at least there is one network interface configured with red role
Should I take that literally, meaning the firewall isn’t working on a single-interface NS ? (On which the single interface is assigned the green role)
(I will be using NS as a mail/file server, not as a gateway. But having a firewall on that server seems like a good idea…)
OK, so firewall mode is only enabled if firewall module is installed (duh), and gateway mode is enabled only if there is at least one red interface.
Sounds logical…