disabling qubes-network and qubes-firewall serivces not supported with debian 9?

23 views
Skip to first unread message

joonas....@openmailbox.org

unread,
Dec 21, 2017, 10:51:42 AM12/21/17
to qubes...@googlegroups.com
Hi,

I'm in the progress to migrate a custom fedora-based proxyVM to a debian 9 template,
because debian's longer support cycles.

On my fedora proxyVM I simply disabled
qubes-network and
qubes-firewall
to be in full control of the firewall rules and forwarding.

When I disable these services on the debian template it does not have
the same effect (i.e. /proc/sys/net/ipv4/ip_forward remains 1).

Is this feature
qvm-service proxyvm1 -d qubes-network
qvm-service proxyvm1 -d qubes-firewall
not supported on debian 9 templates or is it currently broken?

I'm on R3.2.

thanks,
Joonas

Unman

unread,
Dec 21, 2017, 1:11:35 PM12/21/17
to joonas....@openmailbox.org, qubes...@googlegroups.com
Hi Joonas,

The feature is supported but it looks to me as if the default template
(and I include Debian-8 here) has this set to 1 regardless. That looks
like a bug in the build process.

Worth downloading a clean template and checking on this before raising an
issue on GitHub.

unman

Reply all
Reply to author
Forward
0 new messages