Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-27842

[RFE] Explicit addition of the port to firewalld by the admin before forwarding

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • rhel-container-tools
    • 3
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • RUN 268, RUN 269, RUN 270, RUN 271, RUN 272, RUN 273, RUN 274
    • Enhancement
    • Hide
      .`StrictForwardPorts` is now available in `firewalld`

      When the `StrictForwardPorts` option in the `/etc/firewalld/firewalld.conf` configuration file is set to `yes`, port forwarding from Podman is no longer possible, and attempting to start a container or pod with the `-p` or `-P` options returns errors. All ports must be forwarded by using `firewalld`. This ensures that containers cannot allow traffic through the firewall without administrator intervention. See the `netavark-firewalld` man page for more details.
      Show
      .`StrictForwardPorts` is now available in `firewalld` When the `StrictForwardPorts` option in the `/etc/firewalld/firewalld.conf` configuration file is set to `yes`, port forwarding from Podman is no longer possible, and attempting to start a container or pod with the `-p` or `-P` options returns errors. All ports must be forwarded by using `firewalld`. This ensures that containers cannot allow traffic through the firewall without administrator intervention. See the `netavark-firewalld` man page for more details.
    • Done
    • Done
    • Done
    • None

      Podman loads NAT rules that bypass firewall restrictions. The DNAT occurs before firewalld's rule set and as a result port 9100 is open to the world.

      Adding configuration option which would require explicit addition of the port to firewalld by the admin before forwarding. 

      https://issues.redhat.com/browse/RHEL-26522 is closed as this would need to be RFE.

       

       

              rhn-support-jnovy Jindrich Novy
              rhn-support-npalanis Nandhika Palanisamy
              Container Runtime Eng Bot Container Runtime Eng Bot
              Yuhui Jiang Yuhui Jiang
              Gabriela Necasova Gabriela Necasova
              Votes:
              0 Vote for this issue
              Watchers:
              16 Start watching this issue

                Created:
                Updated: