> In fact we have an open issue that covers this.

I couldn't find one that references this specific issue. Which issue are you 
referring to? Can you add this information to the issue?

Can you please allow me to post on the forums? My post has been pending for 48 
hours even though multiple moderators have been online and responding to other 
threads, which is not very professional. I want to update the VPN guide as it 
sounds like this isn't going to be resolved in the near future.

I would suggest doing something to make it easier for people to contribute to 
this project. It is made very difficult for people using proxies because this 
mailing list is gated by a Google captcha. The archive link is down pretty much 
always. The forums prevents signing up with proxies until a moderator accepts 
it which is apparently slow. GitHub prevents signing up with proxies. 
Frustration after frustration.

On Sunday, March 23rd, 2025 at 6:40 AM, skiinglasso2 <skiinglas...@proton.me> 
wrote:

> There's a bug in qubes-firewall.service. It should pull in and be ordered 
> before network-pre.target such that the firewall rules are guaranteed to be 
> in place before the network is raised.
>
> From man sytemd.special,
> network-pre.target
> This passive target unit may be pulled in by services that want to
> run before any network is set up, for example for the purpose of
> setting up a firewall. All network management software orders
> itself after this target, but does not pull it in.
>
> From https://systemd.io/NETWORK_ONLINE/
> network-pre.target is used to order services before any network interfaces 
> start to be configured. Its primary purpose is for usage with firewall 
> services that want to establish a firewall before any network interface is 
> up. Services that want to be run before the network is configured should use 
> Before=network-pre.target and Wants=network-pre.target.
>
> I suggest applying this change so that people who are currently relying on 
> this popular guide 
> https://forum.qubes-os.org/t/configuring-a-proxyvm-vpn-gateway/19061 can 
> continue to do so without having to make modifications to systemd themselves.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-devel" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-devel+unsubscr...@googlegroups.com.
To view this discussion visit 
https://groups.google.com/d/msgid/qubes-devel/glBGeQ9T-nP-gHTIuUpwradW4j7mV2nSboQv0HedV5deiiij5raTeW0m0evZ8qapn6AmeSA0dgqHeuWiOAt_6dxfH1KprtywZIVxIubDirU%3D%40proton.me.

Reply via email to