On 2017-09-15 16:11, Ilari Stenroth wrote:
> CentOS did fix the iptables bug before the upstream EL distribution in
> their package release iptables-1.4.21-18.0.1.el7. It's mentioned here:
> https://wiki.centos.org/Manuals/ReleaseNotes/CentOS7 Maybe the fixed
> package can be ported to SL7.4?

I reported the initial bug to RH via bugzilla.

The problem is that the CentOS fix does not completely fix the issue - 
however works around one specific case.

The same race condition also applies for iptables rulesets that load 
kernel modules as the rules are inserted.

I don't believe this has been fixed by CentOS, or RH as yet.

This means any non-bog standard firewall could still cause a silent 
failure of firewall rules on boot.

-- 
Steven Haigh

? [log in to unmask]     ? http://www.crc.id.au
? +61 (3) 9001 6090    ? 0412 935 897