Chapter 29. Networking
arptablescomponent, BZ#1018135- Red Hat Enterprise Linux 7 introduces the arptables packages, which replace the arptables_jf packages included in Red Hat Enterprise Linux 6. All users of arptables are advised to update their scripts because the syntax of this version differs from arptables_jf.
rsynccomponent, BZ#1082496- The
rsyncutility cannot be run as a socket-activated service because thersyncd@.servicefile is missing from the rsync package. Consequently, thesystemctl start systemd.socketcommand does not work. However, runningrsyncas a daemon by executing thesystemctl start systemd.servicecommand works as expected. opensslcomponent, BZ#1062656- It is not possible to connect to any Wi-Fi Protected Access (WPA) Enterprise Access Point (AP) that requires MD5-signed certificates. To work around this problem, copy the
wpa_supplicant.servicefile from the/usr/lib/systemd/system/directory to the/etc/systemd/system/directory and add the following line to theServicesection of the file:Environment=OPENSSL_ENABLE_MD5_VERIFY=1
Environment=OPENSSL_ENABLE_MD5_VERIFY=1Copy to Clipboard Copied! Toggle word wrap Toggle overflow Then run thesystemctl daemon-reloadcommand as root to reload the service file.Important
Note that MD5 certificates are highly insecure and Red Hat does not recommend using them. bindcomponent, BZ#1004300- Previously,
named-chroot.serviceset up thechrootenvironment for thenameddaemon by mounting the necessary files and directories to the/var/named/chroot/path before starting the daemon. However, if the startup of the daemon failed, the mounts remained mounted. As a consequence, thechrootenvironment was corrupted. This also affectednamed-sdb-chroot.service, which used the samechrootpath. With this update,named-chroot.serviceandnamed-sdb-chroot.servicehave been modified and thechrootset up code has been separated into two newsystemdservices,named-chroot-setup.serviceandnamed-sdb-chroot-setup.service. In addition, thenamed-sdbdaemon now uses its ownchrootpath,/var/named/chroot_sdb/. Also,named-sdbdaemon has been removed from the bind-chroot package and is now included in its own bind-sdb-chroot subpackage. Users who usenamed-sdbin thechrootenvironment are advised to install the bind-sdb-chroot package. bind-dyndb-ldapcomponent, BZ#1078295- The
bind-dyndb-ldapplug-in does not fully support the DNS64 server. As a consequence, theBINDdaemon configured with DNS64 terminates unexpectedly when a DNS64 query is processed bybind-dyndb-ldap. To work around this problem, disable DNS64 in thenamed.conffile. The whole section concerning DNS64 can be commented out. openswitchcomponent, BZ#1066493- In certain cases, when connecting two network interface controllers (NIC) that use the
ixgbedriver, the TCP stream throughput does not exceed 8.4 GB. This problem manifests itself both on a NIC to NIC level, although to a very limited degree, as well as in combination with virtual machines running on top of an openvswitch bridge. vsftpdcomponent, BZ#1058712- The
vsftpddaemon does not currently support ciphers suites based on the ECDHE key-assignment protocol. Consequently, when vsftpd is configured to use such suites, the connection is refused with ano shared cipherSSL alert. fcoe-utilscomponent, BZ#1049200- The
-m vn2vnoption of thefcoeadmcommand does not work correctly, and Fabric mode is always used instead of "vn2vn". As a consequence, a vn2vn instance cannot be created usingfcoeadm, and the port state is offline instead of online. To work around this problem, modify thesysfsfile manually to create a vn2vn link. NetworkManagercomponent, BZ#1030947- The
brctl addbr namecommand, which is used for creating a new instance of an Ethernet bridge, also brings the interface up. Consequently, thebrctl delbr namecommand does not delete the instance of an Ethernet bridge because the network interface corresponding to the bridge is not down. To work around the problem:- Either bring the instance down by using the
ip link set dev name downcommand before running thebrctl delbr namecommand; - Or use the
ip link del namecommand for deleting the instance.