When adding undefined ipset rules in firewalld, existing rules are lost.

Solution Unverified - Updated -

Issue

When adding an invalid ipset-rule via firewall-cmd --permanent, the network becomes unresponsive. The invalid rule leads to the previous, valid rules getting removed. It also happens in latest firewalld and nftables version.

Environment

  • Red Hat Enterprise Linux, all versions with firewalld and nft
  • firewalld
  • nftables

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content