Netmaker documents RHEL and Rocky Linux as supported netclient platforms, but
the current netclient firewall setup does not permit inbound overlay traffic on
a default firewalld/nftables host. Could this be fixed in netclient? At minimum,
please document the required firewalld configuration for RHEL-family hosts
(RHEL, Rocky, AlmaLinux, CentOS Stream, Fedora).
Observed behaviour
On a fresh Rocky Linux 10 host using the default public firewalld zone:
netclient joins normally and WireGuard/DERP handshakes are healthy.
- A node can initiate connections to its peers/admins.
- New connections from peers to services listening on the
netmaker interface
are rejected with icmpx admin-prohibited (seen by the peer as No route to host).
The host's iptables rules contain Netmaker's accepting NETMAKER-ACL-IN rule,
but Rocky's firewalld uses a separate nftables base chain. Its default public
zone subsequently rejects traffic received on the unassigned netmaker
interface. This means the iptables accept is not final in this environment.
Reproduction conditions
- Rocky Linux 10
- firewalld running with the default
public zone
netclient using the normal iptables-nft path
- Netmaker's default enabled
All Nodes ACL
- A TCP service listening on the host/host-network namespace through the
netmaker interface
Requested outcome
The preferred long-term fix is for netclient to integrate with an active
firewalld service when it creates the netmaker interface: assign that
interface to a runtime-only accepting zone, reapply the assignment after an
interface recreation or firewalld reload, and remove it on clean shutdown.
That keeps the responsibility at the layer that owns the WireGuard interface.
The integration must preserve Netmaker ACL behavior; please validate both the
default All Nodes allow case and an explicit deny ACL on a
firewalld/nftables host.
If automatic firewalld integration is intentionally out of scope, please add a
prominent RHEL-family documentation note with a supported operator procedure,
such as:
# Run after netclient has created the netmaker interface.
sudo firewall-cmd --permanent --new-zone=netmaker 2>/dev/null || true
sudo firewall-cmd --permanent --zone=netmaker --set-target=ACCEPT
sudo firewall-cmd --permanent --zone=netmaker --add-interface=netmaker
sudo firewall-cmd --reload
This does not disable firewalld. It trusts only traffic that arrives through
the authenticated WireGuard interface. Operators should validate both allowed
and denied Netmaker ACL cases on their target firewalld/nftables release.
Netmaker documents RHEL and Rocky Linux as supported netclient platforms, but
the current netclient firewall setup does not permit inbound overlay traffic on
a default firewalld/nftables host. Could this be fixed in netclient? At minimum,
please document the required firewalld configuration for RHEL-family hosts
(RHEL, Rocky, AlmaLinux, CentOS Stream, Fedora).
Observed behaviour
On a fresh Rocky Linux 10 host using the default
publicfirewalld zone:netclientjoins normally and WireGuard/DERP handshakes are healthy.netmakerinterfaceare rejected with
icmpx admin-prohibited(seen by the peer asNo route to host).The host's
iptablesrules contain Netmaker's acceptingNETMAKER-ACL-INrule,but Rocky's firewalld uses a separate nftables base chain. Its default
publiczone subsequently rejects traffic received on the unassigned
netmakerinterface. This means the iptables accept is not final in this environment.
Reproduction conditions
publiczonenetclientusing the normal iptables-nft pathAll NodesACLnetmakerinterfaceRequested outcome
The preferred long-term fix is for netclient to integrate with an active
firewalld service when it creates the
netmakerinterface: assign thatinterface to a runtime-only accepting zone, reapply the assignment after an
interface recreation or firewalld reload, and remove it on clean shutdown.
That keeps the responsibility at the layer that owns the WireGuard interface.
The integration must preserve Netmaker ACL behavior; please validate both the
default
All Nodesallow case and an explicit deny ACL on afirewalld/nftables host.
If automatic firewalld integration is intentionally out of scope, please add a
prominent RHEL-family documentation note with a supported operator procedure,
such as:
This does not disable firewalld. It trusts only traffic that arrives through
the authenticated WireGuard interface. Operators should validate both allowed
and denied Netmaker ACL cases on their target firewalld/nftables release.