-
Notifications
You must be signed in to change notification settings - Fork 883
Fedora firewall rules caveat and DNS #2206
Comments
On distributions using FirewallD like Fedora, we need to register the new IP to FirewallD. Related to: rkt/rkt#2206
Thanks for the commands! I am using |
On distributions using FirewallD like Fedora, we need to register the new IP to FirewallD. Related to: rkt/rkt#2206
On distributions using FirewallD like Fedora, we need to register the new IP to FirewallD. Related to: rkt/rkt#2206
On distributions using FirewallD like Fedora, we need to register the new IP to FirewallD. Related to: rkt/rkt#2206
On distributions using FirewallD like Fedora, we need to register the new IP to FirewallD. Related to: rkt/rkt#2206
On distributions using FirewallD like Fedora, we need to register the new IP to FirewallD. See https://fedoraproject.org/wiki/FirewallD Related to: rkt/rkt#2206
On distributions using FirewallD like Fedora, we need to register the new IP to FirewallD. Supported plugins: ptp, bridge. See https://fedoraproject.org/wiki/FirewallD Related to: rkt/rkt#2206
On distributions using FirewallD like Fedora, we need to register the new IP to FirewallD. Supported plugins: ptp, bridge. See https://fedoraproject.org/wiki/FirewallD Related to: rkt/rkt#2206
Pending on the CNI PR. Moving to next milestone. |
still waiting on CNI? |
@jonboulle yes. @steveej added a comment but I didn't have time to follow up. |
Removing from specific milestone until firewall issues are followed up in CNI. |
@rhatdan Is there anyone from the Fedora or RH community who would want to figure out how to integrate rkt and CNI with firewalld? |
@philips there is a PR already (containernetworking/cni#138) but @steveej wanted to refactor it as a CNI plugin. |
Best to open a bugzilla on rkt and then we can point the firewalld team at it. But this pull request looks like someone has been looking at it. |
Do we have any update on this issue? |
Is the situation still the same? If so, would be great to update the docs to refer to current Fedora releases - 26 and 27. The docs refer to Fedora 24 and 25 which are EOL. |
Yes, I believe this is still the case. |
The distributions doc metions that Fedora's firewall rules block traffic and recommend flushing the IP tables.
That works, but maybe that recommendation can be less destructive? Better to trust each
rkt
net?Maybe this is something CNI should address or does address?
Original Problem (for people Googling): Some minimal examples with alpine or busybox resolve DNS queries properly when run on a Debian/Ubuntu host, but fail on a Fedora host.
Ping-able, but not DNS query-able.
Versions:
The text was updated successfully, but these errors were encountered: