UPDATE:
I installed Sentinel packages in reForis Package Management > Packages
Evn after rebooting, there are no Sentinel options in the left column menu and Threat detection shows disabled in Overview.
After I repeated the installation in shell and accept EULA in shell following the official docs at: Setup - Turris Documentation
The end result
remains unchanged. Am I missing something? Installation output from shell is pasted below.
root@turris:~# opkg install foris-controller-sentinel
-module sentinel-certgen sentinel-dynfw-client sentine
l-eula sentinel-firewall sentinel-fwlogs sentinel-mini
pot sentinel-proxy
Installing foris-controller-sentinel-module (0.3.0-3.10-4) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/foris-controller-sentinel-module_0.3.0-3.10-4_aarch64_cortex-a53.ipk
Installing sentinel-eula (1.1.1-1) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/sentinel-eula_1.1.1-1_aarch64_cortex-a53.ipk
Installing libzmq-nc (4.3.4-2) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/packages/libzmq-nc_4.3.4-2_aarch64_cortex-a53.ipk
Installing libgpg-error (1.45-3) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/packages/libgpg-error_1.45-3_aarch64_cortex-a53.ipk
Installing libgcrypt (1.9.4-1) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/packages/libgcrypt_1.9.4-1_aarch64_cortex-a53.ipk
Installing libmicrohttpd-ssl (0.9.75-2) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/packages/libmicrohttpd-ssl_0.9.75-2_aarch64_cortex-a53.ipk
Installing liblz4 (1.9.3-1) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/packages/liblz4_1.9.3-1_aarch64_cortex-a53.ipk
Installing czmq (4.2.1-2) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/packages/czmq_4.2.1-2_aarch64_cortex-a53.ipk
Installing libpaho-mqtt-c (1.3.9-2) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/libpaho-mqtt-c_1.3.9-2_aarch64_cortex-a53.ipk
Installing libconfig (1.7.3-1) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/packages/libconfig_1.7.3-1_aarch64_cortex-a53.ipk
Installing logc (0.4.0-5) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/logc_0.4.0-5_aarch64_cortex-a53.ipk
Installing logc-argp (0.4.0-5) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/logc-argp_0.4.0-5_aarch64_cortex-a53.ipk
Installing logc-czmq (0.1.0-2) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/logc-czmq_0.1.0-2_aarch64_cortex-a53.ipk
Installing msgpack-c (6.0.0-1) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/packages/msgpack-c_6.0.0-1_aarch64_cortex-a53.ipk
Installing sentinel-proxy (2.1.0-4) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/sentinel-proxy_2.1.0-4_aarch64_cortex-a53.ipk
Configuring libgpg-error.
Configuring libgcrypt.
Configuring libconfig.
Configuring msgpack-c.
Configuring libzmq-nc.
Configuring libmicrohttpd-ssl.
Configuring liblz4.
Configuring czmq.
Configuring libpaho-mqtt-c.
Configuring logc.
Configuring logc-argp.
Configuring logc-czmq.
Configuring sentinel-eula.
Configuring sentinel-proxy.
Not agreed with EULA.
EULA could be found at /usr/share/sentinel-eula/ and you can
agree with it either in ReForis data collect tab or using
uci config:
uci set sentinel.main.agreed_with_eula_version=1 && uci commit
EULA version may increase in time. See documentation for more details.
Configuring foris-controller-sentinel-module.
Package sentinel-certgen (6.2-3.10-14) installed in root is up to date.
Installing sentinel-dynfw-client (1.4.0-19) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/sentinel-dynfw-client_1.4.0-19_aarch64_cortex-a53.ipk
Installing python3-zmq (22.3.0-3.10-3) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/python3-zmq_22.3.0-3.10-3_aarch64_cortex-a53.ipk
Installing python3-msgpack (1.0.2-3.10-1) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/packages/python3-msgpack_1.0.2-3.10-1_aarch64_cortex-a53.ipk
Installing libipset (7.15-2) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/base/libipset_7.15-2_aarch64_cortex-a53.ipk
Installing ipset (7.15-2) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/base/ipset_7.15-2_aarch64_cortex-a53.ipk
Installing sentinel-dynfw-cert (0.1.3-23) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/sentinel-dynfw-cert_0.1.3-23_aarch64_cortex-a53.ipk
Installing sentinel-firewall-iptables (0.1.3-23) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/sentinel-firewall-iptables_0.1.3-23_aarch64_cortex-a53.ipk
Configuring sentinel-firewall-iptables.
* Flushing IPv4 filter table
* Flushing IPv4 nat table
* Flushing IPv4 mangle table
* Flushing IPv6 filter table
* Flushing IPv6 mangle table
* Flushing conntrack table ...
* Populating IPv4 filter table
* Rule 'Allow-DHCP-Renew'
* Rule 'Allow-Ping'
* Rule 'Allow-IGMP'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 nat table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv6 filter table
* Rule 'Allow-DHCPv6'
* Rule 'Allow-MLD'
* Rule 'Allow-ICMPv6-Input'
* Rule 'Allow-ICMPv6-Forward'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Rule #11
* Rule #12
* Rule #13
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv6 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Set tcp_ecn to off
* Set tcp_syncookies to on
* Set tcp_window_scaling to on
* Running script '/etc/firewall.user'
* Clearing IPv4 filter table
* Clearing IPv4 nat table
* Clearing IPv4 mangle table
* Populating IPv4 filter table
* Rule 'Allow-DHCP-Renew'
* Rule 'Allow-Ping'
* Rule 'Allow-IGMP'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 nat table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Clearing IPv6 filter table
* Clearing IPv6 mangle table
* Populating IPv6 filter table
* Rule 'Allow-DHCPv6'
* Rule 'Allow-MLD'
* Rule 'Allow-ICMPv6-Input'
* Rule 'Allow-ICMPv6-Forward'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Rule #11
* Rule #12
* Rule #13
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv6 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Set tcp_ecn to off
* Set tcp_syncookies to on
* Set tcp_window_scaling to on
* Running script '/usr/libexec/sentinel/firewall.sh'
iptables v1.8.7 (legacy): can't initialize iptables table `raw': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `nat': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `raw': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
Configuring sentinel-dynfw-cert.
Configuring python3-zmq.
Configuring libipset.
Configuring ipset.
Configuring python3-msgpack.
Configuring sentinel-dynfw-client.
Warning: Option @zone[1].sentinel_dynfw is unknown
* Clearing IPv4 filter table
* Clearing IPv4 nat table
* Clearing IPv4 mangle table
* Populating IPv4 filter table
* Rule 'Allow-DHCP-Renew'
* Rule 'Allow-Ping'
* Rule 'Allow-IGMP'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 nat table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Clearing IPv6 filter table
* Clearing IPv6 mangle table
* Populating IPv6 filter table
* Rule 'Allow-DHCPv6'
* Rule 'Allow-MLD'
* Rule 'Allow-ICMPv6-Input'
* Rule 'Allow-ICMPv6-Forward'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Rule #11
* Rule #12
* Rule #13
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv6 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Set tcp_ecn to off
* Set tcp_syncookies to on
* Set tcp_window_scaling to on
* Running script '/usr/libexec/sentinel/firewall.sh'
iptables v1.8.7 (legacy): can't initialize iptables table `raw': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `nat': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `raw': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
* Dynamic blocking on zone 'wan'
- input
- forward
Package sentinel-eula (1.1.1-1) installed in root is up to date.
Package sentinel-firewall-iptables (0.1.3-23) installed in root is up to date.
Installing sentinel-fwlogs (0.3.0-6) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/sentinel-fwlogs_0.3.0-6_aarch64_cortex-a53.ipk
Installing kmod-nfnetlink-log (5.15.148-1-fabd4c287b8e9da7a34d0dfcf85f6a24) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/core/kmod-nfnetlink-log_5.15.148-1-fabd4c287b8e9da7a34d0dfcf85f6a24_aarch64_cortex-a53.ipk
Installing libnetfilter-log (1.0.2-1) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/packages/libnetfilter-log_1.0.2-1_aarch64_cortex-a53.ipk
Installing kmod-ipt-nflog (5.15.148-1-fabd4c287b8e9da7a34d0dfcf85f6a24) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/core/kmod-ipt-nflog_5.15.148-1-fabd4c287b8e9da7a34d0dfcf85f6a24_aarch64_cortex-a53.ipk
Installing iptables-mod-nflog (1.8.7-7) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/core/iptables-mod-nflog_1.8.7-7_aarch64_cortex-a53.ipk
Configuring kmod-nfnetlink-log.
Configuring kmod-ipt-nflog.
Configuring libnetfilter-log.
Configuring iptables-mod-nflog.
Configuring sentinel-fwlogs.
Warning: Option @zone[1].sentinel_dynfw is unknown
Warning: Option @zone[1].sentinel_fwlogs is unknown
* Clearing IPv4 filter table
* Clearing IPv4 nat table
* Clearing IPv4 mangle table
* Populating IPv4 filter table
* Rule 'Allow-DHCP-Renew'
* Rule 'Allow-Ping'
* Rule 'Allow-IGMP'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 nat table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Clearing IPv6 filter table
* Clearing IPv6 mangle table
* Populating IPv6 filter table
* Rule 'Allow-DHCPv6'
* Rule 'Allow-MLD'
* Rule 'Allow-ICMPv6-Input'
* Rule 'Allow-ICMPv6-Forward'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Rule #11
* Rule #12
* Rule #13
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv6 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Set tcp_ecn to off
* Set tcp_syncookies to on
* Set tcp_window_scaling to on
* Running script '/usr/libexec/sentinel/firewall.sh'
iptables v1.8.7 (legacy): can't initialize iptables table `raw': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `nat': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `raw': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
* Dynamic blocking on zone 'wan'
- input
- forward
Not agreed with EULA.
EULA could be found at /usr/share/sentinel-eula/ and you can
agree with it either in ReForis data collect tab or using
uci config:
uci set sentinel.main.agreed_with_eula_version=1 && uci commit
EULA version may increase in time. See documentation for more details.
Installing sentinel-minipot (2.3.0-5) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/sentinel-minipot_2.3.0-5_aarch64_cortex-a53.ipk
Installing logc-libevent (0.1.0-2) to root...
Downloading https://repo.turris.cz/hbs/mox/packages/turrispackages/logc-libevent_0.1.0-2_aarch64_cortex-a53.ipk
Configuring logc-libevent.
Configuring sentinel-minipot.
Warning: Option @zone[1].sentinel_dynfw is unknown
Warning: Option @zone[1].sentinel_fwlogs is unknown
Warning: Option @zone[1].sentinel_minipot is unknown
* Clearing IPv4 filter table
* Clearing IPv4 nat table
* Clearing IPv4 mangle table
* Populating IPv4 filter table
* Rule 'Allow-DHCP-Renew'
* Rule 'Allow-Ping'
* Rule 'Allow-IGMP'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 nat table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Clearing IPv6 filter table
* Clearing IPv6 mangle table
* Populating IPv6 filter table
* Rule 'Allow-DHCPv6'
* Rule 'Allow-MLD'
* Rule 'Allow-ICMPv6-Input'
* Rule 'Allow-ICMPv6-Forward'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Rule #11
* Rule #12
* Rule #13
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv6 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Set tcp_ecn to off
* Set tcp_syncookies to on
* Set tcp_window_scaling to on
* Running script '/usr/libexec/sentinel/firewall.sh'
iptables v1.8.7 (legacy): can't initialize iptables table `raw': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `nat': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `raw': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
* Dynamic blocking on zone 'wan'
- input
- forward
Not agreed with EULA.
EULA could be found at /usr/share/sentinel-eula/ and you can
agree with it either in ReForis data collect tab or using
uci config:
uci set sentinel.main.agreed_with_eula_version=1 && uci commit
EULA version may increase in time. See documentation for more details.
Package sentinel-proxy (2.1.0-4) installed in root is up to date.
root@turris:~# uci set sentinel.main.agreed_with_eula_
version=1 && uci commit
root@turris:~# sentinel-reload
Warning: Option @zone[1].sentinel_dynfw is unknown
Warning: Option @zone[1].sentinel_fwlogs is unknown
Warning: Option @zone[1].sentinel_minipot is unknown
* Clearing IPv4 filter table
* Clearing IPv4 nat table
* Clearing IPv4 mangle table
* Populating IPv4 filter table
* Rule 'Allow-DHCP-Renew'
* Rule 'Allow-Ping'
* Rule 'Allow-IGMP'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 nat table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Clearing IPv6 filter table
* Clearing IPv6 mangle table
* Populating IPv6 filter table
* Rule 'Allow-DHCPv6'
* Rule 'Allow-MLD'
* Rule 'Allow-ICMPv6-Input'
* Rule 'Allow-ICMPv6-Forward'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Rule #11
* Rule #12
* Rule #13
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv6 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Set tcp_ecn to off
* Set tcp_syncookies to on
* Set tcp_window_scaling to on
* Running script '/usr/libexec/sentinel/firewall.sh'
iptables v1.8.7 (legacy): can't initialize iptables table `raw': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `nat': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `raw': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
* Dynamic blocking on zone 'wan'
- input
- forward
* Logging of zone 'wan'
- DROP
- REJECT
* Minipot FTP on zone 'wan' (21 -> 2133)
* Minipot HTTP on zone 'wan' (80 -> 8033)
* Minipot SMTP on zone 'wan' (25 -> 5873)
* Minipot SMTP submission on zone 'wan' (587 -> 5873)
* Minipot Telnet on zone 'wan' (23 -> 2333)
New device token created
Warning: Option @zone[1].sentinel_dynfw is unknown
Warning: Option @zone[1].sentinel_fwlogs is unknown
Warning: Option @zone[1].sentinel_minipot is unknown
* Clearing IPv4 filter table
* Clearing IPv4 nat table
* Clearing IPv4 mangle table
* Populating IPv4 filter table
* Rule 'Allow-DHCP-Renew'
* Rule 'Allow-Ping'
* Rule 'Allow-IGMP'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 nat table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv4 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Clearing IPv6 filter table
* Clearing IPv6 mangle table
* Populating IPv6 filter table
* Rule 'Allow-DHCPv6'
* Rule 'Allow-MLD'
* Rule 'Allow-ICMPv6-Input'
* Rule 'Allow-ICMPv6-Forward'
* Rule 'Allow-IPSec-ESP'
* Rule 'Allow-ISAKMP'
* Rule 'guest dns rule'
* Rule 'guest dhcp rule'
* Rule #11
* Rule #12
* Rule #13
* Forward 'lan' -> 'wan'
* Forward 'tr_guest' -> 'wan'
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Populating IPv6 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'tr_guest'
* Set tcp_ecn to off
* Set tcp_syncookies to on
* Set tcp_window_scaling to on
* Running script '/usr/libexec/sentinel/firewall.sh'
iptables v1.8.7 (legacy): can't initialize iptables table `raw': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `nat': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.8.7 (legacy): can't initialize ip6tables table `raw': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
* Dynamic blocking on zone 'wan'
- input
- forward
* Logging of zone 'wan'
- DROP
- REJECT
* Minipot FTP on zone 'wan' (21 -> 2133)
* Minipot HTTP on zone 'wan' (80 -> 8033)
* Minipot SMTP on zone 'wan' (25 -> 5873)
* Minipot SMTP submission on zone 'wan' (587 -> 5873)
* Minipot Telnet on zone 'wan' (23 -> 2333)