action #45731

Bug: firewalld is blocking everything until it's restarted

Added by flacco 6 months ago. Updated 5 months ago.

Status:In ProgressStart date:04/01/2019
Priority:UrgentDue date:28/02/2019
Assignee:ingogoeppert% Done:

80%

Category:-
Target version:14.1
Duration: 40

Description

After a reboot of an invis server the new firwalld daemon is blocking everything until it is restarted.

History

#1 Updated by flacco 6 months ago

  • Related to action #36079: Modify sine2 / invisAD-setup to be compatible with leap 15 added

#2 Updated by flacco 6 months ago

  • Status changed from New to In Progress
  • % Done changed from 0 to 80

It seems that firewalld starts to early. The original service-unit file defines to start firewalld before "network-pre.target":

"[Unit]
Description=firewalld - dynamic firewall daemon
Before=network-pre.target
Wants=network-pre.target
After=dbus.service
After=polkit.service
..."

Starting firewalld later brings the risk that the system runs for a few moments without the firewall. Sytemd knows three different network targets. "network-pre.target", "network.target" and "network-online.target". The last one means that all network interfaces are up and online. Starting the firewall before this target should be secure enough.

Changing the firewalld service-unit file to:

"[Unit]
Description=firewalld - dynamic firewall daemon
After=network-pre.target
Before=network-online.target
After=dbus.service
After=polkit.service
..."

did the job. This should be secure enough.

#3 Updated by flacco 6 months ago

... but I don't know if we should place a "Wants=network.online.target" in the service-unit file?

#4 Updated by ingogoeppert 6 months ago

firewalld does not start to early. It works on my system. I am unable to reproduce this issue.

#5 Updated by flacco 6 months ago

  • Target version changed from 14.0 to Future

#6 Updated by flacco 6 months ago

  • Related to deleted (action #36079: Modify sine2 / invisAD-setup to be compatible with leap 15)

#7 Updated by flacco 6 months ago

  • Target version changed from Future to 14.1

#8 Updated by flacco 5 months ago

  • Due date changed from 11/01/2019 to 28/02/2019

Also available in: Atom PDF