Firewall Flashcards
where are system-defined zone rules stored
/usr/lib/firewalld/zones
where are user-defined zone rules stored
/etc/firewalld/zones
status of firewalld
sudo firewall-cmd –state
determin the name of the current default zone
sudo firewall-cmd –get-default-zone
add permanent rule to allow http
sudo firewall-cmd –permanent –add-service http
sudo firewall-cmd –reload
sudo firewall-cmd –list-services
see services running
sudo firewall-cmd –list-services
or
cat /etc/firewalld/zones/public.xml
add permanent rule for internal zone with a TCP port range 5901-5910
sudo firewall-cmd –add-port 5901-5910/tcp –permanent –zone internal
sudo firewall-cmd –reload
change default zone
sudo firewall-cmd –set-default-zone internal
confirm:
sudo firewall-cmd –get-default-zone
remove http from public zone
sudo firewall-cmd –remove-service=http –zone public –permanent