Release of the firewalld 2.4.0 firewall

A release of the dynamically managed firewall firewalld 2.4.0 has been formed, implemented as a wrapper over the packet filters nftables and iptables. Firewalld runs as a background process, allowing dynamic changes to packet filter rules via D-Bus, without the need to reload packet filter rules and without breaking established connections. The project is already used in many Linux distributions, including RHEL 7+, Fedora 18+, and SUSE/openSUSE 15+. The firewalld code is written in Python and is distributed under the GPLv2 license.

The firewall is managed using the utility firewall-cmd, which creates rules based not on (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community., network interfaces and port numbers, but rather on service names (for example, to allow access to SSH, you need to run "firewall-cmd --add --service=ssh", and to close SSH — "firewall-cmd --remove --service=ssh"). The graphical interface firewall-config (GTK) and the applet firewall-applet (Qt) can also be used to modify the firewall configuration. Support for managing the firewall via the D-BUS API of firewalld is available in projects such as NetworkManager, libvirt, podman, docker, and fail2ban.

Key changes:

  • A set of rules ‘gateway’ has been added, covering the functionality of a typical home router (including NAT, conntrack handlers, and traffic forwarding between zones). An example of configuring a gateway with internal and external network interfaces using the ‘gateway’ rule set: firewall-cmd --permanent --zone internal --add-interface eth0 firewall-cmd --permanent --zone external --add-interface eth1 firewall-cmd --permanent --policy-set gateway --remove-disable firewall-cmd --reload
  • A ‘disable’ flag has been implemented, which can be used in XML configurations, command-line utility, or via DBus to disable individual rules and rule sets (policy set).
  • The maximum size of rule names has been increased from 17 to 128 characters.
  • The gitea service has been added for the eponymous collaborative development platform (TCP port 3000).
  • The syslog-ng service has been added for the eponymous logging system (ports 514, 601, and 6514).
  • The proxy-http service for HTTP/HTTPS proxy, such as Squid, has been added (TCP port 3128).
  • The socks service has been added for proxy-servers with SOCKS protocol implementation (TCP port 1080).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster