use nft is available and ignore iptables errors
This commit is contained in:
parent
d17d62ecf9
commit
dc75ac0406
|
@ -14,6 +14,8 @@ The **patch** part changes is incremented if multiple releases happen the same m
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
|
use nft is available and ignore iptables errors
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
### Removed
|
### Removed
|
||||||
|
|
|
@ -425,13 +425,9 @@ task_iptables() {
|
||||||
debug "Task: iptables"
|
debug "Task: iptables"
|
||||||
|
|
||||||
iptables_bin=$(command -v iptables)
|
iptables_bin=$(command -v iptables)
|
||||||
nft_bin=$(command -v nft)
|
|
||||||
|
|
||||||
if [ -n "${nft_bin}" ]; then
|
|
||||||
debug "* nft found, skip iptables"
|
|
||||||
else
|
|
||||||
if [ -n "${iptables_bin}" ]; then
|
if [ -n "${iptables_bin}" ]; then
|
||||||
last_result=$({ ${iptables_bin} -L -n -v; ${iptables_bin} -t filter -L -n -v; } >> "${dump_dir}/iptables-v.txt")
|
last_result=$({ ${iptables_bin} -L -n -v; ${iptables_bin} -t filter -L -n -v; } > "${dump_dir}/iptables-v.txt")
|
||||||
last_rc=$?
|
last_rc=$?
|
||||||
|
|
||||||
if [ ${last_rc} -eq 0 ]; then
|
if [ ${last_rc} -eq 0 ]; then
|
||||||
|
@ -439,10 +435,11 @@ task_iptables() {
|
||||||
else
|
else
|
||||||
debug "* iptables -v ERROR"
|
debug "* iptables -v ERROR"
|
||||||
debug "${last_result}"
|
debug "${last_result}"
|
||||||
rc=10
|
# Ignore errors because we don't know if this is nft related or a real error
|
||||||
|
# rc=10
|
||||||
fi
|
fi
|
||||||
|
|
||||||
last_result=$({ ${iptables_bin} -L -n; ${iptables_bin} -t filter -L -n; } >> "${dump_dir}/iptables.txt")
|
last_result=$({ ${iptables_bin} -L -n; ${iptables_bin} -t filter -L -n; } > "${dump_dir}/iptables.txt")
|
||||||
last_rc=$?
|
last_rc=$?
|
||||||
|
|
||||||
if [ ${last_rc} -eq 0 ]; then
|
if [ ${last_rc} -eq 0 ]; then
|
||||||
|
@ -450,7 +447,8 @@ task_iptables() {
|
||||||
else
|
else
|
||||||
debug "* iptables ERROR"
|
debug "* iptables ERROR"
|
||||||
debug "${last_result}"
|
debug "${last_result}"
|
||||||
rc=10
|
# Ignore errors because we don't know if this is nft related or a real error
|
||||||
|
# rc=10
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
debug "* iptables not found"
|
debug "* iptables not found"
|
||||||
|
@ -467,11 +465,26 @@ task_iptables() {
|
||||||
else
|
else
|
||||||
debug "* iptables-save ERROR"
|
debug "* iptables-save ERROR"
|
||||||
debug "${last_result}"
|
debug "${last_result}"
|
||||||
rc=10
|
# Ignore errors because we don't know if this is nft related or a real error
|
||||||
|
# rc=10
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
debug "* iptables-save not found"
|
debug "* iptables-save not found"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
nft_bin=$(command -v nft)
|
||||||
|
|
||||||
|
if [ -n "${nft_bin}" ]; then
|
||||||
|
last_result=$(${nft_bin} list ruleset > "${dump_dir}/nft-ruleset.txt")
|
||||||
|
last_rc=$?
|
||||||
|
|
||||||
|
if [ ${last_rc} -eq 0 ]; then
|
||||||
|
debug "* nft ruleset OK"
|
||||||
|
else
|
||||||
|
debug "* nft ruleset ERROR"
|
||||||
|
debug "${last_result}"
|
||||||
|
rc=10
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue