From: Dave Taht <dave.taht@gmail.com>
To: "cerowrt-devel@lists.bufferbloat.net"
<cerowrt-devel@lists.bufferbloat.net>,
cerowrt@lists.bufferbloat.net
Subject: [Cerowrt-devel] [Bug #445] doesn't load firewall rules under some circumstances
Date: Wed, 30 Jul 2014 16:46:26 -0400 [thread overview]
Message-ID: <CAA93jw68=YxkG+Rc42c=xoGKjCY=+-S35PWp8-4xdDo6zammXw@mail.gmail.com> (raw)
[-- Attachment #1: Type: text/plain, Size: 1115 bytes --]
I usually kill off the firewall rules for an internal router almost
completely. Recently, I didn't do that, and didn't have the external
interface connected, so a new cerowrt-3.10.50-1 install automagically
meshed with another router over wifi.
...and didn't run the default firewall rules at all.
I first noticed that /etc/firewall.user wasn't run (which is the lousy
place I'm using to export the /24 local network via babel), so I didn't
have connectivity to the next hop mesh... and then I
checked to see there were no iptables rules in place at all. So, some
trigger for running the firewall "fw3 load" doesn't run unless there is an
external ethernet interface up in cerowrt.
And arguably it should run pretty early. So somewhere there is a missing
trigger?? to load the fw...
(and I hope this is a cerowrt specific bug and it did use to work)
... and I'd really rather run this out of /etc/config/network somehow
ip route add unreachable my.subnet.add.ress/24
--
Dave Täht
NSFW:
https://w2.eff.org/Censorship/Internet_censorship_bills/russell_0296_indecent.article
[-- Attachment #2: Type: text/html, Size: 4267 bytes --]
next reply other threads:[~2014-07-30 20:46 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-07-30 20:46 Dave Taht [this message]
2014-07-30 20:52 ` Ranga Krishnan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: https://lists.bufferbloat.net/postorius/lists/cerowrt-devel.lists.bufferbloat.net/
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='CAA93jw68=YxkG+Rc42c=xoGKjCY=+-S35PWp8-4xdDo6zammXw@mail.gmail.com' \
--to=dave.taht@gmail.com \
--cc=cerowrt-devel@lists.bufferbloat.net \
--cc=cerowrt@lists.bufferbloat.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox