ip6tables-save error in syslog

gecko64

Member
Jun 19, 2013
3
0
21
Hello, i've got a problem with my proxmox server.
I've done an upgrade of the server and since i've got this every 10seconds in my syslog :
Code:
Feb 13 05:14:37 sd-xxxxxx pve-firewall[2757]: status update error: command '/sbin/ip6tables-save' failed: exit code 1

When i execute this in command line, i've got this :
Code:
root@sd-xxxxxx:~# /sbin/ip6tables-save
ip6tables-save v1.4.14: Cannot initialize: Address family not supported by protocol

I think it's a problem with ipv6 but i've actually no more idea...
Don't know if someone can help me ?
My server has no ipv6 for the moment.

Thank you !
Gecko64
 
Code:
root@sd-xxxxxx:~# pveversion -v
proxmox-ve-2.6.32: 3.3-147 (running kernel: 2.6.32-37-pve)
pve-manager: 3.3-19 (running version: 3.3-19/c4c740ea)
pve-kernel-2.6.32-37-pve: 2.6.32-147
pve-kernel-2.6.32-34-pve: 2.6.32-140
lvm2: 2.02.98-pve4
clvm: 2.02.98-pve4
corosync-pve: 1.4.7-1
openais-pve: 1.1.4-3
libqb0: 0.11.1-2
redhat-cluster-pve: 3.2.0-2
resource-agents-pve: 3.9.2-4
fence-agents-pve: 4.0.10-2
pve-cluster: 3.0-16
qemu-server: 3.3-17
pve-firmware: 1.1-3
libpve-common-perl: 3.0-24
libpve-access-control: 3.0-16
libpve-storage-perl: 3.0-30
pve-libspice-server1: 0.12.4-3
vncterm: 1.1-8
vzctl: 4.0-1pve6
vzprocps: 2.0.11-2
vzquota: 3.1-2
pve-qemu-kvm: 2.1-12
ksm-control-daemon: 1.1-1
glusterfs-client: 3.5.2-1
 
I see the same messages since I did the a dist-upgrade yesterday

Code:
vmonster:/var/log# pveversion -v
proxmox-ve-2.6.32: 3.3-147 (running kernel: 2.6.32-37-pve)
pve-manager: 3.3-19 (running version: 3.3-19/c4c740ea)
pve-kernel-2.6.32-37-pve: 2.6.32-147
pve-kernel-2.6.32-34-pve: 2.6.32-140
lvm2: 2.02.98-pve4
clvm: 2.02.98-pve4
corosync-pve: 1.4.7-1
openais-pve: 1.1.4-3
libqb0: 0.11.1-2
redhat-cluster-pve: 3.2.0-2
resource-agents-pve: 3.9.2-4
fence-agents-pve: 4.0.10-2
pve-cluster: 3.0-16
qemu-server: 3.3-17
pve-firmware: 1.1-3
libpve-common-perl: 3.0-24
libpve-access-control: 3.0-16
libpve-storage-perl: 3.0-30
pve-libspice-server1: 0.12.4-3
vncterm: 1.1-8
vzctl: 4.0-1pve6
vzprocps: 2.0.11-2
vzquota: 3.1-2
pve-qemu-kvm: 2.1-12
ksm-control-daemon: 1.1-1
glusterfs-client: 3.5.2-1
 
What is the output of

# lsmod|grep ip6


Hello,

Same problem for me after update in 3.4
ipv6 doesnt' run anymore a few second after boot.

root@:~# lsmod|grep ipv6
nf_conntrack_ipv6 8441 2
nf_defrag_ipv6 27300 1 nf_conntrack_ipv6
nf_conntrack 80689 9 nf_conntrack_ipv4,xt_state,nf_nat,iptable_nat,nf_conntrack_ftp,nf_nat_ftp,vzcpt,vzrst,nf_conntrack_ipv6
ipv6 340972 104 ib_addr,ib_ipoib,bonding,ip6table_mangle,ip6t_REJECT,vzcpt,vzrst,nf_defrag_ipv6,nf_conntrack_ipv6
 
Similar issue here, syslog is FULL of

Code:
[COLOR=#000000][FONT=tahoma]Feb 23 12:06:32 trns-ve1 pve-firewall[675193]: status update error: iptables_restore_cmdlist: Try `ip6tables-restore -h' or 'ip6tables-restore --help' for more information.[/FONT][/COLOR]


Version / debug info:

Code:
root@trns-ve1:/etc/pve # pveversion -vproxmox-ve-2.6.32: 3.3-147 (running kernel: 2.6.32-34-pve)
pve-manager: 3.4-1 (running version: 3.4-1/3f2d890e)
pve-kernel-2.6.32-32-pve: 2.6.32-136
pve-kernel-2.6.32-37-pve: 2.6.32-147
pve-kernel-2.6.32-34-pve: 2.6.32-140
lvm2: 2.02.98-pve4
clvm: 2.02.98-pve4
corosync-pve: 1.4.7-1
openais-pve: 1.1.4-3
libqb0: 0.11.1-2
redhat-cluster-pve: 3.2.0-2
resource-agents-pve: 3.9.2-4
fence-agents-pve: 4.0.10-2
pve-cluster: 3.0-16
qemu-server: 3.3-20
pve-firmware: 1.1-3
libpve-common-perl: 3.0-24
libpve-access-control: 3.0-16
libpve-storage-perl: 3.0-31
pve-libspice-server1: 0.12.4-3
vncterm: 1.1-8
vzctl: 4.0-1pve6
vzprocps: 2.0.11-2
vzquota: 3.1-2
pve-qemu-kvm: 2.1-12
ksm-control-daemon: 1.1-1
glusterfs-client: 3.5.2-1

Code:
root@trns-ve1:/etc/pve # lsmod|grep ip6
ip6t_REJECT             4671  0
ip6table_mangle         3693  0
ip6table_filter         3057  0
ip6_tables             19016  2 ip6table_filter,ip6table_mangle
ipv6                  324356  146 ib_addr,ip6table_mangle,ip6t_REJECT,vzrst
 
Hello, i've got a problem with my proxmox server.
I've done an upgrade of the server and since i've got this every 10seconds in my syslog :
Code:
Feb 13 05:14:37 sd-xxxxxx pve-firewall[2757]: status update error: command '/sbin/ip6tables-save' failed: exit code 1

Same problem here after upgrading to 3.4!
 
I'm not familiar with the PVE-Firewall since i'm not using it on my DEV Server. But per definition the PVE-Firewall should be disabled as I learned. I checked all of my configuration Files if the PVE-Firewall service is really disabled.
Just out of curiosity I stopped the PVE-Firewall

Code:
/etc/init.d/pve-firewall stop

and the following entries in /var/log/daemon.log disappeard.
Code:
Feb 25 16:06:11 vmonster pve-firewall[401070]: status update error: command '/sbin/ip6tables-save' failed: exit code 1

I'm not sure, but this seems to be a bug in 3.4 - I might be wrong.
 
Solved. It seems that installation has ipv6 disabled.
Edit /etc/modprobe.d/local.conf and change line:

options ipv6 disabled=0

Worked for me.
 
Solved. It seems that installation has ipv6 disabled.
Edit /etc/modprobe.d/local.conf and change line:

options ipv6 disabled=0

Worked for me.
this is just a workaround.

We dont use ipv6, so we disable it in all servers.
proxmox pve firewall sould check for ipv6 support, and dont run ipv6 save/restore if it is disabled.

Elbandi