Was firewalld behavior supposed to change for forward-ports: like this?

Hello,

Before I installed the F45 candidate, I configured firewalld with firewall-cmd --add-forward-port to forward external interface website traffic (80/tcp and 443/tcp) to the machine to be forewarded to my webserver via the DMZ interface. Before F45, firewalld routed traffic received as external input to the forward ports. Any traffice forwarded from other internal interfaces was routed out of the external interface.

After F45, all traffic to the forwarded ports, whether internal or external, was redirected the forward to-addr host.

Was this an intended change or was this an error change? I don’t see any git log messages that look like they are specifically intending this new behavior. It feels like it would be a mistake, but I don’t follow the specific changes in firewalld to know.

At the very least, it forced me to close off external access to only my CDN. As a work-around, I removed the basic forward-ports and added rich rules forwarding traffic from my CDN addresses to the DMZ webserver. All other external traffic to those ports is blocked.

Please report in the fedora bug tracker Making sure you're not a bot!

@barryascott I reported it here: Was firewalld behavior supposed to change for forward-ports: like this? I was asking beforehand in case someone with knowledge of the recent changes to firewalld knew whether this is a behavior bug or an item requiring some documentation.

Less likely when you are running software that is not even in beta yet.
Once it’s released there will be release notes and a lot more people using f45.

You probably need to go upstream.

I opened a Buzilla entry for this, asking someone more knowledgable to determine if this is a behavior bug or a change in behavior requiring a documentation change.

As to the “unreleased software”, I am specifically testing the F45 release candidates to help find use-case issues.

Best regards,

Eric

Thanks you for doing this testing.
It’s very much appreciated!