or 'iptables --help' for more information.
Bad argument `venet0'
Try `iptables -h' or 'iptables --help' for more information.
Bad argument `venet0'
Try `iptables -h' or 'iptables --help' for more information.
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name

Here is what I see in the log file:

APF Status Log:
Feb 09 16:50:01 apf(24837): firewall offline
Feb 09 16:50:01 apf(24837): flushing & zeroing chain policies
Feb 09 16:48:32 apf(22583): firewall initalized
Feb 09 16:48:32 apf(22695): default (ingress) input drop
Feb 09 16:48:32 apf(22695): default (egress) output accept
Feb 09 16:48:31 apf(22695): resolv dns discovery for 66.90.68.26
Feb 09 16:48:31 apf(22695): resolv dns discovery for 66.90.68.25
Feb 09 16:48:31 apf(22695): opening inbound icmp type 8 on 127.0.0.1
Feb 09 16:48:31 apf(22695): opening inbound icmp type 30 on 127.0.0.1
Feb 09 16:48:31 apf(22695): opening inbound icmp type 0 on 127.0.0.1
Feb 09 16:48:31 apf(22695): opening inbound icmp type 11 on 127.0.0.1
Feb 09 16:48:31 apf(22695): opening inbound icmp type 5 on 127.0.0.1
Feb 09 16:48:31 apf(22695): opening inbound icmp type 3 on 127.0.0.1
Feb 09 16:48:31 apf(22695): opening inbound tcp port 22 on 127.0.0.1
Feb 09 16:48:31 apf(22695): loading main.rules
Feb 09 16:48:31 apf(22695): opening inbound icmp type 8 on
Feb 09 16:48:31 apf(22695): opening inbound icmp type 30 on
Feb 09 16:48:31 apf(22695): opening inbound icmp type 0 on
Feb 09 16:48:31 apf(22695): opening inbound icmp type 11 on
Feb 09 16:48:31 apf(22695): opening inbound icmp type 5 on
Feb 09 16:48:31 apf(22695): opening inbound icmp type 3 on
Feb 09 16:48:31 apf(22695): opening inbound tcp port 22 on
Feb 09 16:48:31 apf(22695): loading x.x.x.x.rules
Feb 09 16:48:31 apf(22695): virtual net subsystem enabled; loading vnet rules.
Feb 09 16:48:31 apf(22695): loading log.rules
Feb 09 16:48:30 apf(22695): loading ds_hosts.rules
Feb 09 16:48:30 apf(22695): loading bt.rules
Feb 09 16:48:30 apf(22695): loading preroute.rules
Feb 09 16:48:30 apf(22695): setting sysctl_syn enabled.
Feb 09 16:48:30 apf(22695): setting sysctl_tcp enabled.
Feb 09 16:48:30 apf(22695): setting sysctl_syncookies enabled.
Feb 09 16:48:30 apf(22695): loading sysctl.rules
Feb 09 16:48:30 apf(22695): determined (OUT_IF) venet0 has address 127.0.0.1
Feb 09 16:48:30 apf(22695): determined (IN_IF) venet0 has address 127.0.0.1
Feb 09 16:48:30 apf(22695): development mode enabled!; firewall will flush every 5 minutes.
Feb 09 16:48:30 apf(22583): parsing block.txt into /etc/apf/ds_hosts.rules
Feb 09 16:48:24 apf(22583): downloading http://feeds.dshield.org/block.txt
Feb 09 16:48:24 apf(22583): activating firewall

It's Fedora Core 1

Thanks for any help anyone can give me!

arty
02-09-2005, 22:04
as far as i know apf cannot run on a vds for some reason
at least i couldn't get it to work

BaCkBuRn
02-09-2005, 22:07
try shorewall

do a search on freshmeat.net for it. Im too lazy :)

-bb

stozka
04-30-2006, 22:14
Well it seem that AFP works on VDC also,
you have to use monolith mode and venet0 and that's it

i spend a few hours on this stuff and now i'm quite happy with it.