-
-
Notifications
You must be signed in to change notification settings - Fork 425
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Found unexpected rule --comment '"CNI' #449
Comments
Same
root@udm0-office:/data/on_boot.d# ubnt-device-info summary; echo
Device information summary:
Subsystem ID: ea11
Family: UniFi Dream Machine (UDM)
Model: UniFi Dream Machine (UDM)
Default MAC address: (removed)
Default IPv4 address: 127.0.0.1
Firmware: 2.4.23 (2.4.23) |
This rule is created by the firewall CNI plugin. Make sure your CNI plugins are up to date and that you're not using firewall |
I'm not quite sure I understand what you are saying @boostchicken. Are you saying this isn't an issue of I installed the latest version of the CNI-plugins, i.e. |
Those rule are absolutely made by the CNI plugins, when and where I am not sure. |
To me it appears like unifi is checking
the iptables rules generated by CNI(?) don't have these IDs and have comments such as the following:
Currently I get the following warnings in
And since more containers mean more Currently these warnings don't do anything besides spamming the logs. Similar warnings were already noted in another issue: #49 I found a German blogpost detailing the same warnings (https://nerdig.es/udm-pro-netzwerktrennung-2/) and it states that the solution is to create |
You could open an issue in the CNI repo and send them a PR to fix it |
I sure could, if I was an expert in creating I still believe we need a note in Maybe the best way would be to have a |
Describe the bug
Checked
/var/log/messages
and every couple of seconds I get the error messageDream-Router ubios-udapi-server[3290]: firewall: Found unexpected rule --comment '"CNI'
.Checking
iptables -S | grep CNI
I see the following rules:To Reproduce
Steps to reproduce the behavior:
/var/log/messages
Expected behavior
I suppose there shouldn't be any error messages / unexpected rules? Or maybe this is related to Unifi not knowing about these rules?
UDM Information
The text was updated successfully, but these errors were encountered: