"systemd restart firewalld.service" compounds rules when CleanUpOnExit=no
Issue
systemd restart firewalld.service
compounds rules whenCleanUpOnExit=no
is set in/etc/firewalld/firewalld.conf
.firewalld
doesn't flush its ownnftables
table at startup whenCleanUpOnExit=no
is set in/etc/firewalld/firewalld.conf
.- The
nftables
maintained byfirewalld
has grown so significantly after restarts that system is spending excessive time innetfilter
code paths with system performance and packet loss occurring as a result.
Environment
- Red Hat Enterprise Linux (RHEL) 8
- Red Hat Enterprise Linux (RHEL) 9
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.