RE: Problem adding connlimit rule

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tue, 10 May 2005, Ruben Cardenal wrote:

Hi,

netfilter-bounces@xxxxxxxxxxxxxxxxxxx wrote:
El mar, 10-05-2005 a las 13:26 +0200, Ruben Cardenal escribió:
Hi,

  I'm trying to add a quite simple rule but I get an error:

# iptables -I INPUT -p tcp --syn --dport 25 -m connlimit
--connlimit-above 10 -j REJECT iptables: No chain/target/match by
that name

Maybe you don't have the support for the connlimit match compiled for iptables. Check if you have the file: /lib/iptables/libipt_connlimit.so

For this system libs are located under /usr/local/lib/iptables and libipt_connlimit.so is there.


OK, you have the libs, but, is the module loded? the modules live in a seperate place. Look under /lib/modules/<kernel version>/kernel/net/ipv4/netfilter/

and then do an lsmod to see if it;s loaded correctly.

ipt_limit.o

Thanks,


Ron DuFresne
- -- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
admin & senior security consultant: sysinfo.com
http://sysinfo.com
Key fingerprint = 9401 4B13 B918 164C 647A E838 B2DF AFCC 94B0 6629


...We waste time looking for the perfect lover
instead of creating the perfect love.

                -Tom Robbins <Still Life With Woodpecker>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFCgSAFst+vzJSwZikRAqqrAKDIayJF7m93ohK9zEnmZH4c6hAOcQCfTDUT
XaRaqhNvKvc/al3k8rDg4aI=
=Qru6
-----END PGP SIGNATURE-----

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux