add dhcpv6-client to /etc/sysconfig/ip6tables (RHBZ#1169036)

In firewalld it's also allowed by default.
This commit is contained in:
Jiri Popelka 2014-12-01 12:46:00 +01:00
parent 2962b798c0
commit 69f9a1a33c
2 changed files with 5 additions and 1 deletions

View File

@ -7,7 +7,7 @@
Name: iptables Name: iptables
Summary: Tools for managing Linux kernel packet filtering capabilities Summary: Tools for managing Linux kernel packet filtering capabilities
Version: 1.4.21 Version: 1.4.21
Release: 13%{?dist} Release: 14%{?dist}
Source: http://www.netfilter.org/projects/iptables/files/%{name}-%{version}.tar.bz2 Source: http://www.netfilter.org/projects/iptables/files/%{name}-%{version}.tar.bz2
Source1: iptables.init Source1: iptables.init
Source2: iptables-config Source2: iptables-config
@ -221,6 +221,9 @@ done
%changelog %changelog
* Mon Dec 01 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-14
- add dhcpv6-client to /etc/sysconfig/ip6tables (RHBZ#1169036)
* Mon Nov 03 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-13 * Mon Nov 03 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-13
- iptables.init: use /run/lock/subsys/ instead of /var/lock/subsys/ (RHBZ#1159573) - iptables.init: use /run/lock/subsys/ instead of /var/lock/subsys/ (RHBZ#1159573)

View File

@ -9,6 +9,7 @@
-A INPUT -p ipv6-icmp -j ACCEPT -A INPUT -p ipv6-icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT -A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -d fe80::/64 -p udp -m udp --dport 546 -m state --state NEW -j ACCEPT
-A INPUT -j REJECT --reject-with icmp6-adm-prohibited -A INPUT -j REJECT --reject-with icmp6-adm-prohibited
-A FORWARD -j REJECT --reject-with icmp6-adm-prohibited -A FORWARD -j REJECT --reject-with icmp6-adm-prohibited
COMMIT COMMIT