>>Has ipset been installed into SME8 before?
Perhaps the lack of feedback indicates no?
>>Does installing or using ipset break things?
I put the testing server back together again, for old
time's sake, and ran about 180MB of updates into it.
After running...
# wget http://flexbox.sourceforge.net/centos/5/i386/ipset-4.5-1.el5.i686.rpm
# wget http://flexbox.sourceforge.net/centos/5/i386/kmod-ipset-4.5-1.2.6.18_238.9.1.el5.i686.rpm
# yum localinstall *.rpm
...there were no unresolved dependencies and rebooted.
The test server made it past boot (eg no kernel panic)
through to the console and a test ping back to SME HQ.
Best I could I manage as it's quite old kit.
Did the same with the production server but opted for...
wget http://flexbox.sourceforge.net/centos/5/i386/kmod-ipset-PAE-4.5-1.2.6.18_238.9.1.el5.i686.rpm
...as dmesg on that box shows it starts with 'PAE'.
Nothing seems broken so far but I haven't managed to
get ipset operating properly as it's functionality relies
on the 'set' matching module in iptables... Apparently
our edition of iptables is without the set shared object.
I looked with MC and it really isn't in there so SME8 is
perfectly correct. The flexbox download area does have
its 'own' version of iptables... but it's got an older number.
I've made up some suitable ipsets but, until ipset can
reference the (missing) set module in iptables, cannot
really continue.
Ipset documentation is quite confusing, contains errors
and with difficult-to-read English language. Makes it
hard for me to work out if I'm not doing it right, haven't
interpreted the documentation properly enough or even
whether the MAN is in error. Actually there are errors:-/
I think I could work it all out and sustainably run with it -
if it actually worked... but it doesn't work so that's it.
Disappointing.
With respect to 'The Furture' elsewhere I expect all
things developery are now off to fight their halves of the
imminent Holy SME Wars. Hasn't been the best of days.
Time to file for my pension... Damn, looks like the UK Gov.
just took THAT away. And the rain it raineth... still. Time
for some cocoa - g'night - tomorrow's GOT to be better?
PostEdit: clarified... unclear documentation is that of ipset