Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upDisabling qubes-network and qubes-firewall serivces does not work on Debian based templates #3453
Comments
andrewdavidwong
added
bug
C: Debian
labels
Jan 13, 2018
andrewdavidwong
added this to the Release 3.2 updates milestone
Jan 13, 2018
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
unman
Feb 6, 2018
Member
As I pointed out, this arises even for non proxy qubes. I don't see a difference between iptables for Fedora and Debian - both have the FORWARD chain set. But Debian has /etc/sysctl.d/80_qubes.conf setting /proc/sys/net/ipv4/ip_forward to 1.
This file is provided by qubes-core-agent.
|
As I pointed out, this arises even for non proxy qubes. I don't see a difference between iptables for Fedora and Debian - both have the FORWARD chain set. But Debian has /etc/sysctl.d/80_qubes.conf setting /proc/sys/net/ipv4/ip_forward to 1. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
unman
Feb 6, 2018
Member
@qjoo Can you check again to see if the Fedora FORWARD chain is empty in iptables? It doesn't seem to be for me with the service disabled.
I'm content to leave it in any case, if forwarding itself is disabled, as it should be. Would you agree?
|
@qjoo Can you check again to see if the Fedora FORWARD chain is empty in iptables? It doesn't seem to be for me with the service disabled. |
qjoo commentedJan 13, 2018
Qubes OS version:
R3.2
Affected TemplateVMs:
Debian 9
Steps to reproduce the behavior:
Expected behavior:
/proc/sys/net/ipv4/ip_forward should be 0
iptables rules should be empty.
Actual behavior:
/proc/sys/net/ipv4/ip_forward is 1
iptables rules are present (as if qubes-network and qubes-firewall was not disabled)
This (disabling services) works as expected on Fedora 25 and 26 templates.
I stumbled on this problem when migrating from Fedora to Debian templates.
Mailing list post:
https://groups.google.com/forum/#!msg/qubes-users/jz_Z85WeY4Y/3VwY2az-BAAJ