Bug#775544: nftables: init system stop action shouldn't flush rules

2015-01-21 Thread Christoph Anton Mitterer
On Tue, 2015-01-20 at 11:47 +0100, Arturo Borrero Gonzalez wrote: > As I said before, the intended behaviour of stopping the firewall > service is firewalling happening no longer in the machine. Well as I've explained before, that should conceptually mean that there is no longer networking at all.

Bug#775544: nftables: init system stop action shouldn't flush rules

2015-01-19 Thread Christoph Anton Mitterer
reopen 775544 stop On Mon, 2015-01-19 at 10:56 +0100, Arturo Borrero Gonzalez wrote: > First, when stopping a service, I expect all effects of the service to > disappear. Well but a firewall isn't a service like a daemon like postfix. It's more like the initial-entropy-seeding of urandom on boot

Bug#775544: nftables: init system stop action shouldn't flush rules

2015-01-16 Thread Christoph Anton Mitterer
Package: nftables Version: 0.4-2 Severity: important Tags: security Hi. I had the same discussion basically already for netfilter-prsistent: IMHO, init system stop action shouldn't lead to firewall rules being flushed. First, there is a security reason, i.e. when you shut down the system there