Modify

Ticket #2010 (closed defect: worksforme)

Opened 3 years ago

Last modified 5 months ago

dhcpd: send_packet: Operation not permitted

Reported by: valshare Owned by: jacalvo@…
Milestone: 1.4-maint Component: firewall
Severity: critical Keywords: dhcp
Cc: jsalamero@…

Description

Error message in logfile on DHCPINFORM to Client. Opening Port 68 on firewall resolv the problem.

kernel: [1214996.917571] ebox-firewall drop IN= OUT=vlan701 SRC=192.168.57.241 DST=192.168.57.244 LEN=328 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=67 DPT=68 LEN=308

DHCPINFORM from 192.168.57.244 via vlan701 Jul 21 09:28:40 pat-gw-ebox01 dhcpd: DHCPACK to 192.168.57.244 (00:23:7d:ca:xx:xx) via vlan701

dhcpd: send_packet: Operation not permitted

Attachments

Change History

comment:1 Changed 3 years ago by anonymous

  • Owner changed from ejhernandez@… to cperez@…
  • Component changed from dhcp to firewall

comment:2 Changed 3 years ago by jacalvo@…

  • Cc jsalamero@… added
  • Owner changed from cperez@… to jacalvo@…

Could you send paste the output of "iptables -L -n -v"? Have you modified the eBox default firewall settings in any way?

comment:3 Changed 3 years ago by jacalvo@…

  • Status changed from new to closed
  • Resolution set to worksforme

Reopen if you can provide more info to reproduce it...

comment:4 Changed 11 months ago by asotos@…

  • Status changed from closed to reopened
  • Resolution worksforme deleted

Having the same thing..

Jun 19 16:23:42 hera2 dhcpd: DHCPINFORM from 192.168.2.97 via eth4 Jun 19 16:23:42 hera2 dhcpd: DHCPACK to 192.168.2.97 (50:e5:49:58:a3:4b) via eth4 Jun 19 16:23:42 hera2 dhcpd: send_packet: Operation not permitted

iptables output

7 2296 ACCEPT udp -- * eth0 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:67 0 0 ACCEPT udp -- * eth1 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:67

19 6232 ACCEPT udp -- * eth2 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:67

comment:5 Changed 11 months ago by jamor@…

Hello Asotos,

what interface are you using to serve dhcp? It is marked as internal?.

What traffic ules do you have in Firewall -> Packet Filter -> Filtering rules for traffic coming out from Zentyal ?

Regards,

Javier

comment:6 Changed 11 months ago by jamor@…

  • Status changed from reopened to closed
  • Resolution set to worksforme

Hello,

the service 'DHCP; includes port 67 and 68 you can use it to set any rule you need in the firewall section

comment:7 Changed 5 months ago by Millyfranco

Здраствуйте!! ввожу sudo service rslsyog restart ответ:rsyslog start/running, process 2227ввожу tail -f /var/log/dhcpd.logtail : невозможно открыть var/log/dhcpd.log для чтения: нет такого каталога или файла.когда создаю его вручную то при команде tail -f /var/log/dhcpd.log просто нет ответа, пока не нажмешь ctr + c (ничего не работает) В файле ничего не записалось .

View

Add a comment

Modify Ticket

Change Properties
<Author field>
Action
as closed
The resolution will be deleted. Next status will be 'reopened'
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.