Your message dated Sun, 30 Dec 2007 00:12:46 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#336611: Shorewall disables IPv6 on boot.
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: shorewall
Version: 2.2.3-2
Severity: important

Shorewall doesn't seem to disable IPv6 during bootup. I have
DISABLE_IPV6=Yes set in /etc/shorewall/shorewall.conf, and yet, after a
reboot:

$ sudo ip6tables --list
Password:
Chain INPUT (policy ACCEPT)
target     prot opt source               destination         

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination         

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination         
$ sudo /etc/init.d/shorewall restart
Restarting "Shorewall firewall": done.
$ sudo ip6tables --list
Chain INPUT (policy DROP)
target     prot opt source               destination         

Chain FORWARD (policy DROP)
target     prot opt source               destination         

Chain OUTPUT (policy DROP)
target     prot opt source               destination         

-- System Information:
Debian Release: 3.1
Architecture: i386 (i686)
Kernel: Linux 2.6.8-2-686
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)

Versions of packages shorewall depends on:
ii  debconf                       1.4.30.13  Debian configuration management sy
ii  iproute                       20041019-3 Professional tools to control the 
ii  iptables                      1.2.11-10  Linux kernel 2.4+ iptables adminis

-- debconf information:
  shorewall/upgrade_20_22:
  shorewall/upgrade_14_20:
  shorewall/upgrade_to_14:
  shorewall/dont_restart:


--- End Message ---
--- Begin Message ---
> I have a bit more information on this.  Basically, the problem is
> related to a bug reported in redhat [0].  It turns out that shorewall
> loads nf_nat_h323, which loads nf_conntrack_h323, which loads ipv6.
> According to that last message posted in the redhat bugzilla, the
> problem was fixed by the netfilter team upstream.  Based on that, I do
> not think that this bug is really a bug in shorewall.  Thus, I am
> inclined to close it.  If you have an objection, please let me know.  If
> I do not receive an objection in the near future, I will go ahead and
> close this bug.

Makes sense to me. Thanks for investigating! :)

> Regards,
> 
> -Roberto
> 
> [0] https://bugzilla.redhat.com/show_bug.cgi?id=375581
> [1] http://marc.info/?l=netfilter-devel&m=119676981314842&w=4


-- 
Sam Morris <[EMAIL PROTECTED]>

Attachment: signature.asc
Description: This is a digitally signed message part


--- End Message ---

Reply via email to