On 03/02/2011 04:55 PM, edison wrote:
There is a bug in
netcf-libs(https://bugzilla.redhat.com/show_bug.cgi?id=651032), which
automatically sets "-A FORWARD -m physdev --physdev-is-bridged -j
ACCEPT " if /proc/sys/net/bridge/bridge-nf-call-iptables == 1.
I hit the bug last week, which drove me crazy...
As of netcf-0.1.7, netcf no longer reads or modifies any iptables
information. This scenario is one of several reasons that functionality
was removed.