Author Topic: Shorewall Error  (Read 2261 times)

ZDevil

  • Hero Member
  • *****
  • Posts: 1998
    • View Profile
    • http://
Shorewall Error
« on: April 28, 2005, 11:36:43 am »
Hi,

I wonder if anyone can teach me how to get Shorewall to work in my C860 (Cacko Lite 122 + Hotfix).  

I installed these packages:
iptables-base_1.2.11-lite-1_arm.ipk and iptables-extras_1.2.11-2_arm.ipk (or either one is enough?)
iptables-modules_2.4.18-rmk 7-pxa3-embedix.ipk
iproute_2.2.4-sharprom-1.ipk
shorewall-1.4.5-1_sharprom_arm.ipk

When I enter the command to try to start the firewall I got this:

Code: [Select]
$ su
# /etc/rc.d/init.d/shorewall start
Processing /etc/shorewall/params ...
Processing /etc/shorewall/shorewall.conf...
Starting Shorewall...
Loading Modules...
Initializing...
Determining Zones...
   Zones: loc vpn
Validating interfaces file...
Validating hosts file...
Validating Policy file...
Determining Hosts in Zones...
   Local Zone: eth0:0.0.0.0/0
   VPN Zone: ipsec0:0.0.0.0/0
Processing /etc/shorewall/init ...
iptables v1.2.11: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
Processing /etc/shorewall/stop ...
iptables v1.2.11: can't initialize iptables table `mangle': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter':
Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter':
Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter':
Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter':
Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
Processing /etc/shorewall/stopped ...
Terminated      

I try chmod 744 /etc/shorewall but it didn't help.  Very likely I just lose the picture.

However as I remember there was no issue at all when running Shorewall in the original sharp rom in the past.  Any idea?  

Thanks a zillion!
zdevil
« Last Edit: April 29, 2005, 09:57:23 am by ZDevil »

Life is too precious for hacking *too much*
Visit my Z screencap gallery[/color]
My EeePC 701 Black = Debian (Lenny) on IceRocks + Transcend SDHC Class6 8GB + 2GB RAM
My Zaurus SL-C3200 = Debian EABI (kernel 2.6.24.3-yonggun) on a swapped internal Sandisk Extreme III CF 16gb
My Debian EABI feed: http://matrixmen.free.fr/zaurus/debian/
My OpenBSD/Zaurus feeds:  Link1, Link2
[/i][/font][/color][/size]

Meanie

  • Hero Member
  • *****
  • Posts: 2803
    • View Profile
    • http://www.users.on.net/~hluc/myZaurus/
Shorewall Error
« Reply #1 on: May 20, 2005, 10:32:08 am »
Quote
Hi,

I wonder if anyone can teach me how to get Shorewall to work in my C860 (Cacko Lite 122 + Hotfix). 

I installed these packages:
iptables-base_1.2.11-lite-1_arm.ipk and iptables-extras_1.2.11-2_arm.ipk (or either one is enough?)
iptables-modules_2.4.18-rmk 7-pxa3-embedix.ipk
iproute_2.2.4-sharprom-1.ipk
shorewall-1.4.5-1_sharprom_arm.ipk

When I enter the command to try to start the firewall I got this:

Code: [Select]
$ su
# /etc/rc.d/init.d/shorewall start
Processing /etc/shorewall/params ...
Processing /etc/shorewall/shorewall.conf...
Starting Shorewall...
Loading Modules...
Initializing...
Determining Zones...
   Zones: loc vpn
Validating interfaces file...
Validating hosts file...
Validating Policy file...
Determining Hosts in Zones...
   Local Zone: eth0:0.0.0.0/0
   VPN Zone: ipsec0:0.0.0.0/0
Processing /etc/shorewall/init ...
iptables v1.2.11: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
Processing /etc/shorewall/stop ...
iptables v1.2.11: can't initialize iptables table `mangle': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter':
Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter':
Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter':
Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.2.11: can't initialize iptables table `filter':
Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
Processing /etc/shorewall/stopped ...
Terminated      

I try chmod 744 /etc/shorewall but it didn't help.  Very likely I just lose the picture.

However as I remember there was no issue at all when running Shorewall in the original sharp rom in the past.  Any idea?   

Thanks a zillion!
zdevil
[div align=\"right\"][a href=\"index.php?act=findpost&pid=77377\"][{POST_SNAPBACK}][/a][/div]


Since I only got a c3000, I am only guessing here, but you will need both iptables-base_1.2.11-lite-1_arm.ipk and iptables-extras_1.2.11-2_arm.ipk because iptables-base only has the most minimal set of modules required to run iptables, but shorewall is fully flexed and requires more modules to do everything so you will need iptables-extras as well. But you do not and should not have installed iptables-modules_2.4.18-rmk 7-pxa3-embedix.ipk, because it contains modules that iptables-base and iptables-extras contain as well and probably overriden some of them and might have broken some dependancies. iproute is only required if you are using dhcp but it wont hurt to have it. and of course you will need shorewall
SL-C3000 - pdaXii13 build5.4.9 (based on pdaXrom beta3) / SL-C3100 - Sharp ROM 1.02 JP (heavily customised)
Netgear MA701 CF, SanDisk ConnectPlus CF, Socket Bluetooth CF, 4GB Kingston CF,  4GB pqi SD, 4GB ChoiceOnly SD, 2GB SanDisk SD USB Plus, 1GB SanDisk USB Plus, 1GB Transcend SD, 2GB SanDisk MicroSD with SD adaptor, Piel Frama Leather Case, GoldX 5-in-1 USB cable, USB hub, USB mouse, USB keyboard, USB ethernet, USB HDD, many other USB accessories...
(Zaurus SL-C3000 owner since March 14. 2005, Zaurus SL-C3100 owner since September 21. 2005)
http://members.iinet.net.au/~wyso/myZaurus - zBook3K

ZDevil

  • Hero Member
  • *****
  • Posts: 1998
    • View Profile
    • http://
Shorewall Error
« Reply #2 on: May 20, 2005, 10:34:40 am »
Wow.  You're great!  Thanks for your advice.  I'll try it out tonight and report the results here.

Life is too precious for hacking *too much*
Visit my Z screencap gallery[/color]
My EeePC 701 Black = Debian (Lenny) on IceRocks + Transcend SDHC Class6 8GB + 2GB RAM
My Zaurus SL-C3200 = Debian EABI (kernel 2.6.24.3-yonggun) on a swapped internal Sandisk Extreme III CF 16gb
My Debian EABI feed: http://matrixmen.free.fr/zaurus/debian/
My OpenBSD/Zaurus feeds:  Link1, Link2
[/i][/font][/color][/size]