Bug 1034494 - Ship default /etc/sysconfig/iptables and ip6tables config files
Summary: Ship default /etc/sysconfig/iptables and ip6tables config files
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: iptables
Version: 20
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Thomas Woerner
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 1031127 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-11-26 00:17 UTC by Adam Tkac
Modified: 2014-01-11 14:25 UTC (History)
4 users (show)

Fixed In Version: iptables-1.4.21-4.fc21
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-01-10 15:55:29 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
Proposed patch (3.56 KB, patch)
2013-11-26 00:20 UTC, Adam Tkac
no flags Details | Diff

Description Adam Tkac 2013-11-26 00:17:55 UTC
Description of problem:
When user wants to use ip{,6}tables & initscripts instead of firewalld, he must always create /etc/sysconfig/iptables and /etc/sysconfig/ip6tables configuration files from scratch. Better will be to ship default set of rules together with iptables-services.

Version-Release number of selected component (if applicable):
iptables-1.4.19.1-1.fc20

How reproducible:
always

Steps to Reproduce:
1. install iptables-services and remove firewalld
2. manually create default ip{,6}tables sysconfig files

Actual results:
Sysconfig files have to be created manually from scratch.

Expected results:
Pre-installed sysconfig files with default "REJECT" policy.

Additional info:
I will attach proposed patch.

Comment 1 Adam Tkac 2013-11-26 00:20:43 UTC
Created attachment 828986 [details]
Proposed patch

The patch adds /etc/sysconfig/iptables and /etc/sysconfig/ip6tables config files which were present on every system in pre-firewalld era.

Comment 2 Jiri Popelka 2014-01-10 13:07:24 UTC
Hi Adam,

in the pre-firewalld era these files were created by anaconda during install (bug #860465, comment #6).
But I tend to agree with you that there should be default configuration for ip[6]tables services. firewalld also has a "default" configuration.

Thomas, do you see any problem with shipping these files ?

Comment 3 Jiri Popelka 2014-01-10 13:11:48 UTC
*** Bug 1031127 has been marked as a duplicate of this bug. ***

Comment 4 Thomas Woerner 2014-01-10 13:45:16 UTC
I am ok with the default rule set so far.

You can still use lokkit to create the default rule set, after installing it: "lokkit --service=ssh"

BTW: Further changes to the default ip*tables services rule set to add or remove services, ports, etc. set will most likely be closed WONTFIX.

Comment 5 Jiri Popelka 2014-01-10 15:55:29 UTC
Added in iptables-1.4.21-4.fc21

Comment 6 Adam Tkac 2014-01-11 14:25:31 UTC
(In reply to Jiri Popelka from comment #5)
> Added in iptables-1.4.21-4.fc21

Great, thank you very much!


Note You need to log in before you can comment on or make changes to this bug.