Brocade Fibre Channel Networking Community

Expand all | Collapse all

IPtables - can't activate

  • 1.  IPtables - can't activate

    Posted 11-19-2019 11:28 AM

    Not that I can –show , but can't –activate .  Even when logged in as admin.

    Core issue is unable to get to GUI – looks like our rules are not allowing IPv4, so we want to activate the IPv4 ruleset.  But we cant.

     

    sw107:FID128:admin> ipfilter --show default_ipv4

     Name: default_ipv4, Type: ipv4, State: defined

    Rule    Source IP                               Protocol   Dest Port   Action

    1     any                                            tcp       22     permit

    2     any                                            tcp       23     permit

    3     any                                            tcp       80     permit

    4     any                                            tcp      443     permit

    5     any                                            udp      161     permit

    6     any                                            udp      123     permit

    7     any                                            tcp      600 - 1023     permit

    8     any                                            udp      600 - 1023     permit

    sw107:FID128:admin> ipfilter --activate default_ipv4

    Specified IP filter policy not found

    sw107:FID128:admin>

     

    sw107:FID128:harryc> version

    Kernel:     2.6.14.2

    Fabric OS:  v8.1.0c

    Made on:    Wed Jun 21 20:43:07 2017

    Flash:      Fri Nov 15 22:16:32 2019

    BootProm:   1.0.11

    sw107:FID128:harryc>



    ------------------------------
    Harry C
    SysAdmin
    American Bar Assoc.

    tout jour prest
    ------------------------------


  • 2.  RE: IPtables - can't activate

    Posted 11-25-2019 07:41 AM
    Hello,

    that looks weird please try to clone rule and activate it then (all described in admin guide.)

    ------------------------------
    If my answer fulfilled your question please mark the reply as "Make Best Answer"

    Kind Regards

    Marian
    ------------------------------



  • 3.  RE: IPtables - can't activate

    Posted 11-27-2019 08:31 AM
    We tried clone, tried creating fresh, same result, we have them defined but can't activate.

    Adding insult to injury even though I still can't get in the GUI my security team found it to be running the default password.

    The new switches are otherwise up and stable so now I will upgrade the older pair ( no longer part of the fabric ) and see if this problem recurs.  If it does I will have much more freedom to try things on the unused switches.

    ------------------------------
    Harry C
    SysAdmin
    American Bar Assoc.

    tout jour prest
    ------------------------------



  • 4.  RE: IPtables - can't activate

    Posted 11-27-2019 02:58 PM
    Hello,

    will wait for your findings!

    ------------------------------
    If my answer fulfilled your question please mark the reply as "Make Best Answer"

    Kind Regards

    Marian
    ------------------------------



  • 5.  RE: IPtables - can't activate

    Posted 12-04-2019 11:21 AM

    The old switches won't support FOS 8.0 or higher, so I have upgraded one to 7.4 – now the "installed" hack works on it.

     

    http://10.10.2.95/SwitchExplorer_installed.html

     

    I will put in a CCR to generate/update the keys on the new ones next week – that is the next suggested step.



    ------------------------------
    Harry C
    SysAdmin
    American Bar Assoc.

    tout jour prest
    ------------------------------