Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 19/20 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 22nd August 2008, 05:29 PM
anocelot Offline
Registered User
 
Join Date: Aug 2008
Posts: 1
GUI iptables "apply" differes from boot config - iptables config files load order?

Hi everyone,

Short version:
When I boot my fedora 9 server, "iptables --list" gives me one set of rules. If I login to the command line and run "service iptables restart" the rules still do not work. If I login to the GUI, though, run the firewall application and chose: "Stop, Start, Apply" I get a different set of rules (which work fine!).

More info:
I have some virtual servers that are running on aliased ethernet devices. My iptables script is forwarding requests from three aliases (eth0:0 - eth0:2) to the appropriate virtual machine.

The "new" set of rules I get when I run the gui firewall apply script *DO* give me the results I want, but I *really* don't want to have to login to the gui in order to get the correct rules.

Has anyone run across something similar, and can you offer any suggestions?

TIA!
Reply With Quote
  #2  
Old 22nd August 2008, 06:01 PM
vallimar Offline
Registered User
 
Join Date: Jul 2008
Posts: 1,042
I don't use the iptables "service" or system-config-firewall stuff as I find them lacking, so I could very well be wrong, but it's possible when you are doing a restart, it's just re-loading the saved iptables tables that it writes to a file. Looking through /etc/rc.d/init.d/iptables -- it appears to do just that. However, if you have the IPTABLES_SAVE_ON_STOP config variable set (from /etc/sysconfig/iptables-config), then it will save your current rules on stop (to /etc/sysconfig/iptables), then blank everything and re-load those rules. The default setting for this config variable is "no", meaning when you make rules changes, you have to manually do a "service iptables save" if you want them restored next time. Setting that variable to "yes" will auto-save changes. From what it sounds like, you need to either set that variable, or remember to manually save when tweaking your rules.
Reply With Quote
  #3  
Old 23rd August 2008, 04:56 AM
Evil_Bert Offline
Retired Again - Administrator
 
Join Date: Nov 2007
Location: 'straya
Posts: 3,252
To amplify what vallimar says, the initial iptables script run at boot time is stored in file /etc/sysconfig/iptables (in "iptables-save" format) and an associated set of parameters in /etc/sysconfig/iptables-config.

I'm pretty sure that if you apply (by clicking the Apply button) the rules created in the GUI firewall application (system-config-firewall), those rules are indeed saved to /etc/sysconfig/iptables. I've tested this in F8 - I can't see why it would be different in F9 (it's the same package - based on Lokkit). But, for some unknown reason, the rules are not being saved in your case.

As you probably know, rules can be altered or overwritten at any time using the "iptables" command. Thus, the active rules and saved rules (in /etc/sysconfig/iptables) may not be the same.

Rather than play with the init variables, IMHO, it's better to manually issue the command to save active rules (in iptables-save format) to /etc/sysconfig/iptables:
Code:
service iptables save
or to another file:
Code:
iptables-save > {path}/{filename}
When iptables has been correctly configured in your GUI and rules applied, save using one of the above methods and make a backup copy. (If you replace the originals with the backups, remember to check permissions and SELinux context).

You can verify your saved rules against active rules using:
Code:
iptables -L -n -v
The resulting printout is the active rule set (but it is not in iptables-save format and cannot be used as a script).

You could also use the following (perhaps from within another startup script) to overwrite the current ruleset from a file contaiing your desired rules (in iptables-save format):
Code:
iptables-restore < {path}/{filename}
service iptables restart
Hopefully, this will give you some options to fix the problem.
__________________
Marching to the beat of his own conundrum.

Last edited by Evil_Bert; 23rd August 2008 at 04:58 AM.
Reply With Quote
  #4  
Old 23rd August 2008, 06:06 AM
marcrblevins Offline
Registered User
 
Join Date: Jun 2006
Location: Texas
Age: 43
Posts: 4,168
Damn Bert, make that sticky! Well thought out.
Reply With Quote
Reply

Tags
apply, boot, config, differes, files, gui, iptables, load, order

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Kernel Recompile From SRPM : How to change "new" config files?? Time2IPL Using Fedora 9 22nd February 2008 03:27 AM
Cannot load "system-config-display" Pille456 Using Fedora 0 4th February 2008 01:42 PM
command #service iptables save changed the original config of iptables kesavulur Security and Privacy 0 28th November 2007 06:33 AM
fedorafaq's yum config and "yum update" leads to yum config failure mtk Installation, Upgrades and Live Media 2 9th October 2005 04:34 PM
errors when I try to install "medley-package-config" with "apt-get" I-1 Using Fedora 5 3rd May 2005 11:08 AM


Current GMT-time: 03:40 (Wednesday, 23-07-2014)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat