Swapnil Jain wrote:

> as per the shorewall MultiISP documentation ( 
> http://www1.shorewall.net/MultiISP.html 
>   ), it says
> 
> 
> "Use of this feature requires that your kernel and iptables include  
> CONNMARK target and connmark match support (Warning: Standard Debian™  
> and Ubuntu™ kernels are lacking that support!)."
> 
> 
> it means MultiISP wont work properly if i am using Ubuntu server. if  
> yes whats the workaround.

Assuming that Shorewall is started on the system, as root do the following:

r...@ursa:~# shorewall show capabilities | grep -i CONNMARK
   CONNMARK Target: Available
   Extended CONNMARK Target: Available
   Connmark Match: Available
   Extended Connmark Match: Available
r...@ursa:~#

If the first and third links of output other than the above, then your
kernel and/or iptables are missing the required support.

Workarounds are:

- Upgrade your distribution. Jaunty has the required support.
- Don't use 'track'
- Build and install a kernel with the proper support.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Register Now for Creativity and Technology (CaT), June 3rd, NYC. CaT 
is a gathering of tech-side developers & brand creativity professionals. Meet
the minds behind Google Creative Lab, Visual Complexity, Processing, & 
iPhoneDevCamp as they present alongside digital heavyweights like Barbarian 
Group, R/GA, & Big Spaceship. http://p.sf.net/sfu/creativitycat-com 
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to