This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
|
docpublic:systemes:firewalld [2016/10/02 15:04] procacci@tem-tsp.eu created |
docpublic:systemes:firewalld [2019/04/17 06:46] (current) procacci@tem-tsp.eu [references] |
||
|---|---|---|---|
| Line 9: | Line 9: | ||
| * https:// | * https:// | ||
| * https:// | * https:// | ||
| + | * https:// | ||
| - | ==== commands | + | ==== install |
| + | < | ||
| + | |||
| + | # yum install firewalld firewall-config | ||
| + | # systemctl start firewalld.service | ||
| + | # | ||
| + | # firewall-cmd --get-active-zones | ||
| + | # firewall-cmd --get-services | ||
| + | # firewall-cmd --zone=public --list-all | ||
| + | # firewall-cmd --get-zones | ||
| + | # firewall-cmd --get-default-zone | ||
| + | # firewall-cmd --list-all-zones | ||
| + | |||
| + | </ | ||
| + | |||
| + | ==== fichiers ==== | ||
| + | |||
| + | < | ||
| + | # cat / | ||
| + | # ls / | ||
| + | # cat / | ||
| + | |||
| + | </ | ||
| + | |||
| + | ==== lier une interface a une zone ==== | ||
| + | |||
| + | < | ||
| + | # firewall-cmd --get-zone-of-interface=eth0 | ||
| + | # | ||
| + | # | ||
| + | # grep eth0 / | ||
| + | < | ||
| + | |||
| + | </ | ||
| + | |||
| + | ==== gestion de services simples ==== | ||
| + | |||
| + | ajout httpd et retait ssh pour tous | ||
| + | < | ||
| + | |||
| + | # | ||
| + | # firewall-cmd --zone=public --remove-service=ssh --permanent | ||
| + | # firewall-cmd --reload | ||
| + | # firewall-cmd --list-all | ||
| + | </ | ||
| + | |||
| + | ==== gestion de regles complexes ==== | ||
| + | |||
| + | afin d' | ||
| + | < | ||
| + | # firewall-cmd --permanent --add-rich-rule 'rule family=" | ||
| + | # | ||
| + | # | ||
| + | # firewall-cmd --permanent --add-rich-rule 'rule family=" | ||
| + | # firewall-cmd --reload | ||
| + | </ | ||