Re: [webmin-l] IPTABLES restore under OpenVZ

"Jamie Cameron" <[email protected]>
Newsgroups gmane.comp.web.webmin.general
Message-ID <[email protected]>
On 12/Dec/2016 03:55 Joaquim Homrighausen <[email protected]> wrote ..
> 
> I can't remember if we've talked about this before, sorry if it's a dupe.
> 
> OpenVZ containers running Linux seem to rewrite /etc/network/interfaces 
> every time it re-boots.
> 
> Wouldn't this indicate that /etc/network/interfaces is a bad place to 
> put iptables restore actions and that they should go in /etc/rc.local? I 
> have from time to time found some of our VPS with no active firewall (!) 
> though Webmin thinks there is one (because I don't click revert) ... if 
> I simply click "Apply changes" and set the "Start firewall on boot" to 
> yes, it all works, until it happens again ...
> 
> Or am I dreaming?
> 
> (On a side note, it'd be nice with a show currently active firewall 
> without having to revert/etc, another idea is to allow Webmin to display 
> differences between actual and what Webmin thinks)

I suppose there's no reason why you couldn't just add an entry to /etc/rc.local
to reload the firewall rules. However, Debian does recommend using 
/etc/network/interfaces.

What does OpenVZ rewrite the file for though? Can this be disabled?

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most 
engaging tech sites, SlashDot.org! http://sdm.link/slashdot
-
Forwarded by the Webmin mailing list at [email protected]
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.