[Bug 884398] New: libvirt-created iptables rules lost on DHCP lease renewal
https://bugzilla.novell.com/show_bug.cgi?id=884398 https://bugzilla.novell.com/show_bug.cgi?id=884398#c0 Summary: libvirt-created iptables rules lost on DHCP lease renewal Classification: openSUSE Product: openSUSE 13.1 Version: Final Platform: Other OS/Version: Other Status: NEW Severity: Normal Priority: P5 - None Component: Network AssignedTo: lnussel@suse.com ReportedBy: vuntz@suse.com QAContact: qa-bugs@suse.de CC: mt@suse.com Found By: --- Blocker: --- libvirt is adding some rules to the firewall for the networks configured for the VMs (to allow some NAT). However, when using dhcpcd (ie, default network configuration on a workstation), every time the lease is renewed, /etc/sysconfig/network/if-up.d/SuSEfirewall2 is run and is resetting the firewall rules to what is configured, which doesn't include the libvirt rules. That means that the libvirt rules are lost every now and then. A similar issue was debugged in bug 573246 and the fix was http://bugzillafiles.novell.org/attachment.cgi?id=378796. Is this fix acceptable for SuSEfirewall too? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=884398 https://bugzilla.novell.com/show_bug.cgi?id=884398#c1 Ludwig Nussel <lnussel@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |lnussel@suse.com AssignedTo|lnussel@suse.com |meissner@suse.com --- Comment #1 from Ludwig Nussel <lnussel@suse.com> 2014-06-26 08:28:40 CEST --- Don't modify firewall rules behind SuSEfirewall's back. Either SuSEfirewall2 needs to be adjusted to be able to create the rules for this use case itself or some hook mechanism is needed. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=884398 Liang Yan <lyan@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |lyan@suse.com -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com