Explorar el Código

network: order qubes-firewall service before enabling IP forwarding

Start qubes-firewall (which will add "DROP by default" rule) before
enabling IP forwarding, to not leave a time slot where some connection
could go around configured firewall.

QubesOS/qubes-issues#3269
Marek Marczykowski-Górecki hace 6 años
padre
commit
3fb258db47
Se han modificado 1 ficheros con 2 adiciones y 1 borrados
  1. 2 1
      vm-systemd/qubes-firewall.service

+ 2 - 1
vm-systemd/qubes-firewall.service

@@ -1,7 +1,8 @@
 [Unit]
 Description=Qubes firewall updater
 ConditionPathExists=/var/run/qubes-service/qubes-firewall
-After=qubes-network.service
+After=qubes-iptables.service
+Before=qubes-network.service
 
 [Service]
 ExecStart=/usr/sbin/qubes-firewall