Release of the firewalld 1.2 firewall

The release of the dynamically managed firewall firewalld 1.2 has been announced, implemented as a wrapper over the packet filters nftables and iptables. Firewalld runs as a background process, allowing dynamic modification of packet filter rules via D-Bus, without the need to reload the filter rules and without interrupting established connections. The project is already being used in many Linux distributions, including RHEL 7+, Fedora 18+, and SUSE/openSUSE 15+. The firewalld code is written in Python and is distributed under the GPLv2 license.

The firewall is managed using the utility firewall-cmd, which creates rules based not on (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community., network interfaces, and port numbers, as well as service names (for instance, to allow SSH access, one would execute "firewall-cmd --add --service=ssh", and to close SSH access -- "firewall-cmd --remove --service=ssh"). The firewall configuration can also be modified using the firewall-config graphical interface (GTK) and the firewall-applet (Qt). Support for managing the firewall via the D-BUS API firewalld is available in projects such as NetworkManager, libvirt, podman, docker, and fail2ban.

Key Changes:

  • The services snmptls and snmptls-trap have been implemented to handle access to the SNMP protocol through a secure communication channel.
  • A service supporting the protocol used in the decentralized file system IPFS has been implemented.
  • Services supporting gpsd, ident, ps3netsrv, CrateDB, checkmk, netdata, Kodi JSON-RPC, EventServer, Prometheus node-exporter, kubelet-readonly, and a secure version of the k8s controller-plane have been added.
  • The "--log-target" parameter has been added.
  • A failsafe mode has been introduced, allowing a rollback to the default configuration in the event of issues with the specified rules, ensuring the host remains protected.
  • For bash, support has been provided for command autocompletion for working with rules.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster