sergiomb
(SĂ©rgio M. Basto)
January 23, 2021, 6:17pm
1
How I disabling firewall and just systemcl start iptables I did this [1] , I saw today that zone FedoraWorkstation can be good for me , but still need add ssh rules based on ips .
Thank you
[1]
iptables -I INPUT -p tcp --dport 22 --source 127.0.0.1 -j ACCEPT
iptables -I INPUT -p tcp --dport 22 --source 192.168.1.0/24 -j ACCEPT
iptables -I INPUT -p tcp --dport 22 --source extern_ip -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j DROP
[2]
firewall-offline-cmd --info-zone=FedoraWorkstation
FedoraWorkstation
target: default
icmp-block-inversion: no
interfaces:
sources:
services: dhcpv6-client samba-client ssh
ports: 1025-65535/udp 1025-65535/tcp
protocols:
masquerade: no
forward-ports:
source-ports:
icmp-blocks:
rich rules:
vgaetera
(Vladislav Grigoryev)
January 24, 2021, 1:50am
2
1 Like
sergiomb
(SĂ©rgio M. Basto)
January 25, 2021, 2:39am
3
How I do a reach rule for ssh , with 3 different ips 127.0.0.1, 192.168.1.0/24 and 193.126.232.45 ?
vgaetera
(Vladislav Grigoryev)
January 25, 2021, 3:13am
4
sudo firewall-cmd --set-default-zone=FedoraWorkstation
sudo firewall-cmd --permanent --remove-service ssh
sudo firewall-cmd --permanent --add-rich-rule="rule \
family=ipv4 source address=192.168.1.0/24 service name=ssh accept"
sudo firewall-cmd --permanent --add-rich-rule="rule \
family=ipv4 source address=193.126.232.45 service name=ssh accept"
sudo firewall-cmd --reload
Access from localhost is allowed by default.
1 Like
sergiomb
(SĂ©rgio M. Basto)
January 26, 2021, 10:05pm
5
thank you , seems that is working, just one more detail , and if I want delete the second rich-rule ? what I need to do ?
Many thanks for the help
1 Like
vgaetera
(Vladislav Grigoryev)
January 27, 2021, 2:17am
6
sudo firewall-cmd --permanent --zone=public --remove-rich-rule="rule \
family=ipv4 source address=193.126.232.45 service name=ssh accept"
sudo firewall-cmd --reload
system
(system)
Closed
March 27, 2021, 6:17pm
8
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.