• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Errors when applying firewall rules

AdrianC

Basic Pleskian
When I try to enable firewall rules I get these errors in both 10.0.1 and 10.2.0:


Error: Could not activate firewall configuration:

safeact: safeact: /usr/local/psa/var/modules/firewall/firewall-new.sh failed:
iptables v1.3.5: can't initialize iptables table `nat': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.


proc_close() failed: date_default_timezone_get() [<a href='function.date-default-timezone-get'>function.date-default-timezone-get</a>]: It is not safe to rely on the system's timezone settings. Please use the date.timezone setting, the TZ environment variable or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected 'UTC' for 'GMT/0.0/no DST' instead

The bottom one is different depending on the updates I have installed or plesk version but the iptables thing is usually the same error.

What is the problem?
Is it this issue? http://kb.odin.com/5228
Does it need a kernel update? I have no idea how to do that, I have no "vzup2date utility" as the articles says.

Edit: and that address [email protected] is a bad joke, you will get delivery failure !
 
If you have Plesk installed to Parallels Virtuozzo Container that mentioned KB article is really actual.
vzup2date utility is part of Virtuozzo but not Plesk and should be started on Virtuozzo server but not inside container.
 
Thank you Igor for clarifying, as I expected, this has to be ran by my host, correct ?!
This is their reply :)

I understand that you are getting errors when attempting to add rules to the Plesk firewall.

"safeact: safeact: /usr/local/psa/var/modules/firewall/firewall-new.sh failed: iptables v1.3.5: can't initialize iptables table `nat': Table does not exist (do you need to insmod?) Perhaps iptables or your kernel needs to be upgraded."

Upon review, it appears that Plesk is trying to access modules that we do not support. As you are currently hosted in a virtual environment, we are unable to perform kernel upgrades to resolve the issue. You may consider an alternate firewall solution, modifying your iptables manually, or upgrading to a dedicated server if you require the use of the Plesk firewall specifically. Our dedicated servers also support hardware firewalls which you can add for an additional fee.

Please contact us if you have any further issues.

Regards,
Is like "we thought you do not need a firewall so that is our default setup" and "we will not update anything, buzz off".
 
Yes, unfortunately it is Virtuozzo provider politics. You can only try to avoid using this iptables rules and modify it somehow.
 
Back
Top