Skip to content

Commit

Permalink
Firewall: add warning message, saying that during boot, all interface…
Browse files Browse the repository at this point in the history
…s are loaded before firewall.
  • Loading branch information
nicolas-fort committed Aug 15, 2024
1 parent 5410ab6 commit e131972
Showing 1 changed file with 5 additions and 0 deletions.
5 changes: 5 additions & 0 deletions docs/configuration/firewall/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,11 @@
Firewall
########

.. warning:: Due to a race condition that can lead to a failure during boot
process, all interfaces are initialized before firewall is configured. This
leads to a situation where the system is open to all traffic, and can be
considered as a security risk.

As VyOS is based on Linux it leverages its firewall. The Netfilter project
created iptables and its successor nftables for the Linux kernel to
work directly on packet data flows. This now extends the concept of
Expand Down

0 comments on commit e131972

Please sign in to comment.