On 2017-09-15 16:11, Ilari Stenroth wrote: > CentOS did fix the iptables bug before the upstream EL distribution in > their package release iptables-1.4.21-18.0.1.el7. It's mentioned here: > https://wiki.centos.org/Manuals/ReleaseNotes/CentOS7 Maybe the fixed > package can be ported to SL7.4? I reported the initial bug to RH via bugzilla. The problem is that the CentOS fix does not completely fix the issue - however works around one specific case. The same race condition also applies for iptables rulesets that load kernel modules as the rules are inserted. I don't believe this has been fixed by CentOS, or RH as yet. This means any non-bog standard firewall could still cause a silent failure of firewall rules on boot. -- Steven Haigh ? [log in to unmask] ? http://www.crc.id.au ? +61 (3) 9001 6090 ? 0412 935 897