arno-iptables-firewall / aif

GNU General Public License v2.0
151 stars 24 forks source link

Cannot start aif #66

Closed campones closed 5 years ago

campones commented 5 years ago

Hello

I can't start aif, either the package or the git I get from here. try my dedicated as well as a small vps, it's just not working

Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of stealth scans (nmap probes etc.) enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of INVALID TCP packets disabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of INVALID UDP packets disabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of INVALID ICMP packets disabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Dropping and logging of IPv4 fragmented packets disabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of access from reserved nets disabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Reading custom rules from /etc/arno-iptables-firewall/custom-rules Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Checking for (user) plugins in /usr/local/share/arno-iptables-firewall/plugins... Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Loaded 0 plugin(s)... Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Setting up external(INET) INPUT policy Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of ICMP flooding enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Enabling support for DHCP-assigned-IP (DHCP client) Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of explicitly blocked hosts inbound/outbound enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of denied local output connections enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Packets will NOT be checked for reserved source addresses Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Allowing ANYHOST for TCP port(s): 20,21,22,25,53,80,110,143,443,465,587,993,995,1935,3306,5901,8080,8081,8082,,8112,10000,10050,10051,58846 Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: /sbin/iptables -A EXT_INPUT_CHAIN -d 0/0 -p tcp --dport -j ACCEPT Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: ERROR (2): iptables v1.6.1: invalid port/service -j' specified Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Tryiptables -h' or 'iptables --help' for more information. Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Allowing ANYHOST for UDP port(s): 53 Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Allowing ANYHOST to send IPv4 ICMP-requests (ping) Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of possible stealth scans enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of (other) packets to PRIVILEGED TCP ports enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of (other) packets to PRIVILEGED UDP ports enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of (other) packets to UNPRIVILEGED TCP ports enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of (other) packets to UNPRIVILEGED UDP ports enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of IGMP packets enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of dropped ICMP-request(ping) packets enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of dropped other ICMP packets enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of other IP protocols (non TCP/UDP/ICMP/IGMP) packets enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Setting up external(INET) OUTPUT policy Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Applying external(INET) policy to interface: ens3 Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Security is ENFORCED for external interface(s) in the FORWARD chain Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Logging of dropped FORWARD packets enabled Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Apr 21 00:47:37 WARNING: 1 firewall rules failed to apply! Apr 21 00:47:37 vps665030 firewall[13881]: WARNING: 1 firewall rules failed to apply! Apr 21 00:47:37 vps665030 arno-iptables-firewall[13368]: Apr 21 00:47:37 vps665030 systemd[1]: arno-iptables-firewall.service: Main process exited, code=exited, status=1/FAILURE Apr 21 00:47:37 vps665030 systemd[1]: arno-iptables-firewall.service: Failed with result 'exit-code'. Apr 21 00:47:37 vps665030 systemd[1]: Failed to start Arno's Iptables Firewall(AIF). -- Subject: Unit arno-iptables-firewall.service has failed -- Defined-By: systemd -- Support: http://www.ubuntu.com/support

-- Unit arno-iptables-firewall.service has failed.

-- The result is RESULT.

campones commented 5 years ago

ok got it, once again the script put another "," in the port list

sorry