Skip to content

Commit f5c0625

Browse files
committed
Fixed: enable correct service for restoring IPv4 rules on EL8/EL9
nftables.service loads nft rules from /etc/sysconfig/nftables.conf, but this module generates classic iptables rules which are stored in /etc/sysconfig/iptables. The service to load these on boot is simply and only "iptables.service". IPv6 rules are loaded correctly by ip6tables.service.
1 parent 6620ad2 commit f5c0625

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

manifests/params.pp

+2-2
Original file line numberDiff line numberDiff line change
@@ -30,14 +30,14 @@
3030
}
3131
default: {
3232
if versioncmp($facts['os']['release']['full'], '9') >= 0 {
33-
$service_name = ['nftables','iptables']
33+
$service_name = 'iptables'
3434
$service_name_v6 = 'ip6tables'
3535
$package_name = ['iptables-services', 'nftables', 'iptables-nft-services']
3636
$iptables_name = 'iptables-nft'
3737
$sysconfig_manage = false
3838
$firewalld_manage = true
3939
} elsif versioncmp($facts['os']['release']['full'], '8.0') >= 0 {
40-
$service_name = ['iptables', 'nftables']
40+
$service_name = ['iptables']
4141
$service_name_v6 = 'ip6tables'
4242
$package_name = ['iptables-services', 'nftables']
4343
$iptables_name = 'iptables'

0 commit comments

Comments
 (0)