<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="http://dev1galaxy.org/extern.php?action=feed&amp;tid=5493&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / git netfilter compile problem]]></title>
		<link>http://dev1galaxy.org/viewtopic.php?id=5493</link>
		<description><![CDATA[The most recent posts in git netfilter compile problem.]]></description>
		<lastBuildDate>Thu, 26 Jan 2023 01:57:11 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40584#p40584</link>
			<description><![CDATA[<p>@dcolburn . . . I think your expectations may be a bit unrealistic. You have been asking questions now for some time and had responses from knowledgeable users yet you haven&#039;t been able to get things working. Seems that somehow things are getting &quot;lost in translation&quot;. Perhaps you could find a local Linux user to help you with hands on your machine. There used to be local Linux User Groups (LUGs) for that kind of interaction though I don&#039;t know quite how you would go about connecting with someone in 2023. Just a thought . . .</p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Thu, 26 Jan 2023 01:57:11 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40584#p40584</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40576#p40576</link>
			<description><![CDATA[<p>Thank you.</p><p>I find that those who attack the character and intentions of others - despite clear evidence to the contrary (the site was working and was successfully accessed by several on this Forum) are likely projecting something of their own troubles.</p><p>It&#039;s really easy to just ignore my requests for help and to leave it to those who are willing to answer some very simple questions - from knowledge, rather than conjecture.</p><p>I&#039;ve asked, several times, about my concerns that my nftables install may be corrupted ...</p><p>So far, no one has offered a solution (I&#039;ve looked, a lot, for myself) at how-to restore what I believe to be missing pieces of it (the lib modules, to be precise) - nor, has anyone offered an alternative explanation as to why nftables is not working.</p><p>I&#039;ve been using Linux for a long time and have observed the toxic-assumptions problem before - it&#039;s always unhealthy to the community.</p><p>Answers to my questions should involve simple step-by-step advice ... false assumptions are, well, we all know about assumptions ... sigh.</p>]]></description>
			<author><![CDATA[dummy@example.com (dcolburn)]]></author>
			<pubDate>Wed, 25 Jan 2023 17:48:55 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40576#p40576</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40575#p40575</link>
			<description><![CDATA[<div class="quotebox"><cite>Head_on_a_Stick wrote:</cite><blockquote><div><p>@all: probably best to stop pandering to this person, I suspect they are trolling us.</p></div></blockquote></div><p>@ HoaS the irrepressible cynic . . . I believe that the explanation is much simpler . . .</p><p>I am an old person. A very old person. Because I am an old person I took note that early on dcolburn mentioned he was also of a certain age. IIRC, I beat him by some years. When you are such an age . . . if the earth is still around by then . . . you will come to understand the challenges . . .</p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Wed, 25 Jan 2023 17:00:59 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40575#p40575</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40574#p40574</link>
			<description><![CDATA[<div class="quotebox"><cite>boughtonp wrote:</cite><blockquote><div><div class="quotebox"><cite>Marjorie wrote:</cite><blockquote><div><p>As he has a fixed IP from his ISP (though I recall he does describe it as immutable not fixed) that isn&#039;t necessarily an issue</p></div></blockquote></div><p>I wasn&#039;t referring to dynamic IPs, but rather the security implications.</p><p>Given the level of experience/understanding displayed and the cherry-picking of responses, I don&#039;t want to contribute towards an eventual &quot;My home network is compromised, how do I fix it?&quot; situation.</p><p>My advice: stop trying to do this, host the site with an established provider.</p></div></blockquote></div><p>Security is manageable - it&#039;s a step by step process.</p><p>I have web sites hosted on Bluehost, and have for a long time.</p><p>This is about the Linux spirit of independence and learning.</p><p>Again, this was working, but due to missing the hardware RAID toggle &#039;on&#039;, the system was unstable and had to be reconstructed.</p><p>If nftables would only play nicely it would seem we&#039;d be rocking!</p>]]></description>
			<author><![CDATA[dummy@example.com (dcolburn)]]></author>
			<pubDate>Wed, 25 Jan 2023 16:35:38 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40574#p40574</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40572#p40572</link>
			<description><![CDATA[<p>I powered-off the server overnight and just powered back up.</p><div class="codebox"><pre><code>root@devuan1:/# service nftables status
nftables: unrecognized service
root@devuan1:/# service nftables restart
nftables: unrecognized service
root@devuan1:/# service nftables force-reload
nftables: unrecognized service
root@devuan1:/# nft list ruleset
root@devuan1:/# </code></pre></div><p>I suspected a potential conflict but that doesn&#039;t appear to be the case ...</p><div class="codebox"><pre><code>root@devuan1:/# whereis ufw
ufw: /etc/ufw
root@devuan1:/# whereis iptables
iptables: /usr/sbin/iptables /usr/share/iptables /usr/share/man/man8/iptables.8.gz
root@devuan1:/# service ufw status
ufw: unrecognized service
root@devuan1:/# service iptables status
iptables: unrecognized service
root@devuan1:/# </code></pre></div><p>Just tried <span class="bbc">nft flush ruleset;nft -f /etc/nftables.conf</span> - no change.</p><p>FYI ...</p><div class="codebox"><pre><code>root@devuan1:/# nft -v
nftables v0.9.8 (E.D.S.)
root@devuan1:/# </code></pre></div><p>This remains a concern&#160; ...</p><div class="codebox"><pre><code>root@devuan1:/# whereis libmnl
libmnl:
root@devuan1:/# whereis libnftnl
libnftnl:
root@devuan1:/# </code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (dcolburn)]]></author>
			<pubDate>Wed, 25 Jan 2023 15:49:02 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40572#p40572</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40571#p40571</link>
			<description><![CDATA[<div class="quotebox"><cite>Marjorie wrote:</cite><blockquote><div><p>As he has a fixed IP from his ISP (though I recall he does describe it as immutable not fixed) that isn&#039;t necessarily an issue</p></div></blockquote></div><p>I wasn&#039;t referring to dynamic IPs, but rather the security implications.</p><p>Given the level of experience/understanding displayed and the cherry-picking of responses, I don&#039;t want to contribute towards an eventual &quot;My home network is compromised, how do I fix it?&quot; situation.</p><p>My advice: stop trying to do this, host the site with an established provider.</p>]]></description>
			<author><![CDATA[dummy@example.com (boughtonp)]]></author>
			<pubDate>Wed, 25 Jan 2023 15:47:04 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40571#p40571</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40566#p40566</link>
			<description><![CDATA[<div class="quotebox"><cite>dcolburn wrote:</cite><blockquote><div><p>Love the gone &quot;pear shaped&quot; humor. You remind me of an old friend.</p><p>I swapped your nftables.conf code for mine - do I need to reboot for it to take effect?</p><p>EDIT 1:</p><p>Rebooted - no joy.</p><p>EDIT 2:</p><p><span class="bbc"># nft -cf /etc/nftables.conf</span> reports no errors.</p></div></blockquote></div><p>(as root)</p><p><strong>service nftables status</strong></p><p>will tell you if its running.</p><p><strong>service nftables restart</strong><br />or<br /><strong>service&#160; nftables force-reload</strong></p><p>can be used to restart or just reload the conf file respectively. Or a reboot will also work.</p><p>as well as status run </p><p><strong>nft list ruleset</strong></p><p>and post it so we can check its working.</p><p>If it is working then I expect your problem is elsewhere. </p><p>Try a port scan from another machine on your network to see if ports 80 and 443 are open.</p>]]></description>
			<author><![CDATA[dummy@example.com (Marjorie)]]></author>
			<pubDate>Wed, 25 Jan 2023 10:25:20 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40566#p40566</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40564#p40564</link>
			<description><![CDATA[<div class="quotebox"><cite>Marjorie wrote:</cite><blockquote><div><p>You could try <em>this</em> nftables.conf.</p></div></blockquote></div><p>I did provide the OP with a workable nftable configuration for their use case but they don&#039;t appear to be using it. No idea why.</p><p>@all: probably best to stop pandering to this person, I suspect they are trolling us.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Wed, 25 Jan 2023 07:08:29 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40564#p40564</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40561#p40561</link>
			<description><![CDATA[<p>If the git directory on your system has pathname /home/user/mygitworkspace you would remove that git directory with the terminal command sequence:</p><div class="codebox"><pre><code>$ cd /home/user
$ rm -rf mygitworkspace</code></pre></div><p>Technically, &quot;rm&quot; is the program to run, &quot;-rf&quot; asks for the command variation to delete stuff recursively and force deletion to apply also for read-only files/directories, and &quot;mygitworkspace&quot; identifies the top-level pathname of files and directories to remove.</p>]]></description>
			<author><![CDATA[dummy@example.com (ralph.ronnquist)]]></author>
			<pubDate>Wed, 25 Jan 2023 04:01:40 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40561#p40561</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40560#p40560</link>
			<description><![CDATA[<div class="quotebox"><cite>ralph.ronnquist wrote:</cite><blockquote><div><p>May I suggest that you don&#039;t want to compile any netfilter components?</p></div></blockquote></div><p>Can you point me to a reliable instructional as to how to have git remove the &#039;objects&#039; it loaded, please?</p><p>The less clutter the better.</p><p>Thanks</p>]]></description>
			<author><![CDATA[dummy@example.com (dcolburn)]]></author>
			<pubDate>Wed, 25 Jan 2023 03:11:22 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40560#p40560</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40555#p40555</link>
			<description><![CDATA[<p>Love the gone &quot;pear shaped&quot; humor. You remind me of an old friend.</p><p>I swapped your nftables.conf code for mine - do I need to reboot for it to take effect?</p><p>EDIT 1:</p><p>Rebooted - no joy.</p><p>EDIT 2:</p><p><span class="bbc"># nft -cf /etc/nftables.conf</span> reports no errors.</p>]]></description>
			<author><![CDATA[dummy@example.com (dcolburn)]]></author>
			<pubDate>Tue, 24 Jan 2023 23:16:41 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40555#p40555</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40553#p40553</link>
			<description><![CDATA[<p>You could try <em>this</em> nftables.conf.</p><p>This is based on mine, which works, the only changes are that I&#039;ve pruned the additional ports I&#039;ve opened on mine for email, ntp, dns, monitoring.</p><div class="codebox"><pre><code>#!/usr/sbin/nft -f
flush ruleset
table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;

    iifname lo accept
    ct state established,related accept
    tcp dport ssh ct state new accept
    tcp dport http ct state new accept
    tcp dport https ct state new accept
    
     # ICMP: errors, pings
     ip protocol icmp icmp type { echo-request, echo-reply, destination-unreachable, time-exceeded, parameter-problem, router-solicitation, router-advertisement } accept
     # ICMPv6: errors, pings, routing
     ip6 nexthdr icmpv6 counter accept comment &quot;accept all ICMP types&quot;

     # Reject other packets
     ip protocol tcp reject with tcp reset
  }
}</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (Marjorie)]]></author>
			<pubDate>Tue, 24 Jan 2023 22:41:52 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40553#p40553</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40552#p40552</link>
			<description><![CDATA[<p>You should run</p><div class="codebox"><pre><code># nft -cf /etc/nftables.conf</code></pre></div><p> repeatedly, and each time look at and <span class="bbu">correct only the first error</span>, until that command no longer gives any output.</p><p>Thereafter you apply the corrected rule set with </p><div class="codebox"><pre><code># nft -cf /etc/nftables.conf</code></pre></div><p>Hint: you current nftables.conf has 3 syntax errors.</p>]]></description>
			<author><![CDATA[dummy@example.com (ralph.ronnquist)]]></author>
			<pubDate>Tue, 24 Jan 2023 22:19:42 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40552#p40552</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40551#p40551</link>
			<description><![CDATA[<div class="quotebox"><cite>boughtonp wrote:</cite><blockquote><div><p>The IP in your most recent post is not a private address - it appears to belong to an ISP - indicating that you may be trying to run a public Internet-facing webserver from a machine on your home network...?</p></div></blockquote></div><p>As he has a fixed IP from his ISP (though I recall he does describe it as immutable not fixed) that isn&#039;t necessarily an issue: I have a fixed IP from my ISP (Zen) and it hosts both an accessible (apache) website and my (postfix) family mail server. <br />And we <em>were</em> able to access his website too at one point before it all went pear-shaped.</p><p>But as your (dcolburn) server is on a network behind a router can I assume that you have opened the relevant ports on the router as well as your server&#039;s (nftables) firewall?</p>]]></description>
			<author><![CDATA[dummy@example.com (Marjorie)]]></author>
			<pubDate>Tue, 24 Jan 2023 22:14:44 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40551#p40551</guid>
		</item>
		<item>
			<title><![CDATA[Re: git netfilter compile problem]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=40545#p40545</link>
			<description><![CDATA[<div class="quotebox"><cite>Head_on_a_Stick wrote:</cite><blockquote><div><p>Is nftables actually running?</p><div class="codebox"><pre><code># nft list ruleset</code></pre></div><p>I would just ignore that &quot;guide&quot;. It looks like one of those shitty sites that farm forum &amp; wiki content for ad revenue.</p></div></blockquote></div><div class="codebox"><pre><code>root@devuan1:~/libnftnl# nft list ruleset
table ip nat {
	chain postrouting {
		type nat hook postrouting priority srcnat; policy accept;
		ip saddr 192.168.1.0/24 oif &quot;eth0&quot; snat to 1.2.3.4
	}
}
root@devuan1:~/libnftnl# </code></pre></div><p>What is this telling me about what&#039;s happening - and what&#039;s not happening that should be?</p>]]></description>
			<author><![CDATA[dummy@example.com (dcolburn)]]></author>
			<pubDate>Tue, 24 Jan 2023 18:40:36 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=40545#p40545</guid>
		</item>
	</channel>
</rss>
