Release of firewall firewalld 2.5.0

The release of the dynamically managed firewall firewalld 2.5.0 has been formed, implemented as a wrapper over the packet filters nftables and iptables. Firewalld runs as a background process, allowing dynamic changes to packet filtering rules via D-Bus, without the need to reload packet filter rules and without interrupting established connections. The project is already in use in many Linux distributions, including RHEL 7+, Fedora 18+, and SUSE/openSUSE 15+. The firewalld code is written in Python and is distributed under the GPLv2 license.

The firewall is managed using the utility firewall-cmd, which creates rules based not on (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community., network interfaces and port numbers, but rather on service names (for example, to allow access to SSH, you need to run "firewall-cmd --add --service=ssh", and to close SSH — "firewall-cmd --remove --service=ssh"). The graphical interface firewall-config (GTK) and the applet firewall-applet (Qt) can also be used to modify the firewall configuration. Support for managing the firewall via the D-BUS API of firewalld is available in projects such as NetworkManager, libvirt, podman, docker, and fail2ban.

Key changes:

  • The firewall-config graphical interface now supports automatic switching to a dark theme in GNOME.
  • Changes to the configuration are now logged.
  • A solr service has been added for the eponymous search engine based on Apache Lucene (TCP port 8983).
  • Timeouts have been implemented for processing filtering rules, allowing specification of timeouts for the options "--add-disable", "--ingress-zone", and "--egress-zone".
  • Performance optimization for zone and rule checks has been conducted.
  • The dbus-x11 package has been removed from the rpm package dependency list.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster