Hi Ant R.,

Yes, we linked iptables with services and config which match a lot of usecases. 
So, what you are seeing makes sense in 15.1 context.

You can use the 
https://github.com/inverse-inc/packetfence/blob/devel/conf/ip6tables-custom.conf.inc.example
 to set rules that you want to apply rules without the service.
Once the file /usr/local/pf/conf/ip6tables-custom.conf.inc is created just 
restart the packetfence-ip6tables service or use the `/usr/local/bin/pfcmd 
reloadip6tablesrules`

Thank you for using PacketFence.


Jeremy
 Goimard
Senior Software Engineer
PacketFence<https://www.packetfence.org> - 
Fingerbank<https://www.fingerbank.org>

[Akamai Secure your applications]<https://www.akamai.com/solutions/security>

Support:+1-555-183-6031


Akamai
 Technologies - Inverse
145 Broadway
Cambridge, MA 02142


Connect
 with Us:
        [https://www.akamai.com/us/en/multimedia/images/custom/community.jpg] 
<https://community.akamai.com>  
[https://www.akamai.com/us/en/multimedia/images/custom/rss.png] 
<https://www.akamai.com/blog>  
[https://www.akamai.com/content/dam/site/en/images/logo/2024/x-logo.png] 
<https://x.com/akamai>  
[https://www.akamai.com/us/en/multimedia/images/custom/fb.png] 
<http://www.facebook.com/AkamaiTechnologies>  
[https://www.akamai.com/us/en/multimedia/images/custom/in.png] 
<http://www.linkedin.com/company/akamai-technologies>  
[https://www.akamai.com/us/en/multimedia/images/custom/youtube.png] 
<http://www.youtube.com/user/akamaitechnologies?feature=results_main>



________________________________
From: Ravenhill, Anthony P. via PacketFence-users 
<[email protected]>
Sent: Monday, August 17, 2026 5:02 AM
To: [email protected] 
<[email protected]>
Cc: Ravenhill, Anthony P. <[email protected]>
Subject: [PacketFence-users] 15.0 -> 15.1 and ip6tables

!-------------------------------------------------------------------|
  This Message Is From an External Sender
  This message came from outside your organization.
|-------------------------------------------------------------------!

Hi all

We upgraded pf 15.0 to 15.1 on Debian 12 without major issue except that 
ip6tables rules were no longer being generated or applied, i.e. post upgrade:

# ip6tables -S
-P INPUT ACCEPT
-P FORWARD ACCEPT
-P OUTPUT ACCEPT

If we assign the portal service to the management interface (we don't need it), 
ip6tables rules are now generated and applied as they were in pf 15.0.

Has anyone else noticed this or is this the new intended behaviour?

Kind regards

Ant R.


_______________________________________________
PacketFence-users mailing list
[email protected]
https://urldefense.com/v3/__https://lists.sourceforge.net/lists/listinfo/packetfence-users__;!!GjvTz_vk!XCQ4qAZfZTwU1MAF8lsb5Aj5ckXLz3271Tu9p6u4kiRGpLZJHs80-3aIwYGjICVGvA_nHR_9bVzBdTwFtNennw48cRlqSWuqX_I$
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to