LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 12-19-2020, 09:12 PM   #1
nooobeee
Member
 
Registered: Oct 2004
Distribution: Debian
Posts: 72

Rep: Reputation: 1
debian firewalld reload issue


I have a vanilla debian 10 setup with nginx. I installed firewalld which went fine. I added the HTTP and HTTPS rules using:
Code:
firewall-cmd --add-service={http,https} --permanent --zone=public
However when I attempt to reload, I run into an error:
Code:
sudo firewall-cmd --reload
Error: COMMAND_FAILED: '/usr/sbin/iptables-restore -w -n' failed: iptables-restore v1.8.2 (nf_tables):
line 4: RULE_REPLACE failed (No such file or directory): rule in chain INPUT
line 4: RULE_REPLACE failed (No such file or directory): rule in chain OUTPUT
Doing some digging, it seems there may be a bug.
https://bugs.debian.org/cgi-bin/bugr...cgi?bug=914694

Most of this is, honestly, above my head. But I found a nugget in there so I tried the IndividualCalls=yes attribute and restarting the service because it seemed this may have been a workaround but that didn't seem to work for me:
Code:
> > Setting InvividualCalls=yes in /etc/firewalld/firewalld.conf will be
> > more verbose and help in debugging the cause.
> 
> Fun, this actually *fixes* the problem:

That makes it smell like an iptables-restore issue in the nftables
backed version of iptables. It would be great if we could reproduce
without firewalld using iptables-restore.
apt indicates my firewalld is currently 1.8.2-4.

Has anyone else run into this? Any suggestions or thoughts would be appreciated.
 
Old 12-19-2020, 09:19 PM   #2
nooobeee
Member
 
Registered: Oct 2004
Distribution: Debian
Posts: 72

Original Poster
Rep: Reputation: 1
NVM, I think I was wrong about what they indicted "fixes" the problem in that workaround. Turns out rebooting the server applies the new services without issue. I don't think I'll be modifying the firewall much so it shouldn't be too much of an issue. I guess we may just have to wait until Debian merges the newer versions of iptables into their stable repos.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] apache2.service: Reload operation timed out. Killing reload process. dr-ing Linux - Software 5 03-27-2020 07:59 AM
apache2.service: Reload operation timed out. Killing reload process. dr-ing Linux - Software 1 03-27-2020 02:13 AM
Centos 7 firewalld Zone Issue tech0925 Linux - Security 3 03-01-2019 11:23 PM
Synaptic keeps asking to reload package info - cannot add repositories (debian lenny) Rexx Magnus Linux - Newbie 1 08-03-2008 06:05 PM
Tomcat reload servlet is very slow, but reload jsp is fast and good? gsbarry Programming 2 04-28-2006 09:34 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 02:12 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration