Bug 842321 - nat requires manual adjustment
nat requires manual adjustment
Product: Fedora
Classification: Fedora
Component: firewalld (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: ---
: ---
Assigned To: Thomas Woerner
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2012-07-23 09:27 EDT by Serge Pavlovsky
Modified: 2013-02-15 07:16 EST (History)
2 users (show)

See Also:
Fixed In Version: firewalld-0.2.6-1.fc18
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2013-02-15 07:16:55 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Serge Pavlovsky 2012-07-23 09:27:31 EDT
Description of problem:

when i add interface to external zone, firewalld does not create rules jumping from POSTROUTING_ZONES to POST_ZONE_external in nat table. in sources i can only see handling of INPUT and FORWARD in filter table, but no POSTROUTING in nat table. it actually applies to all zones, not just to external, but i only need postrouting in external atm.
so i have to manually add rules like
-A POSTROUTING_ZONES -o eth1 -j POST_ZONE_external
-A POSTROUTING_ZONES -o ppp0 -j POST_ZONE_external
and i guess they will be lost after reboot

Version-Release number of selected component (if applicable):

How reproducible:
add interface to external zone
sudo iptable-save | grep _ZONES
Actual results:
see jump from POSTROUTING to POSTROUTING_ZONES, but no jump from POSTROUTING_ZONES to POST_ZONE_external
on the other hand FORWARD and INPUT have jumps both to *_ZONES and from *_ZONES

Expected results:
jumps from POSTROUTING_ZONES like with INPUT and FORWARD
Comment 1 Serge Pavlovsky 2012-07-23 10:05:02 EDT
Comment 3 Serge Pavlovsky 2012-07-25 06:15:36 EDT
i see
for some reason i need to add -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu to forward chain in mangle table
so, while you're at it, it would be nice to also add forward to mangle
and may be even shortcut parameter for this rule like for masquerade
Comment 4 Jiri Popelka 2013-02-15 07:16:55 EST
Fedora-18 has had this fixed since firewalld-0.2.6-1.fc18.
This will most likely not be fixed in Fedora-17.

Note You need to log in before you can comment on or make changes to this bug.