From 2da3a5c4a642e23878f07711538f5b4e4eb894c4 Mon Sep 17 00:00:00 2001 From: Dietmar Maurer Date: Tue, 20 May 2014 05:55:58 +0200 Subject: [PATCH 1/1] remove wrong corosync rules using port 9000 --- src/PVE/Firewall.pm | 2 -- 1 file changed, 2 deletions(-) diff --git a/src/PVE/Firewall.pm b/src/PVE/Firewall.pm index 246e7af..1fcb71c 100644 --- a/src/PVE/Firewall.pm +++ b/src/PVE/Firewall.pm @@ -1695,7 +1695,6 @@ sub enable_host_firewall { ruleset_addrule($ruleset, $chain, "-m addrtype --dst-type MULTICAST -j ACCEPT"); ruleset_addrule($ruleset, $chain, "-p udp -m conntrack --ctstate NEW --dport 5404:5405 -j ACCEPT"); - ruleset_addrule($ruleset, $chain, "-p udp -m udp --dport 9000 -j ACCEPT"); #corosync # we use RETURN because we need to check also tap rules my $accept_action = 'RETURN'; @@ -1728,7 +1727,6 @@ sub enable_host_firewall { ruleset_addrule($ruleset, $chain, "-m addrtype --dst-type MULTICAST -j ACCEPT"); ruleset_addrule($ruleset, $chain, "-p udp -m conntrack --ctstate NEW --dport 5404:5405 -j ACCEPT"); - ruleset_addrule($ruleset, $chain, "-p udp -m udp --dport 9000 -j ACCEPT"); #corosync # we use RETURN because we may want to check other thigs later $accept_action = 'RETURN'; -- 2.39.2