Version-Release number of selected component (if applicable): firewalld-0.2.6-1.fc18.noarch firewalld-0.2.7-1.fc18.noarch Steps to Reproduce: 1. firewall-cmd --set-default-zone=block Actual results: Error: COMMAND_FAILED: '/sbin/iptables -A PREROUTING_ZONES -t mangle -i em1 -j REJECT --reject-with icmp-host-prohibited' failed: iptables: Invalid argument. Run `dmesg' for more information. dmesg shows: x_tables: ip_tables: REJECT target: only valid in filter table, not mangle Neither iptables(8) nor Google tell me why REJECT target isn't valid but for example DROP seems to be valid.
Fixed in GIT: http://git.fedorahosted.org/cgit/firewalld.git/commit/?id=70a50157c49e65e049818f25b10d0a2500437847