← Back to team overview

gufw-developers team mailing list archive

[Bug 566764] Re: Enabling firewall with the default rules breaks mintUpdate

 

"Is there scope for making ufw or gufw check for live network
connections and offering the user some sort of a warning before
continuing?"

Possibly in the GUI, but not at the ufw CLI level. If someone types in
the commands to enable the firewall, then the firewall should be enabled
(excepting warning when running under ssh, which is already done). I am
going to mark the ufw as Won't Fix for now.

** Changed in: ufw
       Status: New => Won't Fix

-- 
Enabling firewall with the default rules breaks mintUpdate
https://bugs.launchpad.net/bugs/566764
You received this bug notification because you are a member of Gufw
Developers, which is the registrant for Gufw.

Status in Gufw: Invalid
Status in The Linux Mint Distribution: Invalid
Status in ufw - Uncomplicated Firewall: Won't Fix
Status in “gui-ufw” package in Ubuntu: Invalid

Bug description:
In Mint 8 Helena, enabling the firewall by clicking the Enabled button in the Firewall dialog creates a very odd set of default rules that over-cautiously blocks input packets with no allowance being made for RELATED,EXISTING connections. This is undesirable and has several consequences - for example, it completely breaks mintUpdate which can no longer receive data from Canonical's servers on port 80:

[UFW BLOCK] IN=eth0 OUT= MAC=00:29:aa:6b:13:ca:00:21:1b:52:ef:b0:a7:00 SRC=91.189.88.46 DST=192.168.50.8 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=55764 PROTO=TCP SPT=80 DPT=32948 WINDOW=1024 RES=0x00 RST URGP=0