- 论坛徽章:
- 0
|
5可用积分
firewall-04:/usr/src # ll
total 760
drwxr-xr-x 8 1000 1000 4096 Mar 23 12:44 iptables-1.4.2
-rw-r--r-- 1 root root 435891 Mar 20 10:53 iptables-1.4.2.tar.bz2
-rw-r--r-- 1 root root 128951 Mar 20 10:53 l7-protocols-2008-12-18.tar.gz
lrwxrwxrwx 1 root root 19 Mar 20 10:10 linux -> linux-2.6.25.20-0.1
drwxr-xr-x 23 root root 4096 Mar 24 11:15 linux-2.6.25.20-0.1
drwxr-xr-x 3 root root 4096 Mar 20 10:28 linux-2.6.25.20-0.1-obj
lrwxrwxrwx 1 root root 23 Mar 20 10:10 linux-obj -> linux-2.6.25.20-0.1-obj
drwxr-xr-x 4 1000 1000 4096 Jan 8 10:48 netfilter-layer7-v2.21
-rw-r--r-- 1 root root 174702 Mar 20 10:53 netfilter-layer7-v2.21.tar.gz
drwxr-xr-x 7 root root 4096 Jun 10 2008 packages我安装了l7也编译了内核和iptables,过程没有报错.然后应用了下
$IPTABLES -A FORWARD -m layer7 --l7proto xunlei -j DROP
$IPTABLES -A FORWARD -m layer7 --l7proto pplive -j DROP
$IPTABLES -A FORWARD -m layer7 --l7proto kugoo -j DROP
$IPTABLES -A FORWARD -m layer7 --l7proto bittorrent -j DROP我查看log:
Mar 25 13:04:43 firewall-04 named[2661]: unexpected RCODE (SERVFAIL) resolving 'gndfeblb.cn/A/IN': 202.96.209.133#53
Mar 25 13:04:44 firewall-04 kernel: layer7: couldn't get conntrack.
Mar 25 13:04:58 firewall-04 syslog-ng[2276]: last message repeated 47 times
Mar 25 13:04:58 firewall-04 kernel: layer7: matched kugoo
Mar 25 13:04:58 firewall-04 kernel: layer7: couldn't get conntrack.
^[[BMar 25 13:05:23 firewall-04 syslog-ng[2276]: last message repeated 71 times
Mar 25 13:05:23 firewall-04 kernel: layer7: matched xunlei
Mar 25 13:05:24 firewall-04 kernel: layer7: couldn't get conntrack.
Mar 25 13:05:25 firewall-04 syslog-ng[2276]: last message repeated 15 times
Mar 25 13:05:25 firewall-04 kernel: layer7: matched xunlei
Mar 25 13:05:25 firewall-04 kernel: layer7: matched kugoo
Mar 25 13:05:27 firewall-04 kernel: layer7: couldn't get conntrack.layer7: couldn't get conntrack是什么意思啊 我看内核里也有这个conntrack模块了啊,为什么layer7会得不到这个啊,还有一台机器我也是这么编译的,却没发现日志里有这个现象.我看了些资料,有些说这个是l7的一个bug,有些说是编译问题,我现在没方向了,哪位大哥跟我详细解释下啊,谢谢!另外l7真的能把xunlei,bit,qq,msn完全的封杀吗? |
|