Ensuring network security when iptables encounters an error on network startup
Issue
- If a fully qualified domain name is inserted into an IPTables ruleset without being evaluated into its constituent A records, IPTables will fail into an open state, with default ACCEPT policies for all chains.
Environment
- Red Hat Enterprise Linux 5 or 6
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.