firewalld 2.4.0 release

Firewalld 2.4.0, a dynamically managed firewall built around the nftables and iptables packet filters, has been released. Firewalld runs as a background process, allowing dynamic packet filter rule changes via D-Bus, without reloading packet filter rules or interrupting existing connections. The project is already being used in many distributions. Linux, including RHEL 7+, Fedora 18+, and SUSE/openSUSE 15+. The firewalld code is written in Python and distributed under the GPLv2 license.

To manage the firewall, the firewall-cmd utility is used, which does not rely on IP addresses, network interfaces, and port numbers, as well as service names (for example, to open SSH access, run "firewall-cmd --add --service=ssh"; to close SSH, run "firewall-cmd --remove --service=ssh"). The firewall-config graphical interface (GTK) and the firewall-applet (Qt) can also be used to change the firewall configuration. Support for firewall management via the firewalld D-BUS API is available in projects such as NetworkManager, libvirt, podman, docker, and fail2ban.

Key changes:

  • A "gateway" ruleset has been added, covering the functionality of a typical home router (including NAT, conntrack handlers, and inter-zone traffic redirection). An example of configuring a gateway with internal and external network interfaces using the "gateway" ruleset: firewall-cmd --permanent --zone internal --add-interface eth0 firewall-cmd --permanent --zone external --add-interface eth1 firewall-cmd --permanent --policy-set gateway --remove-disable firewall-cmd --reload
  • A "disable" flag has been implemented that can be used in XML settings, the command line utility, or via DBus to disable individual rules and policy sets.
  • The maximum size of rule names has been increased from 17 to 128 characters.
  • Added the gitea service for the collaborative development platform of the same name (TCP port 3000).
  • Added the syslog-ng service for the logging system of the same name (ports 514, 601 and 6514).
  • Added proxy-http service for HTTP/HTTPS proxy, such as Squid (TCP port 3128).
  • Added socks service for proxyservers with the implementation of the SOCKS protocol (TCP port 1080).

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster