Re: [CentOS] CentOS 7 SELinux issue

2016-02-25 Thread Brandon Vincent
On Thu, Feb 25, 2016 at 12:34 AM, Frank Cox wrote: > Turns out you get the "Could not downgrade policy file > /etc/selinux/targeted/policy/policy.24" error if you're running with SELinux > disabled and something tries to install or reload policy: semodule -vR does > it. This is why if anyone i

Re: [CentOS] CentOS 7 SELinux issue

2016-02-25 Thread Steve Snyder
On 02/25/2016 07:23 AM, Brandon Vincent wrote: On Thu, Feb 25, 2016 at 12:34 AM, Frank Cox wrote: Turns out you get the "Could not downgrade policy file /etc/selinux/targeted/policy/policy.24" error if you're running with SELinux disabled and something tries to install or reload policy: semo

Re: [CentOS] IPtables block user from outbound ICMP

2016-02-25 Thread Always Learning
On Thu, 2016-02-25 at 07:19 +, James Hogarth wrote: > Well if you really want to call it a problem... Blocking ICMP via a host > based firewall remains pretty silly. On all servers I used IPtables to block (DROP) all incoming ICMPs except:- type 0 state RELATED,ESTABLISHED type 3 state REL