Re: Some oddities while setting up outbound filtering on a web server

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Friday, March 07, 2014 09:05:10 PM Anthony Taylor wrote:
> On Thu, Mar 6, 2014 at 11:01 PM, Neal Murphy <neal.p.murphy@xxxxxxxxxxxx> 
wrote:
> > On Thursday, March 06, 2014 11:46:17 PM Mart Frauenlob wrote:
> >> >> Then try to enable it???
> >> > 
> >> > echo 1 > /proc/sys/net/netfilter/nf_conntrack_tcp_be_liberal
> >> > -su: /proc/sys/net/netfilter/nf_conntrack_tcp_be_liberal: Permission
> >> > denied
> >> 
> >> strange, don't know what is the problem there...
> > 
> > Module nf_conntrack_ipv4 has not been INSed.
> 
> I'm not sure what that means.

'insmod nf_conntrack_ipv4' and the error should go away. That particular file 
(among others) doesn't exist if that particular module has not been loaded. 
And, if I presume correctly, userspace (generally) cannot create files in 
/proc. Thus the permission error.
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux