[CentOS] ipset-service save fails when module compiled into kernel

Kenneth Porter

shiva at sewingwitch.com
Sat Sep 15 02:29:26 UTC 2018


I want to use the ipset-service to store ipsets persistently across boots. 
(For use by iptables rules. firewalld has direct support for persistent 
ipsets but I need the more general capability of raw iptables.)

I'm using a kernel with ipsets compiled in, rather than loaded as a module. 
The support script that saves ipsets checks if the module is loaded before 
saving and finds nothing, so aborts. Why does it need to make this check?

Should this package be able to handle a custom kernel with compiled-in 
modules?

(I'm actually running CentOS 7 on a Linode VM with the default Linode 
kernel. Their kernel has modules compiled in and listed in /proc/config.gz.)

For reference, here's the latest Rawhide package containing the 
ipset.start-stop script that's used to save ipsets persistently.

<https://fedora.pkgs.org/rawhide/fedora-x86_64/ipset-service-6.38-1.fc29.noarch.rpm.html>




More information about the CentOS mailing list