Bug 30510 - Accept Echo request for IPV6 is ignored in Mageia CCM shorewall6, wrong port defined; FIX GIVEN
Summary: Accept Echo request for IPV6 is ignored in Mageia CCM shorewall6, wrong port ...
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Mageia tools maintainers
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-06-05 10:56 CEST by pat dealt
Modified: 2022-06-08 15:49 CEST (History)
0 users

See Also:
Source RPM: libdrakx-net-2.55-1.mga8
CVE:
Status comment:


Attachments

Description pat dealt 2022-06-05 10:56:35 CEST
Description of problem:

IPv6 relies on ICMP(v6) then  in order to have IPV6 fully operational, 
ICMP should be enabled.

Echo request for IPV6 has to be authorized by firewall.
When I activate, through Mageia CCM, the firewall for IPv6 (shorewall6) and tick
the Echo request (ping"6") "for IPV6", the following rule is added in ip6tables :

ACCEPT	net	fw	icmp	8	-

... and echo request is not authorized because this rule is for IPV4 (shorewall/iptables instead of shorewall6/ip6tables).
Version-Release number of selected component (if applicable):
libdrakx-net-2.55-1.mga8
file : /lib/libDrakX/network/drakfirewall6.pm

How reproducible:

Permanent.

Steps to Reproduce:
1.Select Echo request (ping) in CCM / firewall for IPV6.Save.
2.Try to contact your machine from outside with a ping6.
3.Result 100% failed

Solution :
To achieve the expected result, the following change is needed in /lib/libDrakX/network/drakfirewall6.pm :

replace :
  {
   name => N_("Echo request (ping)"),
   ports => '8/icmp',
   force_default_selection => 0,
  },
by 
  {
   name => N_("Echo request (ping)"),
   ports => '128/icmp',
   force_default_selection => 0,
  },
Comment 1 Lewis Smith 2022-06-08 15:49:04 CEST
Thank you for the detailed and helpful report.

Assigning to mageiatools group.

Summary: Accept Echo request for IPV6 is ignored in Mageia CCM shorewall6 => Accept Echo request for IPV6 is ignored in Mageia CCM shorewall6, wrong port defined; FIX GIVEN
Assignee: bugsquad => mageiatools


Note You need to log in before you can comment on or make changes to this bug.