ennservogt
08.10.03, 20:18
Servus,
ich suche nun schon Tage nach dem Fehler in folgender iptables Regel:
---ANFANG---
[21:07:16]netserv: /scripts/iptables.rules# iptables -t mangle -A PREROUTING -i eth1 -p tcp,udp --dport 130:140 -j DROP
iptables v1.2.6a: unknown protocol `tcp,udp' specified
Try `iptables -h' or 'iptables --help' for more information.
---ENDE---
Ausschnitt aus der offiziellen iptables Dokumentation:
Match:
-p, --protocol
Example:
iptables -A INPUT -p tcp
Explanation:
This match is used to check for certain protocols. Examples of protocols are TCP, UDP and ICMP. The protocol must either be one of the internally specified TCP, UDP or ICMP. It may also take a value specified in the /etc/protocols file, and if it can not find the protocol there it will reply with an error. The protocl may also be a integer value. For example, the ICMP protocol is integer value 1, TCP is 6 and UDP is 17. Finally, it may also take the value ALL. ALL means that it matches only TCP, UDP and ICMP. The command may also take a comma delimited list of protocols, such as udp,tcp which would match all UDP and TCP packets. If this match is given the integer value of zero (0), it means ALL protocols, which in turn is the default behavior, if the --protocol match is not used. This match can also be inversed with the ! sign, so --protocol ! tcp would mean to match UDP and ICMP.
die anfangszeilen meiner protocols datei:
---ANFANG---
ip 0 IP # internet protocol, pseudo protocol number
icmp 1 ICMP # internet control message protocol
igmp 2 IGMP # Internet Group Management
ggp 3 GGP # gateway-gateway protocol
ipencap 4 IP-ENCAP # IP encapsulated in IP (officially ``IP'')
st 5 ST # ST datagram mode
tcp 6 TCP # transmission control protocol
egp 8 EGP # exterior gateway protocol
pup 12 PUP # PARC universal packet protocol
udp 17 UDP # user datagram protocol
hmp 20 HMP # host monitoring protocol
----ENDE---
gekürtzte Ausgabe von lsmod:
---ANFANG---
iptable_filter
iptable_mangle
ipt_MASQUERADE
iptable_nat
ip_conntrack
ip_tables
---ENDE---
Debian Linux mit Kernel 2.4.18-586tsc
iptables iptables v1.2.6a
Ich weis wirklich nicht mehr weiter...
ich suche nun schon Tage nach dem Fehler in folgender iptables Regel:
---ANFANG---
[21:07:16]netserv: /scripts/iptables.rules# iptables -t mangle -A PREROUTING -i eth1 -p tcp,udp --dport 130:140 -j DROP
iptables v1.2.6a: unknown protocol `tcp,udp' specified
Try `iptables -h' or 'iptables --help' for more information.
---ENDE---
Ausschnitt aus der offiziellen iptables Dokumentation:
Match:
-p, --protocol
Example:
iptables -A INPUT -p tcp
Explanation:
This match is used to check for certain protocols. Examples of protocols are TCP, UDP and ICMP. The protocol must either be one of the internally specified TCP, UDP or ICMP. It may also take a value specified in the /etc/protocols file, and if it can not find the protocol there it will reply with an error. The protocl may also be a integer value. For example, the ICMP protocol is integer value 1, TCP is 6 and UDP is 17. Finally, it may also take the value ALL. ALL means that it matches only TCP, UDP and ICMP. The command may also take a comma delimited list of protocols, such as udp,tcp which would match all UDP and TCP packets. If this match is given the integer value of zero (0), it means ALL protocols, which in turn is the default behavior, if the --protocol match is not used. This match can also be inversed with the ! sign, so --protocol ! tcp would mean to match UDP and ICMP.
die anfangszeilen meiner protocols datei:
---ANFANG---
ip 0 IP # internet protocol, pseudo protocol number
icmp 1 ICMP # internet control message protocol
igmp 2 IGMP # Internet Group Management
ggp 3 GGP # gateway-gateway protocol
ipencap 4 IP-ENCAP # IP encapsulated in IP (officially ``IP'')
st 5 ST # ST datagram mode
tcp 6 TCP # transmission control protocol
egp 8 EGP # exterior gateway protocol
pup 12 PUP # PARC universal packet protocol
udp 17 UDP # user datagram protocol
hmp 20 HMP # host monitoring protocol
----ENDE---
gekürtzte Ausgabe von lsmod:
---ANFANG---
iptable_filter
iptable_mangle
ipt_MASQUERADE
iptable_nat
ip_conntrack
ip_tables
---ENDE---
Debian Linux mit Kernel 2.4.18-586tsc
iptables iptables v1.2.6a
Ich weis wirklich nicht mehr weiter...