Gary Simat
Jun 30 2005, 12:21 PM
Has anyone gotten apf to actually work? I need to know the correct modules to have enabled, currently i have the following:
ipt_REJECT ipt_state ipt_tos ipt_limit ipt_multiport iptable_filter iptable_mangle ipt_TCPMSS ipt_tcpmss ipt_ttl ipt_length ip_tables ipt_LOG ip_conntrack ip_conntrack_irc ip_conntrack_ftp
anyone have any ideas?
Gary Simat
Jul 1 2005, 12:51 AM
QUOTE (Gary Simat)
Has anyone gotten apf to actually work? I need to know the correct modules to have enabled, currently i have the following:
ipt_REJECT ipt_state ipt_tos ipt_limit ipt_multiport iptable_filter iptable_mangle ipt_TCPMSS ipt_tcpmss ipt_ttl ipt_length ip_tables ipt_LOG ip_conntrack ip_conntrack_irc ip_conntrack_ftp
anyone have any ideas?
I actually got this to work with the above modules just needed to restart the virtuozzo service.
Jeff
Jan 20 2006, 06:35 PM
Do you still get some errors when starting APF with the above options enabled though?
Jeewhizz
Jan 24 2006, 06:14 AM
If you get errors, you need to make sure that you change the network devices from eth0 to venet0 and also enable MONOKERN
Jeff
Jan 24 2006, 02:07 PM
Turns out the error was that the required iptables modules were enabled for the vps but not setup for the hardware node. Now all is well. Many thanks.
madsere
Jan 25 2006, 10:08 PM
I tried getting APF to work with Virtuozzo some time ago, by and large it worked but there were some strange side-effects, for example with apf installed but configured to NOT filter egress (outgoing) traffic it would still prevent any outgoing traffic.
Have you tried to ssh out from the hardware node with APF installed?
Jeff
Jan 25 2006, 10:28 PM
I can't answer this as I only have a VPS end user account (posted here when I was having the issue to try and snag the ear of the person who had solved it on their server above.) All I can say is that when the hardware node wasn't configured properly I had the symptom you describe above on my vz account for a year - I got a few iptables errors and no mail would leave the server (connection errors), whois from the command line wouldn't work, cpanel wouldn't connect with the licensing server. Most things worked, but these few did not. When I saw that SWSoft says APF is supported on their site, I asked ev1 to revisit the issue last week -- once they reconfigured the hardware node with the required iptables modules and rebooted the hardware node, everything is now working with apf - zero errors, and I can ssh out from the vps account, no problem with cpanel licensing, command line whois works, etc. So at last I'm happy with APF on my VPS. It's running great! I'd give it another try if I were you.
madsere
Jan 26 2006, 04:58 AM
I did and still have same issue.
No problem with modules, all required are there.
Don't get the point of restarting vz after apf. Apf is restarted regularly, for example whenever you add undesirables to /etc/apf/deny.apf so it would be unfeasable to reboot 20-30 VE's on a VPS.
But maybe I misunderstood something
madsere
Jan 27 2006, 01:08 AM
I pushed swsoft a little and they have now made a FAQ entry for installing APF on Virtuozzo - on the hardware node as well as in VE's:
http://faq.swsoft.com/article_130_875_en.html
newexpos
Jan 27 2006, 05:47 PM
has anyone been able to get APF to work under FreeBsd?
madsere
Jan 27 2006, 09:31 PM
FreeBSD in a VE or a standard FreeBSD server?
newexpos
Jan 28 2006, 07:39 AM
Both. Ive been getting comfortable with FreeBSD since it seem more secure than a LOT of linux distros out of the box. As a result, Ive also been looking at how the tools I use will work out under that OS for my clients
Ive been looking at going straigtht FreeBSD and using FreeBSD jail or trying to get the FreeBSD template working under Virtuozzo but want to makes sure I can get everything i need working before i go nuts trying to figure it all out
madsere
Jan 28 2006, 08:31 AM
Actually AFAIK you can only have Linux VE's under Virtuozzo so I guess it's a moot point. Perhaps ask over in the FreeBSD forum.
Following the Swsoft FAQ entry made it quite easy for me to setup apf in a Linux VE. I've now got it working with BFD as good as on a standalone server.
newexpos
Jan 29 2006, 08:33 AM
Actually, with 2.5 you can have a FreeBSd VPS.
It may not matter since it's starting to look like APF wont work on FreeBSD without Linux emulation and its just not a good idea to run a firewall like that. So that ends that idea.
madsere
Jan 29 2006, 08:48 AM
FreeBSD on Virtuozzo? Where have you got that from?
newexpos
Jan 29 2006, 09:02 AM
from swsoft
http://www.swsoft.com/en/news/id,1503
New features of Virtuozzo include:
* Improved ‘smart migration’ of VEs (drag and drop) between physical servers with only a few seconds of planned system downtime. Large VEs can now be moved as quickly as small VEs.
* OS template support for Linux (Red Hat 7.1, 7.2, 7.3, SuSE, Debian), FreeBSD
* Performance enhancements: 64GB of memory and 16 CPUs per VE, new support for Intel Hyper-Threading Technology
* 2-level disk quotas – Can manage disk quotas for each VE and setup quotas per user inside a VE
* Improved journaling filesystem support (ext3 and ReiserFS) in addition to ext2
* VzAgent – open and well documented XML-based API
madsere
Jan 29 2006, 11:45 AM
That's an old press release from 2002. Try finding any newer information. There were no freebsd templates last I updated Virtuozzo and the only reference I can find at swsoft's forum is that freebsd support currently is frozen.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.