<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A weekend of IPv6 bug chasing</title>
	<atom:link href="http://berrange.com/posts/2007/03/25/a-weekend-of-ipv6-bug-chasing/feed/" rel="self" type="application/rss+xml" />
	<link>http://berrange.com/posts/2007/03/25/a-weekend-of-ipv6-bug-chasing/</link>
	<description>Writing about photography, open source software, virtualization &#38; more</description>
	<lastBuildDate>Sun, 13 May 2012 09:58:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Dawid</title>
		<link>http://berrange.com/posts/2007/03/25/a-weekend-of-ipv6-bug-chasing/comment-page-1/#comment-45</link>
		<dc:creator>Dawid</dc:creator>
		<pubDate>Sun, 25 Mar 2007 21:04:00 +0000</pubDate>
		<guid isPermaLink="false">http://wordpress.berrange.com/?p=44#comment-45</guid>
		<description>OK, thanks for the clarification.</description>
		<content:encoded><![CDATA[<p>OK, thanks for the clarification.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://berrange.com/posts/2007/03/25/a-weekend-of-ipv6-bug-chasing/comment-page-1/#comment-46</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Sun, 25 Mar 2007 20:09:00 +0000</pubDate>
		<guid isPermaLink="false">http://wordpress.berrange.com/?p=44#comment-46</guid>
		<description>No, it isn&#039;t a dup - &lt;a href=&quot;https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=233725&quot; rel=&quot;nofollow&quot;&gt;my bug&lt;/a&gt; was complaining about the fact that system-config-securitylevel does not even add a match on state == RELATED,ESTABLISHED to the ip6tables ruleset in the first place. &lt;br /&gt;&lt;br /&gt;Though the kernel bug you mention does mean that even if it did add such a conntrack rule, things would still be broken. So I guess my bug 233725 would have to be marked as depending on 209945. As a temporary workaround system-config-securitylevel could at least add an non-conntrack style rule to INPUT matching on &#039;! --syn&#039; to allow return traffic until the kernel conntrack stuff was fixed. As it stands it is just broken out-of-the box which doesn&#039;t help people trying out IPv6 because they  will all have to manually allow port 80 (and similar for any other protocols they use outbound).</description>
		<content:encoded><![CDATA[<p>No, it isn&#8217;t a dup &#8211; <a href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=233725" rel="nofollow">my bug</a> was complaining about the fact that system-config-securitylevel does not even add a match on state == RELATED,ESTABLISHED to the ip6tables ruleset in the first place. </p>
<p>Though the kernel bug you mention does mean that even if it did add such a conntrack rule, things would still be broken. So I guess my bug 233725 would have to be marked as depending on 209945. As a temporary workaround system-config-securitylevel could at least add an non-conntrack style rule to INPUT matching on &#8216;! &#8211;syn&#8217; to allow return traffic until the kernel conntrack stuff was fixed. As it stands it is just broken out-of-the box which doesn&#8217;t help people trying out IPv6 because they  will all have to manually allow port 80 (and similar for any other protocols they use outbound).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dawid</title>
		<link>http://berrange.com/posts/2007/03/25/a-weekend-of-ipv6-bug-chasing/comment-page-1/#comment-47</link>
		<dc:creator>Dawid</dc:creator>
		<pubDate>Sun, 25 Mar 2007 19:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://wordpress.berrange.com/?p=44#comment-47</guid>
		<description>Isn&#039;t IPv6 bug #2 a dupe of https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=209945 ?&lt;br /&gt;&lt;br /&gt;You can also take a look at this post http://www.redhat.com/archives/fedora-test-list/2006-October/msg00580.html&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;Dawid</description>
		<content:encoded><![CDATA[<p>Isn&#8217;t IPv6 bug #2 a dupe of <a href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=209945" rel="nofollow">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=209945</a> ?</p>
<p>You can also take a look at this post <a href="http://www.redhat.com/archives/fedora-test-list/2006-October/msg00580.html" rel="nofollow">http://www.redhat.com/archives/fedora-test-list/2006-October/msg00580.html</a></p>
<p>Regards,<br />Dawid</p>
]]></content:encoded>
	</item>
</channel>
</rss>

