[systemd-devel] [PATCH] Add a network-pre.target to avoid firewall leaks

Zbigniew Jędrzejewski-Szmek zbyszek at in.waw.pl
Sat Jun 7 16:07:38 PDT 2014


On Sun, Jun 08, 2014 at 12:55:55AM +0200, Michael Biebl wrote:
> Could you elaborate why Before=network.target is too late?
Because then network setup races with e.g. iptables setup. Depending
on the timing, a window in which the network has been set up, but
the firewall is not yet in place.

Zbyszek


More information about the systemd-devel mailing list