{"id":100821,"date":"2021-07-23T10:22:39","date_gmt":"2021-07-23T08:22:39","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vypusk-firewalld-1-0"},"modified":"2021-07-23T10:22:39","modified_gmt":"2021-07-23T08:22:39","slug":"vypusk-firewalld-1-0","status":"publish","type":"post","link":"https:\/\/prohoster.info\/et\/blog\/news\/vypusk-firewalld-1-0","title":{"rendered":"Firewalld 1.0 v\u00e4ljalase","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Esitatud on d\u00fcnaamiliselt hallatava tulem\u00fc\u00fcr firewalld 1.0 v\u00e4ljaanne, mis on rakendatud pakettide filtreerimise nftables ja iptables peal. Firewalld t\u00f6\u00f6tab taustprotsessina, v\u00f5imaldades d\u00fcnaamiliselt muuta pakettide filtreerimise reegleid D-Bus kaudu, ilma et oleks vaja filtreerimisreegleid uuesti laadida v\u00f5i katkestada olemasolevaid \u00fchendusi. Projekti kasutatakse juba paljudes Linuxi distributsioonides, sealhulgas RHEL 7+, Fedora 18+ ja SUSE\/openSUSE 15+. Firewaldi kood on kirjutatud Pythonis ja levitatakse GPLv2 litsentsi alusel.      <\/p>\n<p>Tulem\u00fc\u00fcri haldamiseks kasutatakse utiliiti firewall-cmd, mis reeglite loomisel ei tugine <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/et\/lir\/ipv4\/\"   title=\"IP-aadresse\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"837\">IP-aadresse<\/a>, v\u00f5rguliideste ja portide numbrite ning teenuste nimede, n\u00e4iteks SSH-le juurdep\u00e4\u00e4su avamiseks tuleb k\u00e4ivitada &#171;firewall-cmd &#8212;add &#8212;service=ssh&#187;, SSH sulgemiseks &#8212; &#171;firewall-cmd &#8212;remove &#8212;service=ssh&#187;). Ka graafilist liidest firewall-config (GTK) ja appletit firewall-applet (Qt) saab kasutada tulem\u00fc\u00fcri konfiguratsiooni muutmiseks. Tulem\u00fc\u00fcri haldamise tugi D-BUS API firewalld kaudu on olemas sellistes projektides nagu NetworkManager, libvirt, podman, docker ja fail2ban.    <\/p>\n<p>Oluline versiooninumbrite muutus tuleneb muudatustest, mis rikuvad tagasikutsumise \u00fchilduvust ja muudavad t\u00f6\u00f6 k\u00e4itumist tsoonidega. K\u00f5ik tsoonis m\u00e4\u00e4ratud filtreerimise parameetrid rakenduvad n\u00fc\u00fcd ainult sellele liiklusele, mis on adresseeritud hostile, kus firewalld on k\u00e4imas, ning transiitliikluse filtreerimiseks on vaja poliitikate seadistamist. K\u00f5ige silmatorkavamad muudatused:  <\/p>\n<ul>\n<li class=\"l\"> iptables'i peal t\u00f6\u00f6tamise tagamine on kuulutatud aegunuks. Iptables'i tugi s\u00e4ilib l\u00fchikeses tulevikus, kuid seda backend'i arendamine ei j\u00e4tkugi.\n<li class=\"l\"> Intra-zone-forwarding mode, which allows free movement of packets between network interfaces or traffic sources within a single zone (public, block, trusted, internal, etc.), is enabled and activated by default for all new zones. To revert to the old behavior and prohibit packet forwarding within one zone, the command \u2018firewall-cmd \u2014permanent \u2014zone public \u2014remove-forward\u2019 can be used.\n<li class=\"l\"> Address translation (NAT) rules have been moved to the \u2018inet\u2019 protocol family (previously added to the \u2018ip\u2019 and \u2018ip6\u2019 families, which required duplicating rules for both IPv4 and IPv6). This change eliminates duplicates when using ipset \u2014 one record is now used instead of three copies.\n<li class=\"l\"> The \u2018default\u2019 action specified in the \u2018\u2014set-target\u2019 parameter is now equivalent to \u2018reject\u2019, meaning that all packets not matching specific zone rules will be blocked by default. An exception has been made for ICMP packets, which will still be allowed. To revert to the old behavior for the publicly accessible \u2018trusted\u2019 zone, the following rules can be used:       firewall-cmd \u2014permanent \u2014new-policy allowForward      firewall-cmd \u2014permanent \u2014policy allowForward \u2014set-target ACCEPT     firewall-cmd \u2014permanent \u2014policy allowForward \u2014add-ingress-zone public     firewall-cmd \u2014permanent \u2014policy allowForward \u2014add-egress-zone trusted     firewall-cmd \u2014reload\n<li class=\"l\"> Policies with positive priority are now executed just before the \u2018\u2014set-target catch-all\u2019 rule is applied, that is, just before the final drop, reject, or accept rules are added, including for zones that use \u2018\u2014set-target drop|reject|accept\u2019.\n<li class=\"l\"> ICMP blokeerimine kehtib n\u00fc\u00fcd ainult hetkelisele hostile suunatud sissetulevatele pakkidele (input) ning ei m\u00f5juta tsoonide vahel suunatud pakette (forward).\n<li class=\"l\"> Teenust tftp-client, mis oli m\u00f5eldud TFTP protokolli \u00fchenduste j\u00e4lgimiseks, kuid oli kasutusk\u00f5lbmatuks muutunud, on eemaldatud.\n<li class=\"l\"> The \u2018direct\u2019 interface, which allowed the direct insertion of pre-defined packet filtering rules, has been deprecated. The need for this interface has diminished after the addition of the ability to filter redirected and outgoing packets.\n<li class=\"l\"> A new parameter, CleanupModulesOnExit, has been added, which is set to \u2018no\u2019 by default. This parameter can be used to manage the unloading of kernel modules after firewalld has stopped.\n<li class=\"l\"> Lubatud on ipset'i kasutamine sihts\u00fcsteemi (destination) m\u00e4\u00e4ramisel.\n<li class=\"l\"> Lisatud teenuste m\u00e4\u00e4ratlased WireGuard, Kubernetes ja netbios-ns.\n<li class=\"l\"> Zsh-i automaatse t\u00e4itmise reeglid on rakendatud.\n<li class=\"l\"> Python 2 toe l\u00f5petamine.\n<li class=\"l\"> S\u00f5ltuvuste loetelu on l\u00fchendatud. Firewalld'i t\u00f6\u00f6ks on n\u00fc\u00fcd lisaks Linuxi tuumale vajalik vaid python-raamatukogud dbus, gobject ja nftables, samas kui paketid ebtables, ipset ja iptables on n\u00fc\u00fcd valikuliselt vajalikud. S\u00f5ltuvuste hulgast on eemaldatud python-raamatukogud decorator ja slip.    <\/ul>\n<p>Allikas: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55537\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables. Firewalld \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u0432 \u0432\u0438\u0434\u0435 \u0444\u043e\u043d\u043e\u0432\u043e\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0438\u0437\u043c\u0435\u043d\u044f\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 D-Bus, \u0431\u0435\u0437 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043f\u0440\u0430\u0432\u0438\u043b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 \u0438 \u0431\u0435\u0437 \u0440\u0430\u0437\u0440\u044b\u0432\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439. \u041f\u0440\u043e\u0435\u043a\u0442 \u0443\u0436\u0435 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux, \u0432\u043a\u043b\u044e\u0447\u0430\u044f RHEL 7+, Fedora 18+ [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100821","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/et\/blog\/news\/vypusk-firewalld-1-0\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"et_EE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a firewalld 1.0 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/et\/blog\/news\/vypusk-firewalld-1-0\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-07-23T08:22:39+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-07-23T08:22:39+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Firewalld 1.0 v\u00e4ljalase | ProHoster","description":"K\u00e4ivitus on d\u00fcnaamiliselt hallatava tulem\u00fc\u00fcride firewalld 1.0, mis on tehtud pakettfiltrite nftables ja iptables kohal.","canonical_url":"https:\/\/prohoster.info\/et\/blog\/news\/vypusk-firewalld-1-0","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"et_EE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a firewalld 1.0 | ProHoster","og:description":"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables.","og:url":"https:\/\/prohoster.info\/et\/blog\/news\/vypusk-firewalld-1-0","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-07-23T08:22:39+00:00","article:modified_time":"2021-07-23T08:22:39+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100821","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-07-24 00:03:32","updated":"2026-02-08 20:40:15","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/100821","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/comments?post=100821"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/100821\/revisions"}],"predecessor-version":[{"id":158028,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/100821\/revisions\/158028"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/media?parent=100821"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/categories?post=100821"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/tags?post=100821"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}