Summary
The firewalld
project is maintained by Fedora and is the new administrative service and interface for the netfilter
firewall on the Linux Kernel. As administrators, we can choose to use this default service or switch back to iptables
; however, firewalld
is able to provide us with the ability to reload configuration without dropping connections and mechanisms to migrate from iptables
. We have seen how we can use zones to segregate network interfaces and sources if we need to share address ranges on a single NIC. Neither the NIC nor the source is bound to the zone. We can then add rules to a zone to control access to our resources. These rules are based on services or ports. If more complexity is required, we have the option of using rich or direct rules. Rich rules are written in the rich language from firewalld
, whereas direct rules are written in the iptables
syntax.