- Subject: Iptables "-m time" option doesn't update when the clock changes
- From: Sebastian Arcus <shop@xxxxxxxxxxxx>
- Date: Thu, 29 Mar 2012 10:10:18 +0100
- User-agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.15) Gecko/20110323 Lightning/1.0b2 Thunderbird/3.1.9
I'm using the following line in my iptables firewall to block internet
access for one of the machines on the network for one hour a day:
Code:
iptables -A FORWARD -p ALL -o $INET_IFACE -m mac --mac-source
$BLOCKED_MAC1 -m time --timestart $BLOCKED_TIMESTART1 --timestop
$BLOCKED_TIMESTOP1 -j DROP
Everything works fine - except that when the clocks change from winter
time to summer time (in UK) - the rule keeps on working on the old time.
The clock of this server (checked with "date") updates correctly. If I
restart the server - the rule finally starts working on the correct
time. Last year when this happened, I posted here and I was advised to
change the hardware clock to UTC (from local time) - which I did.
However, now that the clock just changed again from winter time to
summer time - the user is complaining again that their Internet access
slot is off by an hour.
Does anybody know why is this happening?
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
[Linux Netfilter Development]
[Linux Kernel Networking Development]
[Linux Networking Development]
[Linux Kernel Development]
[Linux Resources]
[LARTC]
[Bugtraq]
[Consulting]
[Free Internet Dating]
[Yosemite Forum]
[Photo]