diff options
Diffstat (limited to 'man/systemd.network.xml')
-rw-r--r-- | man/systemd.network.xml | 16 |
1 files changed, 9 insertions, 7 deletions
diff --git a/man/systemd.network.xml b/man/systemd.network.xml index ea558c4b4e..1f30cc13b3 100644 --- a/man/systemd.network.xml +++ b/man/systemd.network.xml @@ -1342,13 +1342,15 @@ Table=1234</programlisting></para> Fallback Peer Labeling</ulink> rules. They will be removed when the interface is deconfigured. Failures to manage the labels will be ignored.</para> - <para>Warning: Once labeling is enabled for network traffic, a lot of LSM access control points in - Linux networking stack go from dormant to active. Care should be taken to avoid getting into a - situation where for example remote connectivity is broken, when the security policy hasn't been - updated to consider LSM per-packet access controls and no rules would allow any network - traffic. Also note that additional configuration with <citerefentry - project='man-pages'><refentrytitle>netlabelctl</refentrytitle><manvolnum>8</manvolnum></citerefentry> - is needed.</para> + <warning> + <para>Once labeling is enabled for network traffic, a lot of LSM access control points in + Linux networking stack go from dormant to active. Care should be taken to avoid getting into a + situation where for example remote connectivity is broken, when the security policy hasn't been + updated to consider LSM per-packet access controls and no rules would allow any network + traffic. Also note that additional configuration with <citerefentry + project='man-pages'><refentrytitle>netlabelctl</refentrytitle><manvolnum>8</manvolnum></citerefentry> + is needed.</para> + </warning> <para>Example: <programlisting>[Address] |