You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
OpenSnitch installs nftables rules using an inet table named opensnitch and uses NFQUEUE (e.g. queue ... flags bypass to 0).
I need to confirm whether OpenSnitch changes or interferes with existing firewall policies (firewalld and/or iptables),
and what happens after stopping or uninstalling OpenSnitch (whether the system returns to a clean state).
Why this matters
On servers with existing firewall rules (business allow/deny logic), it is critical to ensure that:
Existing firewalld / iptables rules keep working as before.
After systemctl stop opensnitchd, OpenSnitch does not continue intercepting traffic.
After deleting/uninstalling OpenSnitch, all nftables artifacts introduced by OpenSnitch are fully removed
(no leftover tables/chains/queues/hooks), and firewall behavior returns to normal.
Environment / Versions
OpenSnitch version: (e.g. 1.8.0)
OS: Rocky Linux
OS version: 9.7 (Blue Onyx)
Window Manager: (not required for this issue; optional)
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Describe the issue
OpenSnitch installs nftables rules using an
inettable namedopensnitchand uses NFQUEUE (e.g.queue ... flags bypass to 0).I need to confirm whether OpenSnitch changes or interferes with existing firewall policies (firewalld and/or iptables),
and what happens after stopping or uninstalling OpenSnitch (whether the system returns to a clean state).
Why this matters
On servers with existing firewall rules (business allow/deny logic), it is critical to ensure that:
firewalld/iptablesrules keep working as before.systemctl stop opensnitchd, OpenSnitch does not continue intercepting traffic.(no leftover tables/chains/queues/hooks), and firewall behavior returns to normal.
Environment / Versions
uname -aAdditional firewall environment:
iptables --version(if applicable)Evidence observed (nftables)
OpenSnitch created nftables rules similar to:
All reactions