INT-firewalld konfiguration
From Datateknik
(Difference between revisions)
(→Skapa nya zoner) |
(→Lägg till tjänster) |
||
Line 20: | Line 20: | ||
sudo firewall-cmd --zone=allihopa --add-service=http | sudo firewall-cmd --zone=allihopa --add-service=http | ||
sudo firewall-cmd --zone=allihopa --add-service=https | sudo firewall-cmd --zone=allihopa --add-service=https | ||
+ | firewall-cmd --runtime-to-permanent | ||
firewall-cmd --reload | firewall-cmd --reload | ||
Line 25: | Line 26: | ||
firewall-cmd --zone=kompisar --list-all | firewall-cmd --zone=kompisar --list-all | ||
firewall-cmd --zone=allihopa --list-all | firewall-cmd --zone=allihopa --list-all | ||
+ | |||
= Överkurs = | = Överkurs = | ||
'''firewall-cmd --direct --get-all-rules''' | '''firewall-cmd --direct --get-all-rules''' | ||
ipv4 filter INPUT 0 -m state --state NEW -j LOG '--log-prefix=RobLog ' | ipv4 filter INPUT 0 -m state --state NEW -j LOG '--log-prefix=RobLog ' |
Revision as of 13:42, 10 May 2017
Nedanstående fungerar ej!
Contents |
Skapa nya zoner
When adding a zone, you must add it to the permanent firewall configuration. You can then reload to bring the configuration into your running session. For instance, we could create the two zones we discussed above by typing:
firewall-cmd --permanent --new-zone=kompisar firewall-cmd --permanent --new-zone=allihopa firewall-cmd --permanent --zone=drop --change-interface=ens160 firewall-cmd --reload firewall-cmd --permanent --get-zones
Lägg in vilka nät
firewall-cmd --permanent --zone=kompisar --add-source=193.10.128.0/17 firewall-cmd --permanent --zone=kompisar --add-source=212.25.132.0/23 firewall-cmd --reload
Lägg till tjänster
sudo firewall-cmd --zone=kompisar --add-service=ssh sudo firewall-cmd --zone=allihopa --add-service=http sudo firewall-cmd --zone=allihopa --add-service=https firewall-cmd --runtime-to-permanent firewall-cmd --reload firewall-cmd --zone=kompisar --list-all firewall-cmd --zone=allihopa --list-all
Överkurs
firewall-cmd --direct --get-all-rules ipv4 filter INPUT 0 -m state --state NEW -j LOG '--log-prefix=RobLog '