Re: [webmin-l] IPTABLES restore under OpenVZ
"Jamie Cameron" <[email protected]>
| Newsgroups | gmane.comp.web.webmin.general |
|---|---|
| Message-ID | <[email protected]> |
On 12/Dec/2016 03:55 Joaquim Homrighausen <[email protected]> wrote .. > > I can't remember if we've talked about this before, sorry if it's a dupe. > > OpenVZ containers running Linux seem to rewrite /etc/network/interfaces > every time it re-boots. > > Wouldn't this indicate that /etc/network/interfaces is a bad place to > put iptables restore actions and that they should go in /etc/rc.local? I > have from time to time found some of our VPS with no active firewall (!) > though Webmin thinks there is one (because I don't click revert) ... if > I simply click "Apply changes" and set the "Start firewall on boot" to > yes, it all works, until it happens again ... > > Or am I dreaming? > > (On a side note, it'd be nice with a show currently active firewall > without having to revert/etc, another idea is to allow Webmin to display > differences between actual and what Webmin thinks) I suppose there's no reason why you couldn't just add an entry to /etc/rc.local to reload the firewall rules. However, Debian does recommend using /etc/network/interfaces. What does OpenVZ rewrite the file for though? Can this be disabled? ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot - Forwarded by the Webmin mailing list at [email protected] To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list