Bug 917866 - RFE: add DHCPv4 and DHCPv6 server services
Summary: RFE: add DHCPv4 and DHCPv6 server services
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: firewalld
Version: 18
Hardware: x86_64
OS: Linux
unspecified
low
Target Milestone: ---
Assignee: Thomas Woerner
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-03-05 00:27 UTC by Gene Czarcinski
Modified: 2013-08-04 00:09 UTC (History)
2 users (show)

Fixed In Version: firewalld-0.3.4-1.fc19
Clone Of:
Environment:
Last Closed: 2013-08-04 00:09:02 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Gene Czarcinski 2013-03-05 00:27:35 UTC
Description of problem:
I thought I would give firewalld a try as a replacement for some home-brewed iptables and ip6tables rules.  Much to my surprise it looks like it just might do the job.  However, I was also surprised that both DHCPv4 and DHCPv6 server services were not standard definitions.  Yes, it was easy enough to add the ports but with all of the other server services defined I thought that these should be too,

If I had set the internal NIC to be zone trusted instead of internal, it would have worked.

However, I suggest a "server" zone with more thought about just what should be there.

Version-Release number of selected component (if applicable):
Fedora 18, firewalld 0.2.12-2

Comment 1 Jiri Popelka 2013-06-17 15:54:01 UTC
I added a service for DHCPv6 server:
https://git.fedorahosted.org/cgit/firewalld.git/commit/?id=789e5ac40edf0ddcc2014c06bbcffb055e907727

I don't think we need the same for DHCPv4 server because ISC DHCP(v4) makes use of raw sockets which bypass firewall completely, see
https://deepthought.isc.org/article/AA-00378/0/Why-does-DHCP-use-raw-sockets.html

Comment 2 Fedora Update System 2013-07-30 19:13:32 UTC
firewalld-0.3.4-1.fc19 has been submitted as an update for Fedora 19.
https://admin.fedoraproject.org/updates/firewalld-0.3.4-1.fc19

Comment 3 Fedora Update System 2013-08-02 03:48:29 UTC
Package firewalld-0.3.4-1.fc19:
* should fix your issue,
* was pushed to the Fedora 19 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing firewalld-0.3.4-1.fc19'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2013-14046/firewalld-0.3.4-1.fc19
then log in and leave karma (feedback).

Comment 4 Fedora Update System 2013-08-04 00:09:02 UTC
firewalld-0.3.4-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.