Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Register
  • Sign in
  • S slapos.package
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 14
    • Merge requests 14
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • nexedinexedi
  • slapos.package
  • Merge requests
  • !22

playbook: do not touch the firewall

  • Review changes

  • Download
  • Patches
  • Plain diff
Closed Julien Muchembled requested to merge no-fw into master Sep 21, 2016
  • Overview 7
  • Commits 1
  • Pipelines 0
  • Changes 2

The cron task that adds a few ipv6 rules at reboot for babeld/re6stnet is a time bomb. If someone has a firewall, updates its conf and restarts it instead of rebooting, the result is likely to be wrong with consequences like:

  • no more access to the machine (if re6stnet was used to access it)
  • machine acting like a blackhole (INPUT rules still there but FORWARD back to DROP)

Someone who sets up a firewall must understand things a minimum and configure it himself for re6stnet. ipv4 rules are anyway required. Maybe that's what happened on server managed by @romain, where there were only 2 tunnels with outside because the openvpn server was firewalled.

@vpelletier had the idea to document in re6stnet how to configure shorewall. We should finish this.

The playbook could also issue a warning in the case that there's a firewall. Maybe you have better ideas about how to draw attention.

@rafael @alain.takoudjou

Assignee
Assign to
Reviewers
Request review from
Time tracking
Source branch: no-fw
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7