Red Hat Bugzilla – Bug 54703
Dependencies between /etc/sysconfig/network-scripts/ifup-post and /etc/sysconfig/iptables
Last modified: 2014-03-16 22:23:50 EDT
From Bugzilla Helper:
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Description of problem:
The /etc/rc.d/init.d/iptables depends on /etc/sysconfig/network-
scripts/ifup-post to allow dns traffic through the firewall roules. So if
you call the iptables init script without rebooting then the ifup-post
script will not be executed and the dns servers will not be allowed
through the firewall rules. aka DNS won't work.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. /etc/rc.d/init.d/iptables restart
2. Try to resolve any network names
Actual Results: DNS names cannot be resolved and dig says server does not
Expected Results: DNS names should be resolved.
ifup-post doesn't touch iptables at all. That code is there mainly for lokkit
and the like; we assume that custom firewalls would be written to allow DNS.