Kickstarts all contain:

firewall --disabled
selinux --disabled

I even went as far as this:

[stuff deleted]


[stuff deleted]
/sbin/chkconfig iptables off
/sbin/chkconfig ip6tables off
echo '#' > /etc/sysconfig/iptables
echo '#' > /etc/sysconfig/ip6tables
echo '#' > /etc/sysconfig/iptables-config
echo '#' > /etc/sysconfig/ip6tables-config
echo "#\n--disabled" > /etc/sysconfig/system-config-firewall

What happens is that /etc/sysconfig/iptables, /etc/sysconfig/iptables,
and /etc/sysconfig/system-config-firewall ALWAYS get recreated AFTER
%post runs!

That causes the iptables kernel modules to load, and filtering started,
even though iptables is actually configured for off and does not start.

What is doing that? I cannot find it.

Any help is appreciated.

