This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
docpublic:systemes:firewalld [2016/10/02 15:04] procacci@tem-tsp.eu created |
docpublic:systemes:firewalld [2019/04/17 06:46] (current) procacci@tem-tsp.eu [references] |
||
---|---|---|---|
Line 9: | Line 9: | ||
* https:// | * https:// | ||
* https:// | * https:// | ||
+ | * https:// | ||
- | ==== commands | + | ==== install |
+ | < | ||
+ | |||
+ | # yum install firewalld firewall-config | ||
+ | # systemctl start firewalld.service | ||
+ | # | ||
+ | # firewall-cmd --get-active-zones | ||
+ | # firewall-cmd --get-services | ||
+ | # firewall-cmd --zone=public --list-all | ||
+ | # firewall-cmd --get-zones | ||
+ | # firewall-cmd --get-default-zone | ||
+ | # firewall-cmd --list-all-zones | ||
+ | |||
+ | </ | ||
+ | |||
+ | ==== fichiers ==== | ||
+ | |||
+ | < | ||
+ | # cat / | ||
+ | # ls / | ||
+ | # cat / | ||
+ | |||
+ | </ | ||
+ | |||
+ | ==== lier une interface a une zone ==== | ||
+ | |||
+ | < | ||
+ | # firewall-cmd --get-zone-of-interface=eth0 | ||
+ | # | ||
+ | # | ||
+ | # grep eth0 / | ||
+ | < | ||
+ | |||
+ | </ | ||
+ | |||
+ | ==== gestion de services simples ==== | ||
+ | |||
+ | ajout httpd et retait ssh pour tous | ||
+ | < | ||
+ | |||
+ | # | ||
+ | # firewall-cmd --zone=public --remove-service=ssh --permanent | ||
+ | # firewall-cmd --reload | ||
+ | # firewall-cmd --list-all | ||
+ | </ | ||
+ | |||
+ | ==== gestion de regles complexes ==== | ||
+ | |||
+ | afin d' | ||
+ | < | ||
+ | # firewall-cmd --permanent --add-rich-rule 'rule family=" | ||
+ | # | ||
+ | # | ||
+ | # firewall-cmd --permanent --add-rich-rule 'rule family=" | ||
+ | # firewall-cmd --reload | ||
+ | </ | ||