Linode Forum Index Linode Forum
Linode Community Forums
 


APF won't start

Click here to go to the original topic

 
       Linode Forum Index -> General Discussion
Author Message
neorder



Joined: 21 Dec 2003
Posts: 30

Posted: Wed Feb 11, 2004 10:59 am    Post subject: APF won't start  

hi, i use RH9 and Directadmin, i install APF firewall but it won't start, i got this:

lsmod: QM_MODULES: Function not implemented

Unable to load iptables module (ip_tables), aborting.

i'm sure iptables is running, and i'm using a VPS which is made by UML, i supposed it's the kenel problem, so i tried to recompile apache, but i still get same problem in the end.

i've done some research at google but no luck, any idea about this issue?
________
VAPORIZER REVIEW
Back to top  
inkblot



Joined: 08 Sep 2003
Posts: 62
Location: Bucharest

Posted: Wed Feb 11, 2004 11:57 am    Post subject: Re: APF won't start  

neorder wrote: hi, i use RH9 and Directadmin, i install APF firewall but it won't start, i got this:

lsmod: QM_MODULES: Function not implemented

Unable to load iptables module (ip_tables), aborting.

i'm sure iptables is running, and i'm using a VPS which is made by UML, i supposed it's the kenel problem, so i tried to recompile apache, but i still get same problem in the end.

i've done some research at google but no luck, any idea about this issue?

the linode kernels do not support loadable modules. all available functionality is compiled in.
Back to top  
neorder



Joined: 21 Dec 2003
Posts: 30

Posted: Wed Feb 11, 2004 12:56 pm    Post subject:  

is that meaning i'm unable to use APF here?
________
VAPORIZER REVIEWS
Back to top  
Bill Clinton



Joined: 23 Nov 2003
Posts: 79

Posted: Wed Feb 11, 2004 1:08 pm    Post subject: Re: APF won't start  

inkblot wrote: the linode kernels do not support loadable modules. all available functionality is compiled in.
This raises an interesting issue: custom kernel modules.

What are the security implications of such ?

Bill Clinton
Back to top  
smerritt



Joined: 18 Nov 2003
Posts: 30

Posted: Wed Feb 11, 2004 1:08 pm    Post subject:  

It sounds to me like APF is trying to determine whether or not it needs to load the iptables module. If there's a way to tell it not to check for iptables, the rest of it should work.

Alternately, you could try moving /sbin/lsmod somewhere else and seeing what it does. You don't need lsmod if the kernel doesn't support modules.
Back to top  
smerritt



Joined: 18 Nov 2003
Posts: 30

Posted: Wed Feb 11, 2004 1:16 pm    Post subject:  

Quote: This raises an interesting issue: custom kernel modules.

What are the security implications of such ?


Kernel module code runs as part of the kernel. There's no sandboxing or anything; the module code gets loaded into the kernel's address space with the same privileges as the kernel.

Under UML, if I could load a module, I could make my UML process do stuff on the host. At Linode, I think each UML process runs as a different unprivileged user, so there's not much risk of accessing someone's data. However, a malicious user could still do a DoS attack on the host. Something to eat all the memory, thrash the disk, or even just a fork bomb would really slow down all the Linodes on that host.
Back to top  
keithbucher



Joined: 12 Oct 2009
Posts: 1

Posted: Mon Oct 12, 2009 10:32 pm    Post subject:  

This probably won't help the original posters, but if anyone else runs into this problem, you can fix it with the following config option in /etc/apf/conf.apf:

SET_MONOKERN="1"

This makes APF assume that all the required modules are already present without checking.
Back to top  
Guspaz



Joined: 26 May 2009
Posts: 1030
Location: Montreal, QC

Posted: Tue Oct 13, 2009 10:15 am    Post subject:  

keithbucher wrote: This probably won't help the original posters, but if anyone else runs into this problem, you can fix it with the following config option in /etc/apf/conf.apf:

SET_MONOKERN="1"

This makes APF assume that all the required modules are already present without checking.

But Linode uses Xen now, which *does* support loading kernel modules, so you shouldn't need to do that. You're replying to a post that's more than half a decade old.
Back to top  
arjones85



Joined: 12 Oct 2009
Posts: 39

Posted: Tue Oct 13, 2009 11:24 am    Post subject:  

How did you manage to get a copy of APF? rfxnetworks.com is broken and I can't seem to download anything.

I use APF on one of my older VPS's, but considering they aren't taking care of the dead links on their site, it makes me think twice before using their software.
Back to top  
 
       Linode Forum Index -> General Discussion
Page 1 of 1