Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 88388 - Disallowing incoming http connections does not work
Summary: Disallowing incoming http connections does not work
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: redhat-config-securitylevel
Version: 9
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Brent Fox
QA Contact:
Depends On:
TreeView+ depends on / blocked
Reported: 2003-04-09 17:40 UTC by Need Real Name
Modified: 2008-05-01 15:38 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2003-04-10 08:20:51 UTC

Attachments (Terms of Use)

Description Need Real Name 2003-04-09 17:40:52 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.2.1) Gecko/20030225

Description of problem:
My security setting is set to high, with ppp0 as a trusted device.

I have "customize" selected. I do not allow *any* incoming services, but still
have entries from outside in my apache log file.

How reproducible:

Steps to Reproduce:
1. Security level: high
2. Select "customize"
3. Select "ppp0" as a trusted device.
4. Ensure nothing under "allow incoming" is selected.

Additional info:

Rebooting doesn't change anything.

Comment 1 Michael Young 2003-04-10 07:13:53 UTC
I thought that a "trusted device" meant that you trusted (ie. allowed) all
traffic from that device, and the firewall setting only applied to non-trusted

Comment 2 Mark J. Cox 2003-04-10 08:20:51 UTC
This is expected behaviour, trusted devices are exempt from the firewall rules.  See

Comment 3 Need Real Name 2003-04-10 17:19:16 UTC
I think the manual could be clearer:

"..Selecting any of the Trusted Devices allows access *to* your system for
all traffic *from* that device.."

and the gui should give a warning.

Comment 4 Need Real Name 2003-04-10 17:58:42 UTC
This is a dupe of 88136

Note You need to log in before you can comment on or make changes to this bug.