LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Containers
User Name
Password
Linux - Containers This forum is for the discussion of all topics relating to Linux containers. Docker, LXC, LXD, runC, containerd, CoreOS, Kubernetes, Mesos, rkt, and all other Linux container platforms are welcome.

Notices


Reply
  Search this Thread
Old 10-06-2018, 07:31 PM   #1
gregrwm
LQ Newbie
 
Registered: Oct 2018
Posts: 4

Rep: Reputation: Disabled
who/what issues iptables commands?


a couple containers lost networking a couple days ago, i'm thinking it likely the issue is iptables commands being issued by system code somewhere. we manage iptables with our own firewall script. we're running openvz7 on centos7. i already removed firewalld, and i would like to know what code causes the following three entries in /var/log/messages:

Oct 5 15:53:05 pecan kernel: Bridge firewalling registered

Oct 5 15:53:16 pecan systemd: Started SYSV: setup firewall (iptables) rules (INPUT chain for the HN, FORWARD chain for clients).

Oct 5 15:53:48 pecan prl_disp_service: 10-05 15:53:48.987 W /cmn_utils:2214:2391/ Start setting basic firewall rules...
 
Old 10-06-2018, 08:54 PM   #2
ferrari
LQ Guru
 
Registered: Sep 2003
Location: Auckland, NZ
Distribution: openSUSE Leap
Posts: 5,834

Rep: Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148
Code:
Oct 5 15:53:16 pecan systemd: Started SYSV: setup firewall (iptables) rules (INPUT chain for the HN, FORWARD chain for clients).
HN firewall perhaps?
https://wiki.openvz.org/Setting_up_an_iptables_firewall
 
Old 10-07-2018, 03:34 PM   #3
gregrwm
LQ Newbie
 
Registered: Oct 2018
Posts: 4

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by ferrari View Post
that's the page that primarily served as template for the firewall script we're using. in centos6/openvz6 this has worked fine. in centos7/openvz7, even with firewalld already uninstalled, we see quite a bit of firewall/iptables related logging in /var/log/messages (see my OP for examples), but with no indication where to find the code that's causing the messages!

the dearth of documentation leaves me wondering if the path of least resistance is to give up on our own trusty iptables management script, and reinstall and learn to use firewalld, in the likelihood that's what's expected of us.

that's not really what i want to do tho. we already have traffic accounting all implemented in our own script, and learning and reimplementing in a new layer of abstraction doesn't strike me as all that likely to lead to an increase in either functionality or reliability.

Last edited by gregrwm; 10-07-2018 at 03:42 PM.
 
Old 10-07-2018, 09:20 PM   #4
ferrari
LQ Guru
 
Registered: Sep 2003
Location: Auckland, NZ
Distribution: openSUSE Leap
Posts: 5,834

Rep: Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148
Well, it was your OP output that I used for a quick search, and I noticed the reference to the HN firewall, so I assumed that was involved? Did you not investigate that further?

You're not forced to use firewalld, so you can leave that out of the equation if already disabled.
 
Old 10-07-2018, 10:48 PM   #5
gregrwm
LQ Newbie
 
Registered: Oct 2018
Posts: 4

Original Poster
Rep: Reputation: Disabled
indeed, that's the advice from which i wrote our current iptables management script several years ago, and it has served us very well in centos6/openvz6.

documentation for openvz7 however seems rather lacking. i'm trying to find out what system code in centos7/openvz7 is now stepping in to manipulate iptables even in the absence of firewalld. /var/log/messages is filled with messages about manipulating iptables that our script didn't generate. i want to find the code that's generating those messages.
 
Old 10-08-2018, 03:54 AM   #6
ferrari
LQ Guru
 
Registered: Sep 2003
Location: Auckland, NZ
Distribution: openSUSE Leap
Posts: 5,834

Rep: Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148
Well, the first entry is associated with OpenVZ for configured network bridging AFAIU.

Quote:
indeed, that's the advice from which i wrote our current iptables management script several years ago, and it has served us very well in centos6/openvz6.
So you are using HN firewall, that seems to be what the second line you shared is about.

The third line, references 'prl_disp_service'...
https://github.com/OpenVZ/prl-disp-service
Quote:
prl-disp-service is a OpenVZ management service. It is a component of OpenVZ.
That's about all I can offer. I'm sure you can search online as well as I. Perhaps you can get the required support from the OpenVZ forum. Good luck with this.
 
  


Reply

Tags
firewall, iptables, openvz



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
help in iptables commands packets Linux - Security 2 05-31-2010 10:15 PM
iptables commands problem naaman Linux - Security 6 02-23-2010 02:20 AM
iptables commands sujitkale Linux - Networking 5 09-25-2007 01:42 PM
incorrect iptables commands? devel Linux - Networking 3 06-02-2005 09:35 PM
iptables commands downlaw Linux - Networking 3 06-09-2003 01:43 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Containers

All times are GMT -5. The time now is 07:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration