Red Hat Bugzilla – Bug 1422149
The RH-Satellite-6 firewall service file is missing ports
Last modified: 2018-04-10 06:31:38 EDT
Description of problem: There is already /usr/lib/firewalld/services/RH-Satellite-6.xml However, it is missing: --add-port="53/udp" --add-port="53/tcp" --add-port="67/udp" --add-port="68/udp" --add-port="69/udp" Version-Release number of selected component (if applicable): 6.2.6 How reproducible: 100% Steps to Reproduce: 1. Install Satellite 2. Look at the ports defined in the service file. 3. Actual results: The ports mentioned above are missing Expected results: All ports needed for Satellite 6 should be in the service file. Additional info:
The service file is not defined by Satellite, but by firewalld itself. https://github.com/t-woerner/firewalld/blob/master/config/services/RH-Satellite-6.xml I'm moving it to RHEL7, component firewalld, as the Satellite team does not own the firewalld releases so I can't really pin it to 6.2.z, 6.3 or anything, it's entirely up to the firewalld team.
granting qa_ack for 7.5; RPL
*** Bug 1328315 has been marked as a duplicate of this bug. ***
5646, 5647, 5000 are listed in Table 2.7. Ports for Capsule to Satellite Communication from https://access.redhat.com/documentation/en-us/red_hat_satellite/6.2/html-single/installation_guide/#ports_prerequisites
So the full list should be (please verify): - 53 TCP,UDP - 67 UDP - 68 UDP - 69 UDP - 5646 TCP - 5647 TCP - 5000 TCP - 8000 TCP
*** Bug 1337531 has been marked as a duplicate of this bug. ***
upstream commit 34b616a67585 ("Add missing ports to RH-Satellite-6 service")
*** Bug 1541442 has been marked as a duplicate of this bug. ***
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2018:0702