LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 06-16-2017, 04:19 PM   #1
jnojr
Member
 
Registered: Sep 2007
Location: Chandler, AZ
Posts: 227

Rep: Reputation: 20
firewalld - multiple services / sources?


If you have a system with one network interface, and you want to allow ssh from some addresses, freeipa-ldap from others, and https (which is part of freeipa-ldap) from another one; and you do not want to have a sea of rich rules... how do you do that?

I can't tell if firewalld is just really poorly documented or very limited. I am sorely tempted to disable it and just use good ol' iptables, but I don't like the kneejerk "Just disable it!" attitude, partly because one day there'll be something that you have to do "the new way", and you'll be far behind the curve.
 
Old 06-16-2017, 07:26 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,345
Blog Entries: 28

Rep: Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145
Quote:
If you have a system with one network interface, and you want to allow ssh from some addresses, freeipa-ldap from others, and https (which is part of freeipa-ldap) from another one; and you do not want to have a sea of rich rules.
I've never used firewalld, but I have used the firewall script from the now-defunct Project Files project (he said redundantly).

Please don't take this the wrong way, but, given the multiple and diverse requirements you list, I suspect you would be in for a sea of rules regardless of the method you select for configuring iptables, as you seems to have a lake, if not a sea, of requirements.
 
Old 06-19-2017, 09:40 AM   #3
jnojr
Member
 
Registered: Sep 2007
Location: Chandler, AZ
Posts: 227

Original Poster
Rep: Reputation: 20
Quote:
Originally Posted by frankbell View Post
Please don't take this the wrong way, but, given the multiple and diverse requirements you list, I suspect you would be in for a sea of rules regardless of the method you select for configuring iptables, as you seems to have a lake, if not a sea, of requirements.
Not really. It's pretty common to not want to expose management functions to clients. In my case, all clients should be able to hit LDAP and Kerberos, and one or two management stations should have access to the IdM GUI, and one or two to have shell access to the OS. Anyone who isn't breaking things out like that is begging for trouble.

It turns out you can point rich rules at a service instead of a port, so that helps to keep things manageable.
 
Old 06-19-2017, 02:42 PM   #4
lazydog
Senior Member
 
Registered: Dec 2003
Location: The Key Stone State
Distribution: CentOS Sabayon and now Gentoo
Posts: 1,249
Blog Entries: 3

Rep: Reputation: 194Reputation: 194
You might want to combined IPTABLES with IPSET. Or you could compartmentalize your rules. Without knowing how many IP Address you are talking about and what you want to allow where it's kind of hard give a good answer.
 
Old 06-20-2017, 08:23 PM   #5
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,345
Blog Entries: 28

Rep: Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145
Quote:
Not really. It's pretty common to not want to expose management functions to clients.
Agreed, and I understand the need for a complex ruleset in a business environement; the headlines every day point out that more businesses should give thought to this issue.

My only point was that it looked to be a relatively complex ruleset regardless of the means used to configure iptables.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how firewallD start on startup in fedora 17 - System Security Services Demon fails 100201 Fedora 1 07-12-2012 04:15 AM
Multiple sources for Icecast...? resetreset Linux - Software 6 01-25-2011 07:29 PM
multiple sources with iptables doronunu Linux - Security 4 06-05-2006 01:27 AM
Sound from multiple sources Adrohak Linux - Software 5 05-01-2005 10:40 AM
gdb and multiple sources melinda_sayang Programming 0 04-03-2004 09:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:03 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration