{"id":100821,"date":"2021-07-23T10:22:39","date_gmt":"2021-07-23T08:22:39","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vypusk-firewalld-1-0"},"modified":"2021-07-23T10:22:39","modified_gmt":"2021-07-23T08:22:39","slug":"vypusk-firewalld-1-0","status":"publish","type":"post","link":"https:\/\/prohoster.info\/et\/blog\/news\/vypusk-firewalld-1-0","title":{"rendered":"V\u00e4ljaanne firewalld 1.0","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Esitatud on tulemustega d\u00fcnaamiliselt hallatava tulem\u00fc\u00fcri firewalld 1.0 versioon, mis on rakendatud pakettide filtreerimise nftables ja iptables kohal. Firewalld k\u00e4ivitatakse taustprotsessina, mis v\u00f5imaldab d\u00fcnaamiliselt muuta pakettide filtreerimise reegleid D-Bus kaudu, ilma et peaks uuesti laadima pakettide filtreerimise reegleid v\u00f5i katkestama kehtivaid \u00fchendusi. Projekti kasutatakse juba paljudes Linuxi distributsioonides, sealhulgas RHEL 7+, Fedora 18+ ja SUSE\/openSUSE 15+. Firewaldi kood on kirjutatud Pythonis ja levitatakse GPLv2 litsentsi alusel.      <\/p>\n<p>Tulem\u00fc\u00fcri haldamiseks kasutatakse t\u00f6\u00f6riista firewall-cmd, mis reeglite loomisel ei p\u00f5hine <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/et\/lir\/ipv4\/\"   title=\"IP-aadresse\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"837\">IP-aadresse<\/a>, v\u00f5rgu liideste ja portide numbrite ning teenuste nimede kaudu (n\u00e4iteks SSH-i juurdep\u00e4\u00e4su avamiseks tuleb k\u00e4ivitada &#171;firewall-cmd &#8212;add &#8212;service=ssh&#187;, SSH-i sulgemiseks &#8212; &#171;firewall-cmd &#8212;remove &#8212;service=ssh&#187;). Tulekahju seina konfiguratsiooni muutmiseks saab kasutada ka graafilist liidest firewall-config (GTK) ja rakendust firewall-applet (Qt). Tulekahju seina haldamise toetamine D-BUS API kaudu firewalld-s on olemas sellistes projektides nagu NetworkManager, libvirt, podman, docker ja fail2ban.    <\/p>\n<p>Olulise versiooninumbrimuutuse p\u00f5hjustas mitmete tagurpidi \u00fchilduvust rikkuda ja zone\u2019ide t\u00f6\u00f6 k\u00e4itumist muuta. K\u00f5ik ala m\u00e4\u00e4ratud filtreerimisparameetrid rakenduvad n\u00fc\u00fcd ainult sellele hostile suunatud liiklusele, millel firewalld t\u00f6\u00f6tab, ja l\u00e4biva liikluse filtreerimise seadistamiseks on vajalik poliitikate seadistamine. K\u00f5ige t\u00e4helepanuv\u00e4\u00e4rsemad muudatused:  <\/p>\n<ul>\n<li class=\"l\"> Iptables'i kohal t\u00f6\u00f6tamise v\u00f5imalust on kuulutatud vananenuks. Iptables'i tugi j\u00e4\u00e4b l\u00e4hitulevikus alles, kuid seda tagasiteenust ei arendata edasi.\n<li class=\"l\"> Intra-zone-forwarding is enabled and activated by default for all new zones, allowing free movement of packets between network interfaces or traffic sources within the same zone (public, block, trusted, internal, etc.). To revert to the old behavior and prohibit packet forwarding within the same zone, you can use the command \u00abfirewall-cmd \u2014permanent \u2014zone public \u2014remove-forward\u00bb.\n<li class=\"l\"> Address translation (NAT) rules have been moved to the \u00abinet\u00bb protocol family (previously added to the \u00abip\u00bb and \u00abip6\u00bb families, which required rule duplication for IPv4 and IPv6). This change eliminates duplicates when using ipset \u2014 instead of three copies of ipset entries, only one is now used.\n<li class=\"l\"> The action \u00abdefault\u00bb, specified in the parameter \u00ab\u2014set-target\u00bb, is now equivalent to \u00abreject\u00bb, meaning all packets not matching specific rules within the zone will be blocked by default. An exception is made for ICMP packets, which are still allowed. To revert to the old behavior for the publicly accessible zone \u00abtrusted\u00bb, the following rules can be used:       firewall-cmd \u2014permanent \u2014new-policy allowForward      firewall-cmd \u2014permanent \u2014policy allowForward \u2014set-target ACCEPT     firewall-cmd \u2014permanent \u2014policy allowForward \u2014add-ingress-zone public     firewall-cmd \u2014permanent \u2014policy allowForward \u2014add-egress-zone trusted     firewall-cmd \u2014reload\n<li class=\"l\"> Policies with positive priority are now executed just before applying the rule \u00ab\u2014set-target catch-all\u00bb, i.e., at the moment preceding the addition of final rules drop, reject, or accept, including those for zones using \u00ab\u2014set-target drop|reject|accept\u00bb.\n<li class=\"l\"> ICMP blokeerimine rakendatakse n\u00fc\u00fcd ainult sisenevatele pakkidele, mis on suunatud hetkel t\u00f6\u00f6tavale hostile (input) ja ei m\u00f5juta piirkondade vahel suunatud pakette (forward).\n<li class=\"l\"> T\u00fchistatud tftp-client teenus, mis oli m\u00f5eldud TFTP-protokolli \u00fchenduste j\u00e4lgimiseks, kuid oli kasutusv\u00f5imetu.\n<li class=\"l\"> The interface \u00abdirect\u00bb has been deprecated, allowing direct insertion of ready-made packet filter rules. The need for this interface has disappeared after the addition of the ability to filter redirected and outgoing packets.\n<li class=\"l\"> The parameter CleanupModulesOnExit has been added, which is now set to \u00abno\u00bb by default. This parameter allows you to control the unloading of kernel modules after the firewalld operation ends.\n<li class=\"l\"> Ipseti kasutamine sihts\u00fcsteemi (destination) m\u00e4\u00e4ramisel on n\u00fc\u00fcd lubatud.\n<li class=\"l\"> Lisatud teenuste m\u00e4\u00e4ratlused WireGuard, Kubernetes ja netbios-ns.\n<li class=\"l\"> Zsh jaoks on rakendatud automaatse t\u00e4iendamise reeglid.\n<li class=\"l\"> Python 2 toe l\u00f5petamine.\n<li class=\"l\"> S\u00f5ltuvuste nimekiri on l\u00fchendatud. Firewalld jaoks on n\u00fc\u00fcd vajalikud ainult Linuxi tuum ja python-raamatukogud dbus, gobject ja nftables, samas kui ebtables, ipset ja iptables on muudetud volituslikeks. S\u00f5ltuvustest on eemaldatud python-raamatukogud decorator ja slip.    <\/ul>\n<p>Allikas: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55537\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables. Firewalld \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u0432 \u0432\u0438\u0434\u0435 \u0444\u043e\u043d\u043e\u0432\u043e\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0438\u0437\u043c\u0435\u043d\u044f\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 D-Bus, \u0431\u0435\u0437 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043f\u0440\u0430\u0432\u0438\u043b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 \u0438 \u0431\u0435\u0437 \u0440\u0430\u0437\u0440\u044b\u0432\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439. \u041f\u0440\u043e\u0435\u043a\u0442 \u0443\u0436\u0435 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux, \u0432\u043a\u043b\u044e\u0447\u0430\u044f RHEL 7+, Fedora 18+ [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100821","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/et\/blog\/news\/vypusk-firewalld-1-0\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"et_EE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a firewalld 1.0 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/et\/blog\/news\/vypusk-firewalld-1-0\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-07-23T08:22:39+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-07-23T08:22:39+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Firewalld 1.0 v\u00e4ljalaskmine | ProHoster","description":"Presented dynamically managed firewall release firewalld 1.0, implemented as a wrapper over packet filters nftables and iptables.","canonical_url":"https:\/\/prohoster.info\/et\/blog\/news\/vypusk-firewalld-1-0","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"et_EE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a firewalld 1.0 | ProHoster","og:description":"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables.","og:url":"https:\/\/prohoster.info\/et\/blog\/news\/vypusk-firewalld-1-0","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-07-23T08:22:39+00:00","article:modified_time":"2021-07-23T08:22:39+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100821","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-07-24 00:03:32","updated":"2026-02-08 20:40:15","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/100821","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/comments?post=100821"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/100821\/revisions"}],"predecessor-version":[{"id":158028,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/100821\/revisions\/158028"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/media?parent=100821"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/categories?post=100821"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/tags?post=100821"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}