Hello Anton,
i had found an older version of the iptables-extra (Jan 2005) from the cacko feed which i had dled in September. looking into it shows
a) has been made for 2.4.18-rmk7-pxa3-embedix kernel
b) contains a tree /lib/modules/..../ipv4/netfilter/ with the ip_conntrack.o and ip_state.o
c) contains a tree /usr/lib/iptables/
comparing this with the current ipk shows the whole tree b) is not there, only /usr/lib/iptables/
perhaps something in packaging went wrong?
Thanks
George
[div align=\"right\"][a href=\"index.php?act=findpost&pid=103358\"][{POST_SNAPBACK}][/a][/div]
Kernel modules are in separate package iptables-modules
[div align=\"right\"][a href=\"index.php?act=findpost&pid=103464\"][{POST_SNAPBACK}][/a][/div]
Hi Anton,
no, there is not any iptables modules ipk which contains the missing conntrack* and state kernel modules.
See my previous msg about the iptables-modules (lite) ipk on the cacko feed. I have analyzed them all.
My msg about the iptables-extra diff between old and current version was a hint that in the past the missing kernel modules could be found in the extra ipk but nowdays aren't there anymore:
the contents:
iptables-extras_1.2.11-2_arm.1.ipk January 2005 version:
/lib/modules/2.4.18-rmk7-pxa3-embedix/kernel/net/ipv4/netfilter
total 784
-rw-r--r-- 1 root admin 28056 25 Nov 2004 ip_conntrack.o !!!
-rw-r--r-- 1 root admin 6036 25 Nov 2004 ip_conntrack_ftp.o !!!
-rw-r--r-- 1 root admin 4172 25 Nov 2004 ip_conntrack_irc.o !!!
-rw-r--r-- 1 root admin 5000 25 Nov 2004 ip_nat_ftp.o !!!
-rw-r--r-- 1 root admin 4348 25 Nov 2004 ip_nat_irc.o !!!
-rw-r--r-- 1 root admin 14220 25 Nov 2004 ip_nat_snmp_basic.o !!!
-rw-r--r-- 1 root admin 10660 25 Nov 2004 ip_queue.o !!!
-rw-r--r-- 1 root admin 20432 25 Nov 2004 ip_tables.o
-rw-r--r-- 1 root admin 60151 2 Nov 2004 ipchains.o ***
-rw-r--r-- 1 root admin 57389 2 Nov 2004 ipfwadm.o ***
-rw-r--r-- 1 root admin 6388 25 Nov 2004 ipt_LOG.o
-rw-r--r-- 1 root admin 1792 25 Nov 2004 ipt_MARK.o
-rw-r--r-- 1 root admin 3112 25 Nov 2004 ipt_MASQUERADE.o !!!
-rw-r--r-- 1 root admin 2760 25 Nov 2004 ipt_MIRROR.o
-rw-r--r-- 1 root admin 1872 25 Nov 2004 ipt_REDIRECT.o
-rw-r--r-- 1 root admin 5648 25 Nov 2004 ipt_REJECT.o
-rw-r--r-- 1 root admin 4228 25 Nov 2004 ipt_TCPMSS.o
-rw-r--r-- 1 root admin 2320 25 Nov 2004 ipt_TOS.o
-rw-r--r-- 1 root admin 5124 25 Nov 2004 ipt_ULOG.o
-rw-r--r-- 1 root admin 1664 25 Nov 2004 ipt_ah.o
-rw-r--r-- 1 root admin 1664 25 Nov 2004 ipt_esp.o
-rw-r--r-- 1 root admin 1632 25 Nov 2004 ipt_length.o
-rw-r--r-- 1 root admin 2264 25 Nov 2004 ipt_limit.o
-rw-r--r-- 1 root admin 1772 25 Nov 2004 ipt_mac.o
-rw-r--r-- 1 root admin 1416 25 Nov 2004 ipt_mark.1.o
-rw-r--r-- 1 root admin 1784 25 Nov 2004 ipt_multiport.o
-rw-r--r-- 1 root admin 2656 25 Nov 2004 ipt_owner.o
-rw-r--r-- 1 root admin 1704 25 Nov 2004 ipt_state.o !!!
-rw-r--r-- 1 root admin 1948 25 Nov 2004 ipt_tcpmss.1.o
-rw-r--r-- 1 root admin 1412 25 Nov 2004 ipt_tos.1.o
-rw-r--r-- 1 root admin 1868 25 Nov 2004 ipt_ttl.o
-rw-r--r-- 1 root admin 10004 25 Nov 2004 ipt_unclean.o
-rw-r--r-- 1 root admin 3200 25 Nov 2004 iptable_filter.o
-rw-r--r-- 1 root admin 3676 25 Nov 2004 iptable_mangle.o
-rw-r--r-- 1 root admin 26129 25 Nov 2004 iptable_nat.o !!!
in 1.23 cacko full these files are included in "ROM":
/lib/modules.rom/2.4.20/kernel/net/ipv4/netfilter/
total 344
-rwxrwxrwx 1 root admin 17184 26 Sep 17:16 arp_tables.o
-rwxrwxrwx 1 root admin 21956 26 Sep 17:16 ip_tables.o
-rwxrwxrwx 1 root admin 2656 26 Sep 17:16 ipt_DSCP_target.o
-rwxrwxrwx 1 root admin 3300 26 Sep 17:16 ipt_ECN_target.o
-rwxrwxrwx 1 root admin 6872 26 Sep 17:16 ipt_LOG.o
-rwxrwxrwx 1 root admin 2004 26 Sep 17:16 ipt_MARK_target.o
-rwxrwxrwx 1 root admin 2960 26 Sep 17:16 ipt_MIRROR.o
-rwxrwxrwx 1 root admin 6076 26 Sep 17:16 ipt_REJECT.o
-rwxrwxrwx 1 root admin 4636 26 Sep 17:16 ipt_TCPMSS_target.o
-rwxrwxrwx 1 root admin 2512 26 Sep 17:16 ipt_TOS_target.o
-rwxrwxrwx 1 root admin 5780 26 Sep 17:16 ipt_ULOG.o
-rwxrwxrwx 1 root admin 1740 26 Sep 17:16 ipt_ah.o
-rwxrwxrwx 1 root admin 1640 26 Sep 17:16 ipt_dscp.o
-rwxrwxrwx 1 root admin 2252 26 Sep 17:16 ipt_ecn.o
-rwxrwxrwx 1 root admin 1744 26 Sep 17:16 ipt_esp.o
-rwxrwxrwx 1 root admin 1692 26 Sep 17:16 ipt_length.o
-rwxrwxrwx 1 root admin 2432 26 Sep 17:16 ipt_limit.o
-rwxrwxrwx 1 root admin 1864 26 Sep 17:16 ipt_mac.o
-rwxrwxrwx 1 root admin 1472 26 Sep 17:16 ipt_mark.o
-rwxrwxrwx 1 root admin 1852 26 Sep 17:16 ipt_multiport.o
-rwxrwxrwx 1 root admin 3396 26 Sep 17:16 ipt_owner.o
-rwxrwxrwx 1 root admin 1468 26 Sep 17:16 ipt_pkttype.o
-rwxrwxrwx 1 root admin 2156 26 Sep 17:16 ipt_tcpmss.o
-rwxrwxrwx 1 root admin 1468 26 Sep 17:16 ipt_tos.o
-rwxrwxrwx 1 root admin 1988 26 Sep 17:16 ipt_ttl.o
-rwxrwxrwx 1 root admin 10396 26 Sep 17:16 ipt_unclean.o
-rwxrwxrwx 1 root admin 3404 26 Sep 17:16 iptable_filter.o
-rwxrwxrwx 1 root admin 3932 26 Sep 17:16 iptable_mangle.o
as posted before,
/lib/modules/2.4.20/kernel/net/ipv4/netfilter/
contains 1:1 links to every file in /lib/modules.rom/...
The cackofeed
iptables-modules-2.4.20_1.23-lite-1_arm.1.ipk
contains exactly the same modules as the modules.rom above, no wonder, it is probably the missing modules of the lite kernel to have the same funtionality an the full kernel.
/lib/modules/2.4.20/kernel/net/ipv4/netfilter/
total 344
-rw-r--r-- 1 root admin 17184 26 Sep 17:16 arp_tables.o
-rw-r--r-- 1 root admin 21956 26 Sep 17:16 ip_tables.o
-rw-r--r-- 1 root admin 2656 26 Sep 17:16 ipt_DSCP_target.o
-rw-r--r-- 1 root admin 3300 26 Sep 17:16 ipt_ECN_target.o
-rw-r--r-- 1 root admin 6872 26 Sep 17:16 ipt_LOG.o
-rw-r--r-- 1 root admin 2004 26 Sep 17:16 ipt_MARK_target.o
-rw-r--r-- 1 root admin 2960 26 Sep 17:16 ipt_MIRROR.o
-rw-r--r-- 1 root admin 6076 26 Sep 17:16 ipt_REJECT.o
-rw-r--r-- 1 root admin 4636 26 Sep 17:16 ipt_TCPMSS_target.o
-rw-r--r-- 1 root admin 2512 26 Sep 17:16 ipt_TOS_target.o
-rw-r--r-- 1 root admin 5780 26 Sep 17:16 ipt_ULOG.o
-rw-r--r-- 1 root admin 1740 26 Sep 17:16 ipt_ah.o
-rw-r--r-- 1 root admin 1640 26 Sep 17:16 ipt_dscp.o
-rw-r--r-- 1 root admin 2252 26 Sep 17:16 ipt_ecn.o
-rw-r--r-- 1 root admin 1744 26 Sep 17:16 ipt_esp.o
-rw-r--r-- 1 root admin 1692 26 Sep 17:16 ipt_length.o
-rw-r--r-- 1 root admin 2432 26 Sep 17:16 ipt_limit.o
-rw-r--r-- 1 root admin 1864 26 Sep 17:16 ipt_mac.o
-rw-r--r-- 1 root admin 1472 26 Sep 17:16 ipt_mark.o
-rw-r--r-- 1 root admin 1852 26 Sep 17:16 ipt_multiport.o
-rw-r--r-- 1 root admin 3396 26 Sep 17:16 ipt_owner.o
-rw-r--r-- 1 root admin 1468 26 Sep 17:16 ipt_pkttype.o
-rw-r--r-- 1 root admin 2156 26 Sep 17:16 ipt_tcpmss.o
-rw-r--r-- 1 root admin 1468 26 Sep 17:16 ipt_tos.o
-rw-r--r-- 1 root admin 1988 26 Sep 17:16 ipt_ttl.o
-rw-r--r-- 1 root admin 10396 26 Sep 17:16 ipt_unclean.o
-rw-r--r-- 1 root admin 3404 26 Sep 17:16 iptable_filter.o
-rw-r--r-- 1 root admin 3932 26 Sep 17:16 iptable_mangle.o
i can't find any byte diff or any file more than i have on the 1.23 full.
Looking into the
iptables-modules-2.4.18_1.23-lite-1_arm.1.ipk
shows:
/lib/modules/2.4.18-rmk7-pxa3-embedix/kernel/net/ipv4/netfilter
total 512
-rw-r--r-- 1 root admin 28056 26 Sep 17:45 ip_conntrack.o
-rw-r--r-- 1 root admin 6036 26 Sep 17:45 ip_conntrack_ftp.o
-rw-r--r-- 1 root admin 4172 26 Sep 17:45 ip_conntrack_irc.o
-rw-r--r-- 1 root admin 5000 26 Sep 17:45 ip_nat_ftp.o
-rw-r--r-- 1 root admin 4348 26 Sep 17:45 ip_nat_irc.o
-rw-r--r-- 1 root admin 14220 26 Sep 17:45 ip_nat_snmp_basic.o
-rw-r--r-- 1 root admin 10660 26 Sep 17:45 ip_queue.o
-rw-r--r-- 1 root admin 20432 26 Sep 17:45 ip_tables.o
-rw-r--r-- 1 root admin 6388 26 Sep 17:45 ipt_LOG.o
-rw-r--r-- 1 root admin 1792 26 Sep 17:45 ipt_MARK.o
-rw-r--r-- 1 root admin 3112 26 Sep 17:45 ipt_MASQUERADE.o
-rw-r--r-- 1 root admin 2760 26 Sep 17:45 ipt_MIRROR.o
-rw-r--r-- 1 root admin 1872 26 Sep 17:45 ipt_REDIRECT.o
-rw-r--r-- 1 root admin 5648 26 Sep 17:45 ipt_REJECT.o
-rw-r--r-- 1 root admin 4228 26 Sep 17:45 ipt_TCPMSS.o
-rw-r--r-- 1 root admin 2320 26 Sep 17:45 ipt_TOS.o
-rw-r--r-- 1 root admin 5124 26 Sep 17:45 ipt_ULOG.o
-rw-r--r-- 1 root admin 1664 26 Sep 17:45 ipt_ah.o
-rw-r--r-- 1 root admin 1664 26 Sep 17:45 ipt_esp.o
-rw-r--r-- 1 root admin 1632 26 Sep 17:45 ipt_length.o
-rw-r--r-- 1 root admin 2264 26 Sep 17:45 ipt_limit.o
-rw-r--r-- 1 root admin 1772 26 Sep 17:45 ipt_mac.o
-rw-r--r-- 1 root admin 1416 26 Sep 17:45 ipt_mark.1.o
-rw-r--r-- 1 root admin 1784 26 Sep 17:45 ipt_multiport.o
-rw-r--r-- 1 root admin 2656 26 Sep 17:45 ipt_owner.o
-rw-r--r-- 1 root admin 1704 26 Sep 17:45 ipt_state.o
-rw-r--r-- 1 root admin 1948 26 Sep 17:45 ipt_tcpmss.1.o
-rw-r--r-- 1 root admin 1412 26 Sep 17:45 ipt_tos.1.o
-rw-r--r-- 1 root admin 1868 26 Sep 17:45 ipt_ttl.o
-rw-r--r-- 1 root admin 10004 26 Sep 17:45 ipt_unclean.o
-rw-r--r-- 1 root admin 3200 26 Sep 17:45 iptable_filter.o
-rw-r--r-- 1 root admin 3676 26 Sep 17:45 iptable_mangle.o
-rw-r--r-- 1 root admin 26129 26 Sep 17:45 iptable_nat.o
here again for the 2.4.18 kernel we find the conntrack* state and nat kernel modules which are not available for the 2.4.20 kernel.
I have marked in the first listing by !!! those modules which are missing now for 2.4.20, as far as i could spot them.
I don't know where to further look for them.
Marked with *** are modules which were there only for 2.2 kernel firewall compatibility, i think they are really not needed anymore
Sorry for thze long post. I think we need all details now otherwise we enter a loop here.
TIA
George