Bug 761544 - Loading module with parameter failed
Summary: Loading module with parameter failed
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: iptables
Version: 6.2
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: rc
: ---
Assignee: iptables-maint-list
QA Contact: qe-baseos-daemons
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-12-08 15:14 UTC by Branislav Náter
Modified: 2011-12-13 15:10 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-12-13 15:10:51 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Branislav Náter 2011-12-08 15:14:40 UTC
Description of problem:
If you want to run ftp server on different port, you have to tell nf_conntrack_ftp module to track connection on that port. iptables init script is not able to load module with parameter correctly.

Version-Release number of selected component (if applicable):
iptables-1.4.7-4.el6.x86_64

How reproducible:
always

Steps to Reproduce:
1. modify /etc/sysconfig/iptables-config file, add ports=9876 parameter to nf_conntrack_ftp module. Line should look similar to this one:
IPTABLES_MODULES="nf_conntrack_netbios_ns nf_conntrack_ftp ports=9876"
2. re/start iptables (service iptables restart)
  
Actual results:
# service iptables restart
iptables: Flushing firewall rules:                         [  OK  ]
iptables: Setting chains to policy ACCEPT: mangle nat filte[  OK  ]
iptables: Unloading modules:                               [  OK  ]
iptables: Applying firewall rules:                         [  OK  ]
iptables: Loading additional modules: nf_conntrack_netbios_[FAILED]nntrack_ftp ports=9876

Expected results:
iptables: Flushing firewall rules:                         [  OK  ]
iptables: Setting chains to policy ACCEPT: filter          [  OK  ]
iptables: Unloading modules:                               [  OK  ]
iptables: Applying firewall rules:                         [  OK  ]
iptables: Loading additional modules: nf_conntrack_netbios_[  OK  ]nntrack_ftp

Comment 2 Thomas Woerner 2011-12-13 15:10:51 UTC
Please create a new conf file in /etc/modprobe.d and add the option for the module there:

/etc/modprobe.d/nf.conf
options nf_conntrack_ftp ports=9876

IPTABLES_MODULES only contains module names, please have a look at the documentation:

# Load additional iptables modules (nat helpers)
#   Default: -none-
# Space separated list of nat helpers (e.g. 'ip_nat_ftp ip_nat_irc'), which
# are loaded after the firewall rules are applied. Options for the helpers are
# stored in /etc/modprobe.conf.

Closing as not a bug.


Note You need to log in before you can comment on or make changes to this bug.