On 2017-09-15 16:11, Ilari Stenroth wrote:
> CentOS did fix the iptables bug before the upstream EL distribution in
> their package release iptables-1.4.21-18.0.1.el7. It's mentioned here:
> https://wiki.centos.org/Manuals/ReleaseNotes/CentOS7 Maybe the fixed
> package can be ported to SL7.4?
I reported the initial bug to RH via bugzilla.
The problem is that the CentOS fix does not completely fix the issue -
however works around one specific case.
The same race condition also applies for iptables rulesets that load
kernel modules as the rules are inserted.
I don't believe this has been fixed by CentOS, or RH as yet.
This means any non-bog standard firewall could still cause a silent
failure of firewall rules on boot.
--
Steven Haigh
? [log in to unmask] ? http://www.crc.id.au
? +61 (3) 9001 6090 ? 0412 935 897