SCIENTIFIC-LINUX-USERS Archives

June 2015

SCIENTIFIC-LINUX-USERS@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Charles Lane <[log in to unmask]>
Reply To:
Date:
Tue, 16 Jun 2015 10:48:20 -0400
Content-Type:
text/plain
Parts/Attachments:
text/plain (32 lines)
On Tue, 16 Jun 2015 09:36:19 +0200
David Sommerseth <[log in to unmask]> wrote:

> On 16/06/15 09:12, ToddAndMargo wrote:
> > On 06/15/2015 11:55 PM, David Sommerseth
> [...snip...]
> >>
> >> firewalld isn't replacing iptables, it actually depends on it.
> >> Firewalld is more like a more advanced configuration tool for
> >> iptables.

/usr/lib/systemd/system/firewalld.service:
[Unit]
Description=firewalld - dynamic firewall daemon
Before=network.target
Before=libvirtd.service
Before=NetworkManager.service
Conflicts=iptables.service ip6tables.service ebtables.service

Note the "Conflicts". In my experience, you have to shut down
firewalld if you want to run iptables (and yes, I have
iptables-services installed, running iptables under
systemd on SL7) 

At some point I may convert from iptables to firewalld,
but I'm not quite ready yet. 
-- 
 Drexel University    \V               --Chuck Lane
======]---------->-----*------<--------[===========
     (215) 895-1545   / \_/*~~~~~  Particle Physics
FAX: (215) 895-1281  [log in to unmask]

ATOM RSS1 RSS2