Skip to content

RHEL/firewalld: Netclient allow rules do not permit inbound overlay traffic #1345

Description

@DylanBergmann2502

Netmaker documents RHEL and Rocky Linux as supported netclient platforms, but
the current netclient firewall setup does not permit inbound overlay traffic on
a default firewalld/nftables host. Could this be fixed in netclient? At minimum,
please document the required firewalld configuration for RHEL-family hosts
(RHEL, Rocky, AlmaLinux, CentOS Stream, Fedora).

Observed behaviour

On a fresh Rocky Linux 10 host using the default public firewalld zone:

  • netclient joins normally and WireGuard/DERP handshakes are healthy.
  • A node can initiate connections to its peers/admins.
  • New connections from peers to services listening on the netmaker interface
    are rejected with icmpx admin-prohibited (seen by the peer as No route to host).

The host's iptables rules contain Netmaker's accepting NETMAKER-ACL-IN rule,
but Rocky's firewalld uses a separate nftables base chain. Its default public
zone subsequently rejects traffic received on the unassigned netmaker
interface. This means the iptables accept is not final in this environment.

Reproduction conditions

  • Rocky Linux 10
  • firewalld running with the default public zone
  • netclient using the normal iptables-nft path
  • Netmaker's default enabled All Nodes ACL
  • A TCP service listening on the host/host-network namespace through the
    netmaker interface

Requested outcome

The preferred long-term fix is for netclient to integrate with an active
firewalld service when it creates the netmaker interface: assign that
interface to a runtime-only accepting zone, reapply the assignment after an
interface recreation or firewalld reload, and remove it on clean shutdown.

That keeps the responsibility at the layer that owns the WireGuard interface.
The integration must preserve Netmaker ACL behavior; please validate both the
default All Nodes allow case and an explicit deny ACL on a
firewalld/nftables host.

If automatic firewalld integration is intentionally out of scope, please add a
prominent RHEL-family documentation note with a supported operator procedure,
such as:

# Run after netclient has created the netmaker interface.
sudo firewall-cmd --permanent --new-zone=netmaker 2>/dev/null || true
sudo firewall-cmd --permanent --zone=netmaker --set-target=ACCEPT
sudo firewall-cmd --permanent --zone=netmaker --add-interface=netmaker
sudo firewall-cmd --reload

This does not disable firewalld. It trusts only traffic that arrives through
the authenticated WireGuard interface. Operators should validate both allowed
and denied Netmaker ACL cases on their target firewalld/nftables release.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions