| Summary: | drakfirewall6 interferes with ipv6 usage by configuring shorewall6 to block all icmpv6 packets | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Dave Hodgins <davidwhodgins> |
| Component: | RPM Packages | Assignee: | Mageia tools maintainers <mageiatools> |
| Status: | NEW --- | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | ||
| Version: | 8 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7TOO | ||
| Source RPM: | drakx-net-2.55-1.mga8.src.rpm | CVE: | |
| Status comment: | |||
| Attachments: |
Shorewall6 rules to accept icmpv6 packets
shorewall rules to accpet icmp (ipv4) packets |
||
|
Description
Dave Hodgins
2021-04-16 22:51:14 CEST
Created attachment 12643 [details] Shorewall6 rules to accept icmpv6 packets Based on https://www.iana.org/assignments/icmpv6-parameters/icmpv6-parameters.xhtml I've put together the attached rules for shorewall6 to accept icmpv6 traffic. Created attachment 12644 [details] shorewall rules to accpet icmp (ipv4) packets While less critical for ipv4, here are the rules for icmp packets based on https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml For both lists, unassigned, deprecated, reserved, and experimental packet types have been excluded.
Dave Hodgins
2021-04-16 23:42:29 CEST
Whiteboard:
(none) =>
MGA7TOO This reminds me of the complaint in the recent Distrowatch review about how shorewall in Mageia handles IPv4 and IPv6 separately. Maybe it's time to rebase our firewall support on firewalld like RedHat/SUSE have done, and which now handle both protocols consistently. |