Bug 1417685

Summary: Ports 1025:65535 tcp/udp opened by default
Product: [Fedora] Fedora Reporter: Milan Zink <mzink>
Component: firewalldAssignee: Thomas Woerner <twoerner>
Status: CLOSED CANTFIX QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 25CC: twoerner
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-01-30 16:58:35 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Live ISO Fedora25 install - firewall rules none

Description Milan Zink 2017-01-30 16:26:23 UTC
Created attachment 1245922 [details]
Live ISO Fedora25 install - firewall rules

Description of problem:

Why are these ports opened by default?

[liveuser@localhost-live ~]$ sudo firewall-cmd --list-all
FedoraWorkstation (active)
  target: default
  icmp-block-inversion: no
  interfaces: ens3
  sources: 
  services: dhcpv6-client mdns samba-client ssh
  ports: 1025-65535/udp 1025-65535/tcp


Version-Release number of selected component (if applicable):
Fedora 25, live install session, fresh OS install

How reproducible:
Install Fedora 25 from ISO, run firewall-cmd --list-all

Steps to Reproduce:
1. Boot Fedora 25 from iso image
2. run: firewall-cmd --list-all
3. Install to local drive
4. run: firewall-cmd --list-all

Actual results:
ports: 1025-65535/udp 1025-65535/tcp opened by default

Expected results:
I believe that this ports should not be opened by default.

Additional info:

Comment 1 Thomas Woerner 2017-01-30 16:58:35 UTC
The workstation zone has been requested by the workstation team and any change for this zone needs to be requested there.

Please have a look at:

https://pagure.io/fesco/issue/1372
https://bugzilla.redhat.com/show_bug.cgi?id=1172353