| Summary: | No init script provided | ||
|---|---|---|---|
| Product: | [Fedora] Fedora EPEL | Reporter: | Roland Wolters <roland.wolters> |
| Component: | ferm | Assignee: | Pavel Alexeev <pahan> |
| Status: | CLOSED WONTFIX | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | el5 | CC: | pahan, sven |
| Target Milestone: | --- | Keywords: | Reopened |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2012-01-07 05:17:38 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Roland Wolters
2011-12-29 11:24:10 UTC
Hm... Very interesting. And what you suggest?? What init script do you want? Ferm is script, just command-line utility, it is not daemon. May be you want just after apply your rules like: # ferm firewall.ferm save it to system wide: # iptables-save > /etc/sysconfig/iptables-config ? I'll hope it helps. Do not hesitate to reopen this if you had searching something other. Hej Pavel, the idea was to have a script which loads the ferm configuration at boot to make sure that no other process or no other modifcation of iptables screwed up anything - and to make sure that the ferm rules apply even if someone forgot to launch ferm. Debian has such a script: http://packages.debian.org/de/sid/ferm (Check the diff and serach for "init") Maybe that clears what I mean. Again - there is standard RedHat way to store rules. For what we may want create some other? Do you satisfied by mentioned before commands to store that rules? I never had problems storing or applying the rules which are generated by ferm. That can be done by the above mentioned commands, as you stated correctly. The problem I see is that the current ferm package for Fedora or EL does not come along with a bootup script which enforces the current ferm rule set at boot time. That's all. Such a method is given in packages for other distributions like Debian/Ubuntu or Arch Linux. However, if you state that such a method is not needed in Fedora or EL, than feel free to close this bug as wontfix. Additional problem there what it should be systemd unit instead of init script now. So, I have not see any advantage of that. If you think it may be, please ask in ML. P.S. In general, may be have worth speaking about it also with upstream author to include some such possibility into ferm itself. |