FirewallD concern CentOS8.3.2011
Posted: 2020/12/15 18:50:07
FirewallD seems to work on our CentOS 8.3.2011 server however when you look at the status it shows the following:
[root@Server user]# systemctl status firewalld
● firewalld.service - firewalld - dynamic firewall daemon
Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled; vendor preset: enabled)
Active: active (running) since Sun 2020-12-13 02:30:41 MST; 2 days ago
Docs: man:firewalld(1)
Main PID: 895 (firewalld)
Tasks: 2 (limit: 23616)
Memory: 39.0M
CGroup: /system.slice/firewalld.service
└─895 /usr/libexec/platform-python -s /usr/sbin/firewalld --nofork --nopid
Dec 13 02:30:38 Server.domain.com systemd[1]: Starting firewalld - dynamic firewall daemon...
Dec 13 02:30:41 Server.domain.com systemd[1]: Started firewalld - dynamic firewall daemon.
Dec 13 02:30:41 Server.domain.com firewalld[895]: WARNING: AllowZoneDrifting is enabled. This is considered an insecure configuration option. It will be removed in a future release. Please consider disabli>
Dec 13 02:30:43 Server.domain.com firewalld[895]: ERROR: INVALID_SERVICE: smtp.xml
Dec 13 02:30:43 Server.domain.com firewalld[895]: ERROR: 'python-nftables' failed: internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
JSON blob:
{"nftables": [{"metainfo": {"json_schema_version": 1}}, {"add": {"chain": {"family": "inet", "table": "firewalld", "name": "raw_PRE_public"}}}, {"add": {"c>
Dec 13 02:30:43 Server.domain.com firewalld[895]: ERROR: COMMAND_FAILED: 'python-nftables' failed: internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
JSON blob:
{"nftables": [{"metainfo": {"json_schema_version": 1}}, {"add": {"chain": {"family": "inet", "table": "firewalld", "name": "raw_PRE_public"}}}, {"add": {"c>
However when looking at what it claims to be doing:
[root@Server user]# firewall-cmd --list-all
public
target: default
icmp-block-inversion: no
interfaces:
sources:
services: cockpit ssh
ports:
protocols:
masquerade: no
forward-ports:
source-ports:
icmp-blocks:
rich rules:
New rules also appear to take effect after restarting the service:
services: cockpit http https ssh
This server is in a DMZ and I don't yet have a device to run nmap against this server to truly verify that firewalld is indeed running.
Are the errors I am seeing a concern? I have found a reference to a version 8.1 bug but nothing else.
[root@Server user]# systemctl status firewalld
● firewalld.service - firewalld - dynamic firewall daemon
Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled; vendor preset: enabled)
Active: active (running) since Sun 2020-12-13 02:30:41 MST; 2 days ago
Docs: man:firewalld(1)
Main PID: 895 (firewalld)
Tasks: 2 (limit: 23616)
Memory: 39.0M
CGroup: /system.slice/firewalld.service
└─895 /usr/libexec/platform-python -s /usr/sbin/firewalld --nofork --nopid
Dec 13 02:30:38 Server.domain.com systemd[1]: Starting firewalld - dynamic firewall daemon...
Dec 13 02:30:41 Server.domain.com systemd[1]: Started firewalld - dynamic firewall daemon.
Dec 13 02:30:41 Server.domain.com firewalld[895]: WARNING: AllowZoneDrifting is enabled. This is considered an insecure configuration option. It will be removed in a future release. Please consider disabli>
Dec 13 02:30:43 Server.domain.com firewalld[895]: ERROR: INVALID_SERVICE: smtp.xml
Dec 13 02:30:43 Server.domain.com firewalld[895]: ERROR: 'python-nftables' failed: internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
JSON blob:
{"nftables": [{"metainfo": {"json_schema_version": 1}}, {"add": {"chain": {"family": "inet", "table": "firewalld", "name": "raw_PRE_public"}}}, {"add": {"c>
Dec 13 02:30:43 Server.domain.com firewalld[895]: ERROR: COMMAND_FAILED: 'python-nftables' failed: internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
internal:0:0-0: Error: No such file or directory
JSON blob:
{"nftables": [{"metainfo": {"json_schema_version": 1}}, {"add": {"chain": {"family": "inet", "table": "firewalld", "name": "raw_PRE_public"}}}, {"add": {"c>
However when looking at what it claims to be doing:
[root@Server user]# firewall-cmd --list-all
public
target: default
icmp-block-inversion: no
interfaces:
sources:
services: cockpit ssh
ports:
protocols:
masquerade: no
forward-ports:
source-ports:
icmp-blocks:
rich rules:
New rules also appear to take effect after restarting the service:
services: cockpit http https ssh
This server is in a DMZ and I don't yet have a device to run nmap against this server to truly verify that firewalld is indeed running.
Are the errors I am seeing a concern? I have found a reference to a version 8.1 bug but nothing else.