Closed chaosmaou closed 2 months ago
Skynet is complaining about the following rules missing;
iptables -t raw -C PREROUTING -i "$iface" -m set ! --match-set Skynet-MasterWL src -m set --match-set Skynet-Master src -j DROP 2>/dev/null || fail="${fail}#8 " iptables -t raw -C PREROUTING -i br+ -m set ! --match-set Skynet-MasterWL dst -m set --match-set Skynet-Master dst -j DROP 2>/dev/null || fail="${fail}#9 " iptables -t raw -C OUTPUT -m set ! --match-set Skynet-MasterWL dst -m set --match-set Skynet-Master dst -j DROP 2>/dev/null || fail="${fail}#10 " iptables -t raw -C PREROUTING -i "$iface" -m set ! --match-set Skynet-MasterWL src -m set --match-set Skynet-Master src -j LOG --log-prefix "[BLOCKED - INBOUND] " --log-tcp-sequence --log-tcp-options --log-ip-options 2>/dev/null || fail="${fail}#21 " iptables -t raw -C PREROUTING -i br+ -m set ! --match-set Skynet-MasterWL dst -m set --match-set Skynet-Master dst -j LOG --log-prefix "[BLOCKED - OUTBOUND] " --log-tcp-sequence --log-tcp-options --log-ip-options 2>/dev/null || fail="${fail}#22 " iptables -t raw -C OUTPUT -m set ! --match-set Skynet-MasterWL dst -m set --match-set Skynet-Master dst -j LOG --log-prefix "[BLOCKED - OUTBOUND] " --log-tcp-sequence --log-tcp-options --log-ip-options 2>/dev/null || fail="${fail}#23 "
As to why its complaining is another story... do you have any other scripts or "out of the ordinary" aspects to your setup? I see you are using gnuton0 firmware but I would assume everything there is identical to merlin. I am also assuming you have uninstalled Skynet via the menu and reinstalled via amtm to confirm everything is stock as intended.
First I tried doing an uninstall of Skynet, followed by a reboot of the router and clean install. I even tried a full factory reset of the router + clean format of my USB with a clean install of Skynet afterwards.
The gnuton0 firmware support for my router is fairly new, so perhaps the issue doesn't lie with Skynet after all. Currently Skynet will not even install on the latest stable of gnuton0 firmware, so perhaps this issue is on that end of things (I run the latest pre-release). I have the Asus RT-AX3000_V2, which uses the same firmware as the RT-AX58U_V2.
This is a firmware issue and has been fixed by @gnuton https://github.com/gnuton/asuswrt-merlin.ng/issues/559
This should be also fixed on the GT-BE98 in future builds
Brief Description Of Issue
Skynet installs but fails to run correctly.
Tried removing Skynet, rebooting the router, and doing a clean install to troubleshoot. Same result.
Lots of rule integrity violations listed in the debug:
Output of ( sh /jffs/scripts/firewall debug info )