2012年2月6日 星期一

L7-filter Kernel Version HOWTO


Table of Contents

Important links on this page:

What You Need To Get

Kernel Patch

Short version for experts: Apply our kernel patch. Enable the new match option in Netfilter.
Check our kernel compatibility list to see if the Linux version you want to use has been tested.
Use the appropriate kernel patch from the "Layer 7 patches" package to patch[1] the kernel (read the README in the package to determine which patch to use). Set up your kernel as you would otherwise. Now enable the following options (these are correct for Linux 2.6.21.1, but they tend to move around a lot, so you may have to go hunting if you have a different kernel version):
  • "Prompt for development and/or incomplete code/drivers" (under "Code maturity level options")
  • "Network packet filtering framework" (Networking → Networking support → Networking Options)
  • "Netfilter Xtables support" (on the same screen)
  • "Netfilter connection tracking support" (... → Network packet filtering framework → Core Netfilter Configuration), select "Layer 3 Independent Connection tracking"
  • "Connection tracking flow accounting" (on the same screen)
  • And finally, "Layer 7 match support"
  • Optional but highly recommended: Lots of other Netfilter options, notably "FTP support" and other matches. If you don't know what you're doing, go ahead and enable all of them.
Warning: Some users have reported kernel crashes when they using SMP with l7-filter. (Some have also reported that their SMP systems run fine.) If you have a multi-CPU machine, test carefully before putting it into production with l7-filter.
Compile and install the kernel as usual. (Our code may generate warnings about "initialization from incompatible pointer type", ignore them.) Reboot.

1How to patch a source tree

Suppose you have a patch called happy.patch. To apply it, go into the root directory of the source tree you want to patch and run "patch -p1 < happy.patch"

Iptables Setup

First read the README in the package "Layer 7 patches". Depending on your version of iptables, the instructions are different.

iptables 1.4.0 and older

Use the appropriate iptables patch to to patch[1] iptables. Compile iptables, pointing it at your patched kernel source:
  • Run "chmod +x extensions/.layer7-test" (information about file permissions can't be contained in the patch)
  • Then "make KERNEL_DIR=/path/to/patched/kernel_source" (you must have configured your kernel source before this step)
  • And install (as root): "make install KERNEL_DIR=/path/to/patched/kernel_source"

iptables 1.4.1

Don't use this version. There's no reason to and it's difficult to compile.

iptables 1.4.1.1 and newer

Copy libxt_layer7.c and libxt_layer7.man (from the subdirectory of the "Layer 7 patches" package that the README points you to) to the extensions/ directory of your iptables source. Then:
  • "./configure --with-ksource=/path/to/patched/kernel_source" (use the full path)
  • "make"
  • (as root) "make install"

Protocol Definitions (Pattern Files)

These files tell iptables and the kernel how protocol names correspond to regular expressions, e.g. "ftp" means "^220[\x09-\x0d -~]*ftp".
Uncompress the "Protocol Definitions" package and make the resulting directory /etc/l7-protocols.[2]
You should now be ready to actually do stuff.

2Notes for non-conformists

You can also install the patterns in a custom location. If you do this, you need to specify --l7dir before --l7proto when you use l7-filter:

iptables [...] -m layer7 --l7dir /home/bob/patterns --l7proto http [...]

Actually doing stuff

There are three things you may be interested in doing: (1) blocking certain protocols (2) controlling bandwidth use (3) accounting. We cover each of these cases below.
First, a reminder: Just because you're using l7-filter, you don't need to do all of your packet classification using it. It's likely that what you want to accomplish can be at least partially done with less demanding classifiers, such as port matching. For instance, you can probably assume that traffic on TCP port 80 that isn't matched by any P2P patterns is HTTP; you don't need to actually use the HTTP pattern.
l7-filter uses the standard iptables extension syntax. (If you are not familiar with this, it's time to read the documentation at netfilter.org or at least "man iptables".)
iptables [specify table & chain] -m layer7 --l7proto [protocol name] -j [action]
(Or, if you're just interested in accounting, omit "-j [action]".)
For a list of valid protocol names, see the protocols page. You can also add your own protocols.
The only trick is that, in order to do its classification, l7-filter must be able to see all of the relevant traffic. It only sees packets if they go through an l7-filter rule. One way of ensuring this is to use the POSTROUTING chain of the mangle table:
iptables -t mangle -A POSTROUTING -m layer7 --l7proto [etc.]
See this packet flow diagram for details. In some cases, l7-filter can sucessfully match even if it can only see one side of the connection, but in general, this won't work.
If you are using a version of l7-filter earlier than 2.7, you must manually load the ip_conntrack module kernel for l7-filter to work. Newer versions do this automatically.

1. Blocking

Don't. Here's why:
  • l7-filter matching isn't foolproof: there may be both false positives (one protocol can look like another) and false negatives (applications can do obscure things that we didn't count on). Patterns that are known to regularly generate false positives are marked "overmatching" on the protocols page, but others may also do so occasionally.
  • Almost every type of Internet traffic has legitimate uses. For instance, P2P protocols, while widely used to violate copyright, are also an efficient way to distribute open source software and legally free music.
  • Programs can respond to being blocked by port-hopping, switching between TCP and UDP, opening a new connection for every trivial operation, using encryption, or employing other evasion tactics. Trying to block such protocols has consequences on two levels:
    1. In the case of port/protocol-hopping, you make it harder for yourself to identify protocols that already act this way.
    2. You encourage programmers to include these "features" in new programs, making it harder for everyone in the future. For example: In early 2006, Bittorrent started moving towards end-to-end encryption because many networks were either blocking it or severely restricting its bandwidth.
  • l7-filter patterns are not generally designed with blocking in mind. We consider a protocol to be well identified if the identification is useful for controlling its bandwidth. This means, for instance, that for P2P applications, we do not focus on catching connections that are not downloads.
  • Blocking with l7-filter provides no security, since any reasonably determined person can easily circumvent it.
Instead of dropping packets you don't like, we recommend using Linux QoS to restrict their bandwidth usage. If you insist on using l7-filter to drop packets, make sure you have investigated other options first, such as the features of your HTTP proxy (useful for worms).

2. Bandwidth Restriction

To control the bandwidth that a protocol uses, you can use Netfilter to "mark" the packets and QoS to filter on that mark. To mark:
iptables -t mangle -A POSTROUTING -m layer7 --l7proto imap -j MARK --set-mark 3
The number "3" is arbitrary. It can be any integer. Then use tc to filter on that mark (tc is "traffic control", the userspace tool for Linux QoS, part of the iproute2 package):
tc filter add dev eth0 protocol ip parent 1:0 prio 1 handle 3 fw flowid 1:3
Did you understand that last command? You can try reading The Linux Advanced Routing and Traffic Control HOWTO for enlightenment. You should do this so that you have some idea what you're doing, but unfortunately, tc is incredibly obtuse and you're likely to wish you just had a canned script. Well, we can help:
These may need to be modified if your setup is significantly different than mine, but it should provide a much better starting point than most other things you are likely to find.
Be prudent when choosing the amount of bandwidth you allow each protocol. Restricting a protocol to an unusably low bandwidth can have similar consequences to blocking it.

3. Accouting

If you just want to keep track of what's in use on your network, simply use the above command without any -j option. For example:

iptables -t mangle -A POSTROUTING -m layer7 --l7proto imap

You can then get statistics by using iptables -L. (See "man iptables" for details.)

More Information

Dealing with FTP, IRC, etc.

Some protocols open child connections to transfer data. FTP is the most familiar example. If you have loaded the ip_conntrack_ftp or nf_conntrack_ftp kernel module, l7-filter will classify FTP and all its child connections as FTP. The same goes for IRC/IRC-DCC, etc.
If you wish to classify the children differently, use the standard iptables "helper" match. You can use "-m --helper ftp" to match ftp child connections. Of course, once you've done this, it's silly to involve l7-filter, at least for the children.

The "unset" and "unknown" matches

l7-filter marks unmatched connections that it is still trying to match as "unset". The first few packets of all TCP connections as well as those of some UDP connections will match this. Similarly, l7-filter marks connections that it has given up trying to match as "unknown". These are matched just like normal protocols:
iptables -A FORWARD -m layer7 --l7proto unset
iptables -A FORWARD -m layer7 --l7proto unknown

The "unset" match is only supported by l7-filter 2.9 and up.

Upgrading the protocol definitions

The protocol definitions are simple text files with a format described in the Pattern-HOWTO. They can be updated as a package or individually.
If you update the protocol definitions, you need to clear the relevant iptables rules and re-enter them. This is because the pattern files are only read by iptables, not directly by the kernel.

Other things to know

  • By default, l7-filter looks at the first 10 packets or 2kB, whichever is smaller. These limits are somewhat conservative. It is well known that some HTTP connections (those that involve large cookies), for instance, need more packets to be matched.
    • You can alter the number of packets at any time through /proc/net/layer7_numpackets. (i.e. "echo 16 > /proc/net/layer7_numpackets".)
    • In l7-filter versions 2.0 and forward, you can alter the number of bytes at module load time: "modprobe xt_layer7 maxdatalen=N" (ipt_layer7 in old versions), where N is in bytes. This should be used cautiously, since performance may decrease drastically with larger data sizes. To prevent you from accidentally bringing down your network, there is an artificial limit of 65536 imposed. If you're sure you know what you're doing, you can remove this limit by editing ipt_layer7.c or xt_layer7.c in the kernel source.
  • It's possible (although rare) for a connection to be matchable by more than one pattern. The patterns are tested in the order you specified with iptables. After a match is made, l7-filter does not continue testing that connection, so changing the order of your rules may change what happens.
  • Sometimes important messages go only to the system log, not the terminal you are working at. Such messages include notifications that regular expressions failed to compile and various things that tc generates. A useful command is "tail -f /var/log/messages".
Please see the FAQ for more information.

2012年2月3日 星期五

tomato 編譯詳解

看這個帖子這前,請確認一下您能自己搞定ubuntu或debian的安裝,不管是vm下安裝,或實體機安裝均可以,如果您不知道如何安裝它們並使之正常運行,請移步linux社區或論壇學習或放棄..本帖假設您已安裝好ubuntu並可以正常運行和上網. 一.先打開linux終端,在終端命令行下執行,安裝編譯所需的組件


  1. sudo apt-get install build-essential linux-headers-$(uname -r)
  2. sudo apt-get install libncurses5 libncurses5-dev m4 bison flex libstdc++6-4.4-dev g++-4.4 g++ libtool sqlite
  3. sudo apt-get install gcc g++ binutils patch bzip2 flex bison make gettext unzip zlib1g-dev
  4. sudo apt-get install libc6 libncurses5-dev automake automake1.7 automake1.9
  5. sudo apt-get install git-core
  6. sudo apt-get install gitk
以上每複製一行,然後在終執行一次,如果都可以順利完成,請看下一步 二.獲取tomato源代碼


  1. cd ~
  2. sudo -s
  3. mkdir tomato_git
  4. cd tomato_git
  5. git clone git://repo.or.cz/tomato.git
稍等10~30分鐘(取決於網速),完成後,先備份好源碼以便在編譯時改亂了,能恢復原始狀態,需不要重複痛苦的重新下載源碼
  1. tar zcvf tomato_git.tar.gz ./tomato 
完成後,將在當前目錄下生成tomato_git.tar.gz備份包,以備不時之需. 如果源碼有更新,那麼不需要重新下載源碼,只需執行下列命令,可增量同步更新


  1. git pull
三. 建立交叉編譯變量環境
  1. sudo ln -s ~/tomato_git/tomato/tool​​s/brcm /opt/brcm
  1. nano /root/.profile
  2. 在最後一行處加入
  3. if [ -d "/opt/brcm" ] ; then
  4.     PATH=/opt/brcm/hndtools-mipsel-uclibc/bin:/opt/brcm/hndtools-mipsel-linux/bin:$PATH
  5. fi
  6. 按ctrl+xy 保存退出, 以便每次啟動linux時能找到編譯器.
四.查看並獲取當前tomato分支源碼 這部分源碼並不包含在前面的源碼包中,需要另外下載, 1.查看當前源碼分支




  1. cd ~/tomato_git/tomato
  2. git branch -r
  3. 例:
  4. debian:~/tomato_git/tomato# git branch -r
  5.   origin/Clientmon
  6.   origin/HEAD -> origin/tomato
  7.   origin/IPT-X
  8.   origin/QOS-DEV
  9.   origin/QOS-Limiter
  10.   origin/Static-ARP
  11.   origin/Teaman-BWM
  12.   origin/Teaman-IPTraffic
  13.   origin/Teaman-ND
  14.   origin/Teaman-ND-SDHC
  15.   origin/Teaman-RT
  16.   origin/Toastman-IPT-ND
  17.   origin/Toastman-ND
  18.   origin/Toastman-RT
  19.   origin/Toastman-RT-N
  20.   origin/Toastman-VLAN
  21.   origin/Toastman-VLAN-ND
  22.   origin/Toastman-VLAN-RT
  23.   origin/Toastman-VLAN-RT-N
  24.   origin/Tomato-RAF
  25.   origin/Transmission
  26.   origin/VLAN-GUI
  27.   origin/VLAN-MultiSSID
  28.   origin/minidlna
  29.   origin/multilanguage
  30.   origin/nfs_server
  31.   origin/ntfs-3g
  32.   origin/p910nd
  33.   origin/tomato
  34.   origin/tomato-K26-WL
  35.   origin/tomato-ND-USBmod
  36.   origin/tomato-ND-usbmod-mixvpn
  37.   origin/tomato-RT
  38.   origin/tomato-RT-N
  39.   origin/tomato-miniupnpd
  40.   origin/tomato-sdhc-ND-vlan
  41.   origin/tomato-shibby
  42.   origin/tomatovpn
  43.   origin/vpngui
  44.   origin/vsftpd
  45. debian:~/tomato_git/tomato#
2.獲取分支源碼 吐司超人版:


  1. git checkout origin/Toastman-RT
  2. git checkout -b origin/Toastman-RT
Shibby mod版
  1. git checkout origin/tomato-shibby
  2. git checkout -b origin/tomato-shibby
但是要注意,您一次只能獲取一種分支源碼,不能同時下載, 如果已經下載了吐司超人版源碼.. 後來又想編譯Shibby源碼,那麼需要將整個tomato目錄刪掉,重新解壓源碼備份,再獲取shibby源碼,這樣獲得的源碼才乾淨.
  1. sudo rm -rf ~/tomato_git/tomato
  2. tar zxvf ~/tomato_git/tomato.tar.gz .
四.開始編譯. 
如果需要自己配置核心,添加對更多硬件的支持.那麼
  1. R1版:
  2. cd ~/tomato_git/tomato/release/src/linux/linux
  3. 或R2版:
  4. cd ~/tomato_git/tomato/release/src-rt/linux-2.6

  5. sudo make menuconfig
根據情況自行選擇內核參數,沒有經驗不建議更改,很容易導致核心掛掉(省略5000字) 開始編譯.


  1. R1版:
  2. cd ~/tomato_git/tomato/release/src
  3. 或R2版:
  4. cd ~/tomato_git/tomato/release/src-rt
查看有那些參數可選.不同的分支版本,編譯參數是不同的.具體查看
  1. make help
例: 
debian:~/tomato_git/tomato/release/src-rt# make help 
m Ext - (standard plus extra utilities and NTFS support) 
c BTgui - (Ext plus BT gui) 
r BT - (Ext plus BT Client) 
t BT -VPN - (BT plus VPN) 
a Big - (Ext plus NOCAT plus NFS plus BT gui) 
n Mega - (Big + BT Client minus NOCAT) 
e VPN - (standard plus VPN, extra utilities and NTFS support) 
b Big-VPN - (Big plus VPN) 
o Mega-VPN - (Mega plus VPN plus NOCAT minus NFS) 
i MiniIPv6 - (IPv6 with no USB support minus CIFS and RIPv1/2) 
s Std - (no USB support) 
f Mini - (no USB support minus CIFS and RIPv1/2) 
v VPN (no usb) - (VPN with no USB support) 
w SD-VPN (no usb) - (VPN with SD-MOD and no USB support) 
r2m MIPS Release 2 Ext 
r2c MIPS Release 2 BTgui 
r2r MIPS Release 2 BT 
r2t MIPS Release 2 BT-VPN 
r2a MIPS Release 2 Big 
r2n MIPS Release 2 Mega 
r2e MIPS Release 2 VPN 
r2b MIPS Release 2 Big-VPN 
r2o MIPS Release 2 Mega-VPN 
r2z MIPS Release 2 AIO (for routers +8MB flash) 
r2v MIPS Release 2 VPN (no usb) 
r2s MIPS Release 2 Std 
r2i MIPS Release 2 MiniIPv6 (for 4MB flash) 
r2f MIPS Release 2 Mini (for netgear) 
n60m Linksys E-series build Ext 
n60c Linksys E-series build BTGui 
n60r Linksys E-series build BT 
n60t Linksys E-series build BT-VPN 
n60a Linksys E-series build Big 
n60n Linksys E-series build Mega 
n60e Linksys E-series build VPN 
n60b Linksys E-series build Big-VPN 
n60o Linksys E-series build Mega-VPN 
n60s Linksys E-series build Std with IPv6 
n60v Linksys E-series build VPN with IPv6 開始編譯



  1. sudo make V1=Shibby V2=-20111007 r2r
說明:其中V1=分支名稱,V2=版本號,兩個可以自定義,也可以都不要,您自己決定.它會出現在固件的about頁面中的版本中. r2r是表示編譯的是r2版本帶內置bt的功能. 可以休息了,大約1小時到2小時,取決您的電腦速度. 中間如果有出錯,請根據出錯提示信息糾錯解決(需要一定經驗和知識) 編譯完成.在當前的image目錄下可查到,將它複製出來.然後刷機,測試.. 五.重新編譯






  1. 同一版本
  2. make clean

  3. 改動較大版本
  4. make distclean
清整掉以後,再用本節方法重新make. 六.其他 如果您決定編譯shibby源碼最新版.因為最新版的transmission需要libevent-2.0.10以上組件,請替換掉源碼中的libevent舊版本,再進行編譯.否則會出錯



  1. rm -rf ~/tomato_git/tomato/release/src/router/libevent/
  2. wget http://www.monkey.org/~provos/libevent-2.0.10-stable.tar.gz

  3. tar xzvf libevent-2.0.10-stable.tar.gz -C ~/tomato_git/tomato/release/src/router/libevent/
補充參考網站: 
tomatousb官網編譯教程(此教程沒有說明如何獲取tomato分支代碼) http://tomatousb.org/tut:how-to- ... ato-for-total-noobs 數位天堂tomato討論區,認真看,受益非淺. http://digiland.tw/viewforum.php?id=42 
補充內容(2012-1-31 23:49): TT核心配置方面,make menuconfig後會生成.config文件,此配置文件在編譯TT過程中會被刪除,需要處理一下: mv config_base config_base_bak cp .config config_base 
補充內容(2012-1-31 23:50): 還有就是默認情況下編譯shibby下transmission會到libevent時會出錯,處理方法是在src/router/libevent下運行一下./Configure生成配置文件,再回頭繼續編譯,不用替換源碼了。



link from:http://www.right.com.cn/forum/thread-53623-1-1.html

What is Port Triggering?

If you have not read my explanation of port forwarding do so now. You can find it here.
Port triggering is pretty simple once you know what port forwarding is. Port Triggering is port forwarding with an on/off switch for the ports that have been forwarded. This on/off switch is turned on or off by data flowing out of a trigger port.
TriggerPacket.jpg


Let's say that there is a port triggering rule configured in the router. This port triggering rule says when data flows out on port 50 forward port 80. In the picture above you see data flowing from a computer to the internet on port 50.
TriggerForward.jpg


The router see's the traffic coming out of the router on port 50, and evaluates it's triggering rules. The router then forwards port 80 to the computer that sent out the data on port 50. It's important to realize that port 80 can only be forwarded to one computer at a time. If two computers were trying to send data out on port 50, there would be a conflict. What happened after that really depends upon which router you are running. One thing is for sure, port 80 would not be forwarded to both computers.
TriggerNoOut.jpg


The picture above shows that the data has quit being sent out of port 50. Programs do not send data if there is nothing to be sent, so data being sent out of port 50 is not guaranteed. The router keeps port 80 forwarded for a certain amount of time. How much time really depends upon the router.
TriggerNoForward.jpg


Once the router is done waiting, it quits forwarding port 80 to the computer that sent data out on port 50. This makes a port triggering configuration a tricky thing. The software that requires ports to be forwarded must first send data out of a port at a somewhat constant rate. If the software has a port that is constantly sending data out, then port triggering is possible. The length of time that the router keeps those ports open still needs to be taken into account. If the router times out between the gaps of outgoing data, the port forwarding connection will be severed. That is why so few programs support port triggering. What happens when you are trying to download a very large file? Well the software you have setup port triggering for may not keep sending data out of the trigger port. If it doesn't your router closes the incoming ports, and your download is interrupted.
Port Triggering is a little more secure than port forwarding, because the incoming ports are not open all the time. They are only open when a program is actively using the trigger port. Another thing to note, is that most port triggering setups do not require you to enter an internal ip address to forward the incoming ports to. This means that any computer on the network can use your port triggering setup. If two computers try to use the port triggering setup at the same time you will run into problems.

How to repair and clone disk with ddrescue

  ddrescue  is a tool that can be used to repair and clone disks on a  Linux system . This includes hard drives, partitions, DVD discs, flas...