Config firewall » Historie » Version 1
Jeremias Keihsler, 13.01.2017 12:13
1 | 1 | Jeremias Keihsler | h1. Configure firewall |
---|---|---|---|
2 | |||
3 | h2. Requirements |
||
4 | |||
5 | To configure Firewall you will need the following: |
||
6 | * a installed and supported operating system (e.g. CentOS 6.x) |
||
7 | * root-access |
||
8 | |||
9 | h2. Preliminary Note |
||
10 | |||
11 | It is good practice to open only those ports needed. |
||
12 | |||
13 | h2. Configure |
||
14 | |||
15 | <pre><code class="bash"> |
||
16 | system-config-firewall-tui |
||
17 | </code></pre> |
||
18 | |||
19 | Main-Page, this is the place to enable/disable the firewall, via @Customize@ you can alter the configuration |
||
20 | |||
21 | !{width 500}system-config-firewall-tui-1.png! |
||
22 | |||
23 | The @Trusted Service@ page allows to open common ports for incoming connections, e.g. @22 SSH@ |
||
24 | |||
25 | !{width 500}system-config-firewall-tui-2.png! |
||
26 | |||
27 | Ports not being listed in the @Trusted Services@ might be opened here, e.g. @5432 PostgreSQL@ |
||
28 | |||
29 | !{width 500}system-config-firewall-tui-3.png! |
||
30 | |||
31 | If you trust all participants on a specific network-interface, you can mark them here: |
||
32 | |||
33 | !{width 500}system-config-firewall-tui-4.png! |
||
34 | |||
35 | Same goes with @Masquerading@ |
||
36 | |||
37 | !{width 500}system-config-firewall-tui-5.png! |
||
38 | |||
39 | @Portforwarding@ usually goes with @Masquerading@ |
||
40 | |||
41 | !{width 500}system-config-firewall-tui-6.png! |
||
42 | |||
43 | If you want to ignore certain ICMP types, e.g. Ping, this is the place |
||
44 | |||
45 | !{width 500}system-config-firewall-tui-7.png! |
||
46 | |||
47 | Anything not being covered in the previous screens might be entered here |
||
48 | |||
49 | !{width 500}system-config-firewall-tui-8.png! |
||
50 | |||
51 | After doing some changes to the configuration you will be asked to confirm the changes. |
||
52 | |||
53 | !{width 500}system-config-firewall-tui-9.png! |
||
54 | |||
55 | It is always worth double check the configuration by |
||
56 | <pre><code class="bash"> |
||
57 | service iptables status |
||
58 | </code></pre> |
||
59 | or |
||
60 | <pre><code class="bash"> |
||
61 | cat /etc/sysconfig/system-config-firewall |
||
62 | </code></pre> |
||
63 | or |
||
64 | <pre><code class="bash"> |
||
65 | cat /etc/sysconfig/iptables |
||
66 | </code></pre> |