farley 发表于 2007-1-25 21:30:19

移植 iptables到arm linux

1、编译内核,支持netfilter

在宿主机上进入Linux内核目录,配置所需的内核模块:

#cd/root/kernel-2410/kernel-2410s/
#makemenuconfig

选中如下内核选项:

General setup --->
[*] Sysctl support (在ROMFS文件系统中/proc/sys/net/ipv4/出现ip_forward)
Networking options --->
[*] Network packet filtering (replaces ipchains)
IP: Netfilter Configuration --->(全部选择即可)
2、编译生成iptables命令
#cd /root/iiptables-1.2.11
# make KERNEL_DIR=/root/kernel-2410/kernel-2410s/
--------------------
正常
--------------------
# make NO_SHARED_LIBS=1
Extensions found:
/opt/host/armv4l/bin/armv4l-unknown-linux-gcc -O2 -Wall -Wunused -I/usr/src/linux/include -Iinclude/ -DIPTABLES_VERSION=\"1.2.11\"-DNO_SHARED_LIBS=1 -D_UNKNOWN_KERNEL_POINTER_SIZE -D_INIT=ipt_conntrack_init -c -o extensions/libipt_conntrack.o extensions/libipt_conntrack.c
In file included from extensions/libipt_conntrack.c:15:
extensions/../include/linux/netfilter_ipv4/ipt_conntrack.h:29: `IP_CT_DIR_MAX' undeclared here (not in a function)
extensions/../include/linux/netfilter_ipv4/ipt_conntrack.h:30: `IP_CT_DIR_MAX' undeclared here (not in a function)
extensions/../include/linux/netfilter_ipv4/ipt_conntrack.h:30: `IP_CT_DIR_MAX' undeclared here (not in a function)
extensions/libipt_conntrack.c: In function `parse_status':
extensions/libipt_conntrack.c:110: `IPS_EXPECTED' undeclared (first use in this function)
extensions/libipt_conntrack.c:110: (Each undeclared identifier is reported only once
extensions/libipt_conntrack.c:110: for each function it appears in.)
extensions/libipt_conntrack.c:112: `IPS_SEEN_REPLY' undeclared (first use in this function)
extensions/libipt_conntrack.c:114: `IPS_ASSURED' undeclared (first use in this function)
extensions/libipt_conntrack.c: In function `parse':
extensions/libipt_conntrack.c:229: `IP_CT_DIR_ORIGINAL' undeclared (first use in this function)
extensions/libipt_conntrack.c:286: `IP_CT_DIR_REPLY' undeclared (first use in this function)
extensions/libipt_conntrack.c: In function `print_status':
extensions/libipt_conntrack.c:395: `IPS_EXPECTED' undeclared (first use in this function)
extensions/libipt_conntrack.c:399: `IPS_SEEN_REPLY' undeclared (first use in this function)
extensions/libipt_conntrack.c:403: `IPS_ASSURED' undeclared (first use in this function)
extensions/libipt_conntrack.c: In function `matchinfo_print':
extensions/libipt_conntrack.c:457: `IP_CT_DIR_ORIGINAL' undeclared (first use in this function)
extensions/libipt_conntrack.c:477: `IP_CT_DIR_REPLY' undeclared (first use in this function)
make: *** 错误 1
#

谁移植过iptables,大家指点指点,谢谢!
页: [1]
查看完整版本: 移植 iptables到arm linux