Search icon CANCEL
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Learning RHEL Networking

You're reading from   Learning RHEL Networking Gain Linux administration skills by learning new networking concepts in Red Hat Enterprise Linux 7

Arrow left icon
Product type Paperback
Published in Jun 2015
Publisher
ISBN-13 9781785287831
Length 216 pages
Edition 1st Edition
Arrow right icon
Toc

Table of Contents (13) Chapters Close

Preface 1. Introducing Enterprise Linux 7 FREE CHAPTER 2. Configuring Network Settings 3. Configuring Key Network Services 4. Implementing iSCSI SANs 5. Implementing btrfs 6. File Sharing with NFS 7. Implementing Windows Shares with Samba 4 8. Integrating RHEL 7 into Microsoft Active Directory Domains 9. Deploying the Apache HTTPD Server 10. Securing the System with SELinux 11. Network Security with firewalld Index

Using rich rules


The firewalld rich language allows an administrator to easily configure more complex firewall rules without having knowledge of the iptables syntax. This can include logging and examination of the source address.

To add a rule to allow NTP connection on the default zone, but logging the connection at no more than 1 per minute, use the following command:

# firewall-cmd --permanent \
--add-rich-rule='rule service name="ntp" audit limit value="1/m" accept'
# firewall-cmd --reload

Similarly, we can add a rule that only allows access to the squid service from one subnet only:

# firewall-cmd --permanent \
--add-rich-rule='rule family="ipv4" \ 
source address="192.166.0.0/24" service name="squid" accept'
# firewall-cmd --reload

From the following screenshot, we can see the rich rule being added:

Note

The Fedora project maintains the documentation for rich rules in firewalld and these can be accessed at https://fedoraproject.org/wiki/Features/FirewalldRichLanguage should you need...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €18.99/month. Cancel anytime