Quote:
Originally Posted by knc1
Sorry - Missed this one earlier.
The userland application (iptables) seems to be complete, if not, twobob has already built the newest and greatest.
The factory kernel on the other hand is missing a lot of the netfilter modules.
Will have to build those and ship them as part of the BBB (and later, the kWall) button set.
For instance: lab126 did not build the "REJECT" module.
Which is required for proper protocol control operation.
|
I once built netfilter kernel modules for KT 5.3.2 (attached). I had an idea to block outgoing connections by process id (-m owner --pid-owner), but it turned out that this option is not supported by modern kernels anymore.