1

Temat: BanIP na OPENWRT 19.07

HI.

NETGEAR WNDR4300
OpenWrt 19.07-SNAPSHOT r11430-ecbbb373ed / LuCI openwrt-19.07 branch git-22.099.58928-786ebc

Nie chcę (z różnych względów) przechodzić na nowszą wersję OpenWRT. Potrzebuję jednak zainstalować banip. Próba nie powiodła się. Chcę zainstalować zarówno banip jak i uci-app-banip. Bardzo proszę o pomoc. Poniżej log:

root@Netgear:~# opkg update

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_core
Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_base
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_freifunk
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_luci
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_packages
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_routing
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_telephony
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_kmods
Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ckages.sig
Signature check passed.
Collected errors:
* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

root@Netgear:~# opkg install banip

Unknown package 'banip'.
Collected errors:
* opkg_install_cmd: Cannot install package banip.

2

Odp: BanIP na OPENWRT 19.07

Zmień repo openwrt na http://downloads.openwrt.org/releases/19.07.10

To co masz wpisane już dawno nie istnieje.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

3

Odp: BanIP na OPENWRT 19.07

HI. Dziękuję za info. W którym miejscu zmienić repo. Oczywiście nie ma problemu abym dostał się po SSH lub z LUCI. Ale mjak dotąd nigdy (a korzystam z OPENWRT od wielu lat) nie zmieniałem repo. 

DuDuS

4

Odp: BanIP na OPENWRT 19.07

/etc/opkg/distfeeds.conf

Każde 19.07-SNAPSHOT zmień na 19.07.10, dotyczy repo openwrt. Moje mają zostać tak jak są, ja nadal mam je w niezmienionej formie.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

5

Odp: BanIP na OPENWRT 19.07

Zmienione:

# src/gz openwrt_core http://downloads.openwrt.org/releases/1 … d/packages
src/gz openwrt_base http://downloads.openwrt.org/releases/1 … _24kc/base
src/gz openwrt_freifunk http://downloads.openwrt.org/releases/1 … c/freifunk
src/gz openwrt_luci http://downloads.openwrt.org/releases/1 … _24kc/luci
src/gz openwrt_packages http://downloads.openwrt.org/releases/1 … c/packages
src/gz openwrt_routing http://downloads.openwrt.org/releases/1 … kc/routing
src/gz openwrt_telephony http://downloads.openwrt.org/releases/1 … /telephony
src/gz eko1_core http://dl.eko.one.pl/openwrt-19.07/targ … d/packages
src/gz eko1_base http://dl.eko.one.pl/openwrt-19.07/pack … _24kc/base
src/gz eko1_freifunk http://dl.eko.one.pl/openwrt-19.07/pack … c/freifunk
src/gz eko1_luci http://dl.eko.one.pl/openwrt-19.07/pack … _24kc/luci
src/gz eko1_packages http://dl.eko.one.pl/openwrt-19.07/pack … c/packages
src/gz eko1_routing http://dl.eko.one.pl/openwrt-19.07/pack … kc/routing
src/gz eko1_telephony http://dl.eko.one.pl/openwrt-19.07/pack … /telephony
src/gz eko1_kmods http://dl.eko.one.pl/openwrt-19.07/targ … s-4.14.275

root@Netgear:~# opkg update
Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://downloads.openwrt.org/releases/1 … ackages.gz
*** Failed to download the package list from http://downloads.openwrt.org/releases/1 … ackages.gz

Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_core
Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_base
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_freifunk
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_luci
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_packages
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_routing
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_telephony
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_kmods
Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ckages.sig
Signature check passed.
Collected errors:
* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download http://downloads.openwrt.org/releases/1 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

root@Netgear:~# opkg install banip
Unknown package 'banip'.
Collected errors:
* opkg_install_cmd: Cannot install package banip.
root@Netgear:~#

6

Odp: BanIP na OPENWRT 19.07

To zmień jeszcze http://downloads.openwrt.org na http://archive.openwrt.org , ew zmień na https jak masz zainstalowaną bibliotekę kryptograficzną.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

7

Odp: BanIP na OPENWRT 19.07

Ani jedno, ani drugie nie pomogło:

Downloading http://archive.openwrt.org/releases/19. … ackages.gz
*** Failed to download the package list from http://archive.openwrt.org/releases/19. … ackages.gz

Downloading https://archive.openwrt.org/releases/19 … ackages.gz
*** Failed to download the package list from https://archive.openwrt.org/releases/19 … ackages.gz

8

Odp: BanIP na OPENWRT 19.07

Chociaż linki są ewidentnie prawidłowe!!!

9

Odp: BanIP na OPENWRT 19.07

Zmień jeszcze na https. Tylko musisz mieć zainstalowane np. libustream-wolftls czy inne libustream*

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

10

Odp: BanIP na OPENWRT 19.07

Tylko czy zainstalowanie libustream-wolftls nie pokrzaczy mi czegoś w systemie?

11

Odp: BanIP na OPENWRT 19.07

Upewnij się że innej już nie masz, bo tylko jedna wersja może być w systemie. Nie. spowoduje za to ze z linków https będziesz mógł ściągać.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

12

Odp: BanIP na OPENWRT 19.07

root@Netgear:~# opkg list libustream*
libustream-openssl20150806 - 2020-03-13-40b563b1-1 - ustream SSL Library (openssl)

13

Odp: BanIP na OPENWRT 19.07

Ehhh...

opkg list-installed | grep libustream

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

14

Odp: BanIP na OPENWRT 19.07

Mam zainstalowane od początku:

libustream-openssl20150806

15

Odp: BanIP na OPENWRT 19.07

root@Netgear:~# opkg list-installed | grep libustream
libustream-openssl20150806 - 2020-03-13-40b563b1-1

16

Odp: BanIP na OPENWRT 19.07

Ok, zamieniaj na https.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

17

Odp: BanIP na OPENWRT 19.07

root@Netgear:~# ping archive.openwrt.org
PING archive.openwrt.org (81.0.124.218): 56 data bytes
64 bytes from 81.0.124.218: seq=0 ttl=52 time=39.699 ms

18

Odp: BanIP na OPENWRT 19.07

Zmieniłem na https. Nic się mnie zmieniło. Pisałem już wcześniej:

root@Netgear:~# opkg update
Downloading https://archive.openwrt.org/releases/19 … ackages.gz
*** Failed to download the package list from https://archive.openwrt.org/releases/19 … ackages.gz

Downloading https://archive.openwrt.org/releases/19 … ackages.gz
*** Failed to download the package list from https://archive.openwrt.org/releases/19 … ackages.gz

Downloading https://archive.openwrt.org/releases/19 … ackages.gz
*** Failed to download the package list from https://archive.openwrt.org/releases/19 … ackages.gz

Downloading https://archive.openwrt.org/releases/19 … ackages.gz
*** Failed to download the package list from https://archive.openwrt.org/releases/19 … ackages.gz

Downloading https://archive.openwrt.org/releases/19 … ackages.gz
*** Failed to download the package list from https://archive.openwrt.org/releases/19 … ackages.gz

Downloading https://archive.openwrt.org/releases/19 … ackages.gz
*** Failed to download the package list from https://archive.openwrt.org/releases/19 … ackages.gz

Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_core
Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_base
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_freifunk
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_luci
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_packages
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_routing
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_telephony
Downloading http://dl.eko.one.pl/openwrt-19.07/pack … ckages.sig
Signature check passed.
Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ackages.gz
Updated list of available packages in /var/opkg-lists/eko1_kmods
Downloading http://dl.eko.one.pl/openwrt-19.07/targ … ckages.sig
Signature check passed.
Collected errors:
* opkg_download: Failed to download https://archive.openwrt.org/releases/19 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download https://archive.openwrt.org/releases/19 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download https://archive.openwrt.org/releases/19 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download https://archive.openwrt.org/releases/19 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download https://archive.openwrt.org/releases/19 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

* opkg_download: Failed to download https://archive.openwrt.org/releases/19 … ckages.gz, wget returned 4.
* opkg_download: Check your network settings and connectivity.

19

Odp: BanIP na OPENWRT 19.07

No to https://openwrt.org/faq/failed_to_downl … returned_4

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

20

Odp: BanIP na OPENWRT 19.07

Już wiem w czym problem. Ale jak zmusić opkg update do korzystania ip4 a nie ip6. najwyraźniej próbuje z ip6 które mam wyłączone.

21

Odp: BanIP na OPENWRT 19.07

OK

Trzeba było zatrzymać interface WAN6. I "gra gitara".

Dzięki za pomoc Cezary :-)

22

Odp: BanIP na OPENWRT 19.07

Cezary. Podpowiedz jeszcze tylko jedno.

Którą opcją i jak włączyć monitorowanie prób logowania do Luci czy SSH i blokowanie danego IP po określonej liczbie prób! Mnie banip jest tylko do tego potrzebne aktualnie

DuDuS

23

Odp: BanIP na OPENWRT 19.07

Banip robi to odpowiednimi regułkami (firewalla) więc możesz sobie rozwalić banip i wydobyć tylko to co potrzebujesz.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

24 (edytowany przez woma1 2024-08-05 21:20:10)

Odp: BanIP na OPENWRT 19.07

OK

Pobawiłem się już trochę, i wiem że do tego służą parametry:

ban_autoblocklist
ban_nftexpiry
ban_logcount

No i od razu sobie zablokowałem dostęp z WAN. Albowiem wygląda na to, że IP zostaje dodany do  blacklist po liczbie dostępów określonej w ban_logcount, bez względu na to czy logowanie się powiodło czy nie! Pom prostu banip zlicza dostępy danego IP.

Mnie chodzi o to, aby IP został dodany do blacklist wyłącznie po x próbach nieudanego logowania via Luci czy SSH. I nic więcej! Jak ustawić parametry aby uzyskać oczekiwany rezultat.

I jeszcze jedno. Czemu służy opcja "Monitor SSH/LuCI RT"

DuDuS

25

Odp: BanIP na OPENWRT 19.07

On szuka wg ustawionego w configu ban_logterm. Dodaj sobie tam odpowiednie wyrażenie regularne które wg ciebie odpowiada za błędne logowanie i będziesz miał to co trzeba.

Gdzie masz Monitor SSH/LuCI RT  ?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.