netfilter.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Is the current firewall model static?
@ 2011-12-20  9:25 Hansa
  2011-12-20 10:11 ` Andrew Beverley
  0 siblings, 1 reply; 6+ messages in thread
From: Hansa @ 2011-12-20  9:25 UTC (permalink / raw)
  To: netfilter

Hi there,

Fedora is running a project called firewalld. Firewalld manages the firewall
dynamically via D-BUS
(http://fedoraproject.org/wiki/FirewallD/#Why_A_Firewall_Daemon). They say:
"the current firewall model is static and **every** change requires a
complete firewall restart. This includes also to unload the firewall
netfilter kernel modules and to load the modules that are needed for the new
configuration."

I would be very surprised if their claim is true. Because that would break
statefull connections when changing the rules. I'm not familiar with the
code so I can't comment on that. Hence my question. Is the current firewall
model static?

Best regards,

-Hansa




^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2011-12-21 10:22 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-12-20  9:25 Is the current firewall model static? Hansa
2011-12-20 10:11 ` Andrew Beverley
2011-12-21  9:18   ` Hansa
2011-12-21  9:27     ` Andrew Beverley
2011-12-21 10:16       ` Hansa
2011-12-21 10:22         ` Andrew Beverley

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).