[Bug 380696] New: SuSEfirewall2: new variables FW_SERVICES_ACCEPT_RELATED_*
https://bugzilla.novell.com/show_bug.cgi?id=380696 Summary: SuSEfirewall2: new variables FW_SERVICES_ACCEPT_RELATED_* Product: openSUSE 11.0 Version: Alpha 2 Platform: Other OS/Version: Other Status: NEW Severity: Normal Priority: P5 - None Component: Release Notes AssignedTo: coolo@novell.com ReportedBy: lnussel@novell.com QAContact: coolo@novell.com Found By: --- SuSEfirewall2 in 11.0 implements a suble change wrt packets that are considered RELATED by netfilter. To allow finer grained filtering of e.g. samba broadcast packets RELATED packets are no longer accepted unconditionally. The new variables FW_SERVICES_ACCEPT_RELATED_* have been introduced to allow restricting RELATED packets handling to certain networks, protocols and ports. That however means that adding conntrack modules to FW_LOAD_MODULES does no longer automatically result in accepting the packets tagged by those modules. One has to additionally set FW_SERVICES_ACCEPT_RELATED_* to a suitable value. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=380696
User coolo@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=380696#c2
Stephan Kulow
https://bugzilla.novell.com/show_bug.cgi?id=380696
Karl Eichwalder
https://bugzilla.novell.com/show_bug.cgi?id=380696
User ke@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=380696#c3
Karl Eichwalder
https://bugzilla.novell.com/show_bug.cgi?id=380696
User ke@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=380696#c4
Karl Eichwalder
https://bugzilla.novell.com/show_bug.cgi?id=380696
User lnussel@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=380696#c5
--- Comment #5 from Ludwig Nussel
https://bugzilla.novell.com/show_bug.cgi?id=380696
User ke@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=380696#c6
--- Comment #6 from Karl Eichwalder
participants (1)
-
bugzilla_noreply@novell.com