| Summary: | iptables shutdown error when ip6tables running | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 5 | Reporter: | John G. Myers <jgmyers> | ||||||
| Component: | iptables | Assignee: | iptables-maint-list <iptables-maint-list> | ||||||
| Status: | CLOSED NOTABUG | QA Contact: | qe-baseos-daemons | ||||||
| Severity: | low | Docs Contact: | |||||||
| Priority: | unspecified | ||||||||
| Version: | 5.6 | CC: | twoerner | ||||||
| Target Milestone: | rc | ||||||||
| Target Release: | --- | ||||||||
| Hardware: | Unspecified | ||||||||
| OS: | Unspecified | ||||||||
| Whiteboard: | |||||||||
| Fixed In Version: | 6.0 | Doc Type: | Bug Fix | ||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2011-08-18 08:20:11 UTC | Type: | --- | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Attachments: |
|
||||||||
|
Description
John G. Myers
2011-08-11 16:31:44 UTC
Please add the firewall configuration for iptables and ip6tables as a private comment. From files /etc/sysconfig/iptables and /etc/sysconfig/ip6tables or the output of the commands iptables-save and ip6tables-save). Please also add the values of IPTABLES_MODULES and IP6TABLES_MODULES from /etc/sysconfig/iptables-config and /etc/sysconfig/ip6tables-config. Thanks Created attachment 518743 [details]
/etc/sysconfig/iptables
Created attachment 518744 [details]
/etc/sysconfig/ip6tables
Does not reproduce in 6.0. The problem is the use of state in the IPv6 firewall. Connection tracking in the 2.6.18 kernel in EL-5 does not support IPv6. Please have a look at #243739 and #212839 for more information.
You need to replace the state line in the IPv6 firewall by this:
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 32768:61000 ! --syn -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 32768:61000 -j ACCEPT
This is known limitation of the RHEL-5 kernel and can not be changed. The state rule in your IPv6 firewall is not working and all packets are marked INVALID.
Here is an except of the RELEASE_NOTES of EL-5:
o Added nf_conntrack subsystem (2.6.15)
o The existing connection tracking subsystem in netfilter
can only handle ipv4. There were two choices present to
add connection tracking support for ipv6; either
duplicate all of the ipv4 connection tracking code into
an ipv6 counterpart, or (the choice taken by these
patches) design a generic layer that could handle both
ipv4 and ipv6 and thus requiring only one sub-protocol
(TCP, UDP, etc.) connection tracking helper module to be
written. In fact, nf_conntrack is capable of working
with any layer 3 protocol.
I will close this bug as NOT A BUG.
|