Chapter 14. Building a Linux Firewall with firewalld
This chapter covers the basics of using firewalld to build host firewalls. Individual hosts have different requirements. For example, a server has to allow different types of incoming connection requests, and a PC running no services does not have to accept any connection requests. A laptop that is used to access multiple networks needs dynamic firewall management.
firewalld Overview
firewalld, like all firewalls, has a very long list of capabilities. We will mainly learn about using firewalld zones to control traffic entering our systems. A zone is a container for a level of trust; for example, some zones allow all manner of incoming connection requests, and some are very restrictive. Each network interface on a system may be assigned only one zone, and one zone may be assigned to multiple interfaces.
Networking Knowledge Required
The most important networking concepts to understand are ports, services, TCP, UDP, port forwarding, masquerade, routing, and IP addressing. You will understand how to configure your firewall when you understand these. If you need some coaching on computer networking, try Networking Fundamentals by Gordon Davies (Packt Publishing), or Networking All-in-One For Dummies, 7th Edition by Doug Lowe (For Dummies). If you have an O’Reilly Learning Platform subscription, you will find a wealth of great information.
The traditional Linux firewall is built with the netfilter packet-filtering framework in ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access