Groups | Search | Server Info | Login | Register


Groups > linux.debian.maint.firewall > #124

Re: Firewalld + libvirt rules conflict

Path csiph.com!newsfeed.xs4all.nl!newsfeed9.news.xs4all.nl!bofh.it!news.nic.it!robomod
From Nick <decrofn@gmail.com>
Newsgroups linux.debian.maint.firewall
Subject Re: Firewalld + libvirt rules conflict
Date Wed, 29 Dec 2021 02:20:01 +0100
Message-ID <DzvNf-1vG-1@gated-at.bofh.it> (permalink)
References <Dzpya-654-15@gated-at.bofh.it>
X-Mailbox-Line From debian-firewall-request@lists.debian.org Wed Dec 29 01:10:25 2021
Old-Return-Path <decrofn@gmail.com>
X-Amavis-Spam-Status No, score=-7.2 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, LDO_WHITELIST=-5, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
X-Policyd-Weight using cached result; rate: -5.5
X-Gm-Message-State AOAM533s4fzsjTTvO+HKyyD6O1RHrFu0iJKfXtKsN4rAmqONMC8yGOaB 8HsuL24m1+9MoVFYMxSh6USr+86Lw9Y=
X-Google-SMTP-Source ABdhPJyc4xP7uO9O93VoRHqNFQ0mL9w4ozXtU22qDq/zPtMK09VV824c39623EvAAdg6ejlYYvTHyw==
X-Received by 2002:a17:906:478a:: with SMTP id cw10mr19016769ejc.693.1640740209041; Tue, 28 Dec 2021 17:10:09 -0800 (PST)
User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.14.0
MIME-Version 1.0
Content-Type text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding 7bit
Content-Language en-US
X-Mailing-List <debian-firewall@lists.debian.org> archive/latest/9563
List-ID <debian-firewall.lists.debian.org>
List-URL <https://lists.debian.org/debian-firewall/>
List-Archive https://lists.debian.org/msgid-search/6ce38391-f25d-2d1b-7f69-2550dbfadb28@gmail.com
Approved robomod@news.nic.it
Lines 14
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Wed, 29 Dec 2021 03:10:07 +0200
X-Original-Message-ID <6ce38391-f25d-2d1b-7f69-2550dbfadb28@gmail.com>
X-Original-References <CAH-hTEQ3qe_azcSCAyRv2C+eAuumhKv9JDfqU4LMf3W5V-MZqQ@mail.gmail.com>
Xref csiph.com linux.debian.maint.firewall:124

Show key headers only | View raw


I don't see any difference, hook is not triggered after firewall-cmd 
--reload.


Reading the https://www.libvirt.org/hooks.html#location

/etc/libvirt/hooks/network
Executed when a network is started or stopped or an interface is 
plugged/unplugged to/from the network <-- this doesn't seem to be 
exactly what is needed as no such events occur.

At this point systemctl restart libvirtd will trigger 
/etc/libvirt/hooks/network and insert the desired rules which I think is 
strange because there is /etc/libvirt/hooks/daemon for this.

Back to linux.debian.maint.firewall | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

Firewalld + libvirt rules conflict Nick <decrofn@gmail.com> - 2021-12-28 14:50 +0100
  Re: Firewalld + libvirt rules conflict Benoit Hivert <hivert.benoit@gmail.com> - 2021-12-28 19:40 +0100
    Re: Firewalld + libvirt rules conflict Nick <decrofn@gmail.com> - 2021-12-29 02:20 +0100
    Re: Firewalld + libvirt rules conflict Nick <amp@nforced.net> - 2021-12-29 02:40 +0100

csiph-web