Portál AbcLinuxu, 7. května 2025 05:38

Dotaz: Firehol v Gentoo

14.7.2007 18:15 standik | skóre: 17 | blog: vsechno mozne
Firehol v Gentoo
Přečteno: 789×
Odpovědět | Admin
Ahoj, pokouším se rozjet firehol v gentoo, ale vůbec se mi nedaří.
Když se pokusím aplikovat v něm vytvořený pravidla (/etc/init.d/firehol start) tak dostanu spoustu chybových hlášení:
 * Starting FireHOL ...


WARNING 
The file '/etc/firehol/RESERVED_IPS' contains zero IP definitions.
Using internal default values for variable 'RESERVED_IPS' and all inherited ones.

Run the supplied get-iana.sh script to generate this file.

gzcat: /proc/config.gz already has .gz suffix -- unchanged
/tmp/.firehol-tmp-6485-23854-24606/firehol-tmp.sh: line 8: interfaces: command not found

--------------------------------------------------------------------------------
ERROR #: 1
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: policy drop 
SOURCE : line 9 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 2
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: protection strong 10/sec 10 
SOURCE : line 10 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 3
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: server ident reject with tcp-reset 
SOURCE : line 11 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 4
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: server ftp accept 
SOURCE : line 12 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 5
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: server samba accept 
SOURCE : line 13 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 6
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: server dhcp accept 
SOURCE : line 14 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 7
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: server icmp accept 
SOURCE : line 15 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 8
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: server smtp accept 
SOURCE : line 16 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 9
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: server ssh reject 
SOURCE : line 17 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 10
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: client all accept 
SOURCE : line 19 of /etc/firehol/firehol.conf

/tmp/.firehol-tmp-6485-23854-24606/firehol-tmp.sh: line 21: interfaces: command not found

--------------------------------------------------------------------------------
ERROR #: 11
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: policy drop 
SOURCE : line 22 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 12
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: protection strong 10/sec 10 
SOURCE : line 23 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 13
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: server ident reject with tcp-reset 
SOURCE : line 24 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 14
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: server dhcp accept 
SOURCE : line 25 of /etc/firehol/firehol.conf


--------------------------------------------------------------------------------
ERROR #: 15
WHAT   : Initializing
WHY    : The command used requires that a primary command is set.
COMMAND: client all accept 
SOURCE : line 26 of /etc/firehol/firehol.conf
Můj konfigurační soubor:
version 5

FIREHOL_LOG_LEVEL="7"

server_torrent_ports="tcp/6881 udp/6881"
client_torrent_ports="default"

interfaces eth0 lanka
        policy          drop
        protection strong 10/sec 10
        server ident    reject with tcp-reset
        server ftp      accept
        server samba    accept
        server dhcp     accept
        server icmp     accept
        server smtp     accept
        server ssh      reject
#       server multicast accept
        client all      accept

interfaces eth1 wifina
        policy drop
        protection strong 10/sec 10
        server ident    reject with tcp-reset
        server dhcp     accept
        client all      accept
Předem díky za odpovědi.
Nástroje: Začni sledovat (0) ?Zašle upozornění na váš email při vložení nového komentáře.

Odpovědi

14.7.2007 23:24 standik | skóre: 17 | blog: vsechno mozne
Rozbalit Rozbalit vše Re: Firehol v Gentoo
Odpovědět | | Sbalit | Link | Blokovat | Admin
Tak jsem chybu nakonec našel sám. Můžu si za ní vlastně taky sám, když si pořádně nepřečtu co tam má být. V konfiguračním souboru, místo interface jsem měl interfaces :-(.
15.7.2007 03:23 Jiří J. | skóre: 34 | blog: Poutník | Brno
Rozbalit Rozbalit vše Re: Firehol v Gentoo
Spíš opačně, ne? :-)
/tmp/.firehol-tmp-6485-23854-24606/firehol-tmp.sh: line 8: interfaces: command not found
15.7.2007 03:24 Jiří J. | skóre: 34 | blog: Poutník | Brno
Rozbalit Rozbalit vše Re: Firehol v Gentoo
Ajo, to já zas tak pozdě v noci špatně čtu :-D

Založit nové vláknoNahoru

Tiskni Sdílej: Linkuj Jaggni to Vybrali.sme.sk Google Del.icio.us Facebook

ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.