Release of the firewalld version 2.2.0

The release of the dynamically managed firewall firewalld 2.2 has been formed, implemented as a wrapper over the packet filters nftables and iptables. Firewalld runs as a background process, allowing dynamic changes to the packet filter rules via D-Bus, without needing to reload the packet filter rules and without disrupting established connections. The project is already used in many Linux distributions, including RHEL 7+, Fedora 18+, and SUSE/openSUSE 15+. The firewalld code is written in Python and is distributed under the GPLv2 license.

The firewall is managed using the utility firewall-cmd, which creates rules based not on (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community., network interfaces and port numbers, but rather on service names (for example, to allow access to SSH, you need to run "firewall-cmd --add --service=ssh", and to close SSH — "firewall-cmd --remove --service=ssh"). The graphical interface firewall-config (GTK) and the applet firewall-applet (Qt) can also be used to modify the firewall configuration. Support for managing the firewall via the D-BUS API of firewalld is available in projects such as NetworkManager, libvirt, podman, docker, and fail2ban.

Key changes:

  • Services have been added to support STUN and STUNS protocols.
  • A service for Steam traffic in the local network has been added.
  • A service for the MNDP (MikroTik Neighbor Discovery Protocol) has been added.
  • A service for file server XRootD.
  • A service for the WS-Discovery (Web Services Dynamic Discovery) protocol has been added.
  • Services for network activity of the bandwidth measuring tools iperf2 and iperf3 have been added.
  • Using tables with the flags 'owner' and 'persist' in nftables has been allowed.
  • Support for rpfilter (Reverse Path Filter) operating modes has been added: strict-forward, loose-forward, and loose.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster