Skip to main content

Command Palette

Search for a command to run...

Firewall

Updated
•5 min read•View as Markdown
Firewall

What is Firewall

  • A wall that prevents the spread of fire

  • When data moves in and out of a server its packet information is tested against the firewall rules to see it should be allowed or not.

  • In simple words, a firewall is like a watchmen, a bouncer or a shield that has a set of rules given and based on that rule they decide who can enter and leave.

  • There are 2 type of firewalls in IT

    • Software - Runs on operating system

    • Hardware - A dedicated appliance with firewall software

Here, Firewall is setup on server A and B, When we do SSH to server B from server A it will check the protocol(rule) from server A is allowed to come in on port 22 and that rule says, yes, this server can come in.

Another example would be I want to do FTP that runs on port 21, before it established connection with server B, It goes to the firewall and firewall rule says on server B that a server A is not allowed to come in using protocol or service FTP.

Note: Firewall is sitting in the middle i.e., Firewall is sitting on server A as well as server B.
Server A who wants to connect to server B could also have a rule whether this service is even is allowed to leave the server or not and then when it goes to server B, the server B has its own firewall, It checked service is allowed to accepted or not.

Tool to manage Firewall

  • There are 2 tools to manage firewall in most of the Linux distributions

    • iptables - For older Linux versions

    • firewalld - For newer versions like RHEL 7 and higher version

  • We can use one of them to manage the firewall

    • Ensure firewall is not running and disable. If iptables is in used and vice-versa.

    • Commands to disble the firewall

        systemctl stop firewalld    # To stop the service
        systemctl disable firewalld # To prevent from starting at boot time 
        systemctl mask firewalld    # To prevent it from running by other programs
      

Check whether iptables-services package installed

rpm -qa | grep iptables-service  # To check whether it installed or not in RHEL
dpkg -l | grep iptables          # To check whether it installed or not in ubuntu  
yum install iptables-service     # To install 
systemctl start iptables         # To start the service 
systemctl enable iptables        # To start when system reboots
iptables -L                      # To check iptables rules
iptables -F                      # To flush iptables

Function of iptables tool

  • iptables tool is packet filtering

  • The packet filtering mechanism is organized into three different kind of struturces: tables, chains and targets

    1. tables - tables is something that allows you to process packets in specific ways.
      There are 4 different types of tables, filter, mangle, nat and raw.

    2. chains - The chains are attached to tables, These chains allow you to inspect traffic at various points.

      • There are 3 main chains used in iptables

        • INPUT - incoming traffic

        • FORWAD - going to router, from one device to another

        • OUTPUT - outgoing traffic

          • chains allow you to filter traffic by adding rules to them

          • Rule - If traffic is coming from 192.168.1.35 then go to defined target

    3. targets - target decides the fate of a packet, such as allowing or rejecting it. There are 3 different type of targets

      • ACCEPT - connection accepted

      • REJECT - send reject response

      • DROP - drop connection without sending my response

Firewall

  • Firewall works the same way as iptables but of course it has it own commands
firewall-cmd
  • It has a few pre-defined service rules that are very easy to turn on and off

    • Service such as NFS, NTP, HTTPD etc.
  • Firewalld also has the following:

    • Table

    • Chains

    • Rules

    • Targets

To Enable the firewall service, ensure the iptables is stopped, disabled and mask

systemctl stop iptables
systemctl disable iptables
systemctl mask iptables

rpm -qa | grep firewalld  
systemctl start/enable firewalld

firewall-cmd --list-all      # Check the rule of firewall i.e., service which in active
firewall-cmd --get-service   # Lists the all services of firewall
firewall-cmd --reload        # To undo or re-read config. added

firewall-cmd --get-zones                # List of all zones
firewall-cmd --get-active-zones         # List of active zonees
firewall-cmd --zone=public --list-all   # List the public zone  
firewall-cmd --list-all
  • All service are pre-defined by firewalld. If we want to add a 3rd party sevice then

    • path /usr/lib/firewalld/services/allservices.xml
      Here, simply cp any .xml file and change the service, description and port name.
      Ex. cp ssh.xml sap.xml
      Now sap.xml file is created in this file change service i.e, short tag name is as sap,
      description tag provide description of service,
      port protocol tag define port number and protocol need to used.

  • Commands to add/remove a service, to add 3rd party services

      firewall-cmd --add-service=http                # To add a service
      firewall-cmd --remove-service=http             # To remove a service
      firewall-cmd --reload                          # To reload config. or undo previous change
      firewall-cmd --add-service=http --permanent    # To add a service permanently 
      firewall-cmd --remove-service=http --permanent # To remove a service permanently
    
      # To add 3rd party services
      /usr/lib/firewalld/services/                   # Path
      cp ssh.xml sap.xml                             # Copy any existing xml to new xml file and change values as mentioned above
      systemctl restart firewalld
      firewall-cmd --get-service                     # To verify new service
      firewall-cmd --add-service=sap                 # To add a service   
      firewall-cmd --add-port=1110/tcp               # To add a port
      firewall-cmd --remove-port=1110/tcp            # To remove a port
      # To reject incoming traffic from an IP address
      firewall-cmd --add-rich-rule='rule family="ipv4" source address="192.168.0.25" reject'
      # To block and unblock ICMP incoming traffic i.e, PING when ping connection will not establish
      firewall-cmd --add-icmp-block-inversion
      firewall-cmd --remove-icmp-block-inversion
      # To block outgoing traffic to a specific website/IP address
      host -t a www.facebook.com                   # It will find the IP
      firewall-cmd --direct --add-rule ipv4 filter OUTPUT 0 -d 31.13.71.26 -j DROP
      # To unblock outgoing traffic of a specific website/IP address
      firewall-cmd --reload
      systemctl restart firewalld
      ping 31.13.71.26
    

Hope Firewalld concept as clear.