iptables

Tell us your most wanted features from QNAP products.
User avatar
Moogle Stiltzkin
Guru
Posts: 11445
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: iptables

Post by Moogle Stiltzkin »

e..g i got a linksys e4200 router with victek's tomato raf firmware and it has an open vpn client. So i can setup vpn on there, so the qnap and other devices on my network, all benefit from having vpn setup on the router which is the main gateway.

Besides vpns they usually only provide you one license to use, so where else better to put it.



But someone mentioned that with ip tables, the qnap log can be much more powerful in managing ip access to the qnap, is that true ? Any examples ??


I can't think what else we could use the iptables for.
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
User avatar
schumaku
Guru
Posts: 43578
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
Contact:

Re: iptables

Post by schumaku »

Moogle Stiltzkin wrote:But someone mentioned that with ip tables, the qnap log can be much more powerful in managing ip access to the qnap, is that true ? Any examples ??
Pretty good examples here just a few posts back - afraid, you have to learn iptables ... http://forum.qnap.com/viewtopic.php?f=24&t=7886#p205686
User avatar
Moogle Stiltzkin
Guru
Posts: 11445
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: iptables

Post by Moogle Stiltzkin »

schumaku wrote:
Moogle Stiltzkin wrote:But someone mentioned that with ip tables, the qnap log can be much more powerful in managing ip access to the qnap, is that true ? Any examples ??
Pretty good examples here just a few posts back - afraid, you have to learn iptables ... http://forum.qnap.com/viewtopic.php?f=24&t=7886#p205686
*looks
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
jadlak
New here
Posts: 3
Joined: Sat Dec 18, 2010 7:09 am

Re: iptables

Post by jadlak »

+1.

iptables was the reason I came to these forums searching. kinda disappointed that I can't use this machine for that. it isn't just a NAS. this is a home server with NAS features. please fix up what seems to be a glaring hole in the implementation.
fantomas
Experience counts
Posts: 1560
Joined: Mon Feb 07, 2011 5:40 am
Location: Bratislava, Slovakia
Contact:

Re: iptables

Post by fantomas »

gbl wrote: Using a NAS means you're on an internal network. Which means you're behind a router. Which means your router is where your firewall configuration should reside on, not your NAS.
for uploading pictures to public gallery sites, or for viewing them from internet, also for accessing my data from internet, the NAS MUST be accessible somehow. So there's no way why people wouldn't want to use their NAS as home router. Note that WRT routers run on much slower hardware...
experience with administration of UN*X (mostly linux) and applications on internet servers since 1994...
User avatar
Dude-PWB-
Starting out
Posts: 23
Joined: Wed Feb 16, 2011 11:22 am
Location: Canuckistan

Re: iptables

Post by Dude-PWB- »

Just to renew the call for iptables, this is something that is needed for these devices. Almost any linux distribution (client/server) out there comes with iptables enabled by default.
michlv
New here
Posts: 4
Joined: Wed Aug 04, 2010 6:36 am

Re: iptables

Post by michlv »

Another call to add iptables.

Need it for traffic shapping, so when backup over internet runs it does not fill my upstream completely (sometimes for a few days). ADSL router does not support anything like that and to buy extra device just for traffic shapping seems as waste of electricity.
Eddy73
New here
Posts: 6
Joined: Mon Feb 06, 2012 5:57 pm

Re: iptables

Post by Eddy73 »

+1

Need also IPTABLES. Running now the latest firmware (3.6.0) but still got the error below:
[/etc/init.d] # iptables -A PREROUTING -t nat -i eth0 -p tcp --source testing.dyndns.org --dport 12345 -j DNAT -d 192.168.1.10
modprobe: could not parse modules.dep

iptables v1.4.12: can't initialize iptables table `nat': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
JCadet974
First post
Posts: 1
Joined: Wed Feb 22, 2012 1:36 am

Re: iptables

Post by JCadet974 »

+1
Same as Eddy73. Last firmware 3.6.0. but still this uggly error. Nthis does not make sense.
User avatar
schumaku
Guru
Posts: 43578
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
Contact:

Re: iptables

Post by schumaku »

Nothing ugly - the message makes perfect sene: Check the examples on how to load the modules - see init_iptable_modules in /etc/init.d/vpn_openvpn.sh or /etc/init.d/vpn_pptp.sh
Eddy73
New here
Posts: 6
Joined: Mon Feb 06, 2012 5:57 pm

Re: iptables

Post by Eddy73 »

Thanks schumaku, this did help a bit.

Now i have only two problems with this iptables of QNAP:

When i give the following rule:
iptables -A PREROUTING -t nat -i eth0 -p tcp --source testme.dyndns.org --dport 12345 -j DNAT --destination 192.168.1.2:12345

This gives me the error: iptables v1.4.12: host/network `192.168.1.2:12345` not found

When i remove the port at 192.168.1.2:12345 then i get the error:

iptables v1.4.12: Couldn't load target `DNAT`: No such file or directory

Can anybody help me on this one?
Eddy73
New here
Posts: 6
Joined: Mon Feb 06, 2012 5:57 pm

Re: iptables

Post by Eddy73 »

Hi Philippe,

I would like to test that package. Can you give a downloadlink in a PM?

Cheers,
Eddy
Eddy73
New here
Posts: 6
Joined: Mon Feb 06, 2012 5:57 pm

Re: iptables

Post by Eddy73 »

Hi Philippe,

Thanks for the tar file. Tar is just good since I'll untar it on the nas itself.
As soon when I'm home tonight I will test this.

Cheers,
Eddy
lmu
Getting the hang of things
Posts: 55
Joined: Fri Feb 12, 2010 8:00 pm
Contact:

Re: iptables

Post by lmu »

Hi Philippe,

Could you please share the proc. to install your sources. If I understand well, we have to add the path of the provided lib folder in the file ld.so.conf and don't using other like bin, include, ... Correct ?

Can you also explain how to compile iptables on our NAS ?

Thanks in advance for your help,
Laurent
****************************************
Qnap 219 mldonkey
Qnap 239 Pro II+ asterisk, mysql
Qnap 259 Pro+ asterisk, mysql
****************************************
lmu
Getting the hang of things
Posts: 55
Joined: Fri Feb 12, 2010 8:00 pm
Contact:

Re: iptables

Post by lmu »

Sorry Philippe,

my question is not really how but what ... Because, for me the LD_LIBRARY_PATH or ld.so.conf are used to identify the lib path (not bin, include, etc.)

Perhaps you can be more clear on what you add in the ld.so.conf.

Something like (if build is the folder containing your sources) :
[anyPath]/build/lib
or perhaps
[anyPath]/build

Thanks in advance for your clarification,
Laurent
****************************************
Qnap 219 mldonkey
Qnap 239 Pro II+ asterisk, mysql
Qnap 259 Pro+ asterisk, mysql
****************************************
Post Reply

Return to “Features Wanted”