ืžื”ื“ื•ืจืช firewalld 2.1

ืฉื—ืจื•ืจื• ืฉืœ ื—ื•ืžืช ื”ืืฉ 2.1 ื”ื ืฉืœื˜ืช ื“ื™ื ืžื™ืช ืฉืœ ื—ื•ืžืช ื”ืืฉ, ื”ืžื™ื•ืฉืžืช ื‘ืฆื•ืจื” ืฉืœ ืžืขื˜ืคืช ืขืœ ืžืกื ื ื™ ืžื ื•ืช nftables ื•- iptables, ืฉื•ื—ืจืจื”. Firewalld ืคื•ืขืœ ื›ืชื”ืœื™ืš ืจืงืข ื”ืžืืคืฉืจ ืœืš ืœืฉื ื•ืช ื‘ืื•ืคืŸ ื“ื™ื ืžื™ ื›ืœืœื™ ืกื™ื ื•ืŸ ืžื ื•ืช ื‘ืืžืฆืขื•ืช D-Bus ืžื‘ืœื™ ืœื˜ืขื•ืŸ ืžื—ื“ืฉ ืืช ื›ืœืœื™ ืžืกื ืŸ ื”ืžื ื•ืช ืื• ืœืฉื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ืฉื ื•ืฆืจื•. ื”ืคืจื•ื™ืงื˜ ื›ื‘ืจ ื ืžืฆื ื‘ืฉื™ืžื•ืฉ ื‘ื”ืคืฆื•ืช ืœื™ื ื•ืงืก ืจื‘ื•ืช, ื›ื•ืœืœ RHEL 7+, Fedora 18+ ื•-SUSE/openSUSE 15+. ืงื•ื“ ื—ื•ืžืช ื”ืืฉ ื›ืชื•ื‘ ื‘-Python ื•ื”ื•ื ืžื•ืจืฉื” ืชื—ืช ืจื™ืฉื™ื•ืŸ GPLv2.

ืœื ื™ื”ื•ืœ ื—ื•ืžืช ื”ืืฉ, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช Firewall-cmd, ืืฉืจ, ื‘ืขืช ื™ืฆื™ืจืช ื›ืœืœื™ื, ืžื‘ื•ืกืก ืœื ืขืœ ื›ืชื•ื‘ื•ืช IP, ืžืžืฉืงื™ ืจืฉืช ื•ืžืกืคืจื™ ื™ืฆื™ืื•ืช, ืืœื ืขืœ ืฉืžื•ืช ื”ืฉื™ืจื•ืชื™ื (ืœื“ื•ื’ืžื”, ื›ื“ื™ ืœืคืชื•ื— ื’ื™ืฉื” ืœ-SSH ืืชื” ืฆืจื™ืš ื”ืคืขืœ ืืช "firewall-cmd โ€”add โ€”service= ssh", ื›ื“ื™ ืœืกื’ื•ืจ ืืช SSH - "firewall-cmd -remove -service=ssh"). ื›ื“ื™ ืœืฉื ื•ืช ืืช ืชืฆื•ืจืช ื—ื•ืžืช ื”ืืฉ, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื’ื ื‘ืžืžืฉืง ื”ื’ืจืคื™ ืฉืœ ื—ื•ืžืช ื”ืืฉ (GTK) ื•ื‘ื™ื™ืฉื•ืžื•ืŸ ื—ื•ืžืช ื”ืืฉ (Qt). ืชืžื™ื›ื” ื‘ื ื™ื”ื•ืœ ื—ื•ืžืช ืืฉ ื‘ืืžืฆืขื•ืช ื—ื•ืžืช ื”ืืฉ ืฉืœ D-BUS API ื–ืžื™ื ื” ื‘ืคืจื•ื™ืงื˜ื™ื ื›ื’ื•ืŸ NetworkManager, libvirt, podman, docker ื•-fail2ban.

ืฉื™ื ื•ื™ื™ื ืžืจื›ื–ื™ื™ื:

  • ื ื•ืกืฃ ืฉื™ืจื•ืช ืœืฉื™ืžื•ืฉ ื‘-DNS ืขืœ ืคืจื•ื˜ื•ืงื•ืœ QUIC (DNS ืขืœ QUIC, DoQ, RFC 9250).
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ ืกื•ื’ื™ ื”ื•ื“ืขื•ืช ICMPv6 MLD (ื’ื™ืœื•ื™ ืžืื–ื™ื ื™ื ืžืจื•ื‘ื™ ืฉื™ื“ื•ืจื™ื).
  • ื ื•ืกืคื” ืืคืฉืจื•ืช ReloadPolicy ืœืงื•ื‘ืฅ ื”ืชืฆื•ืจื” firewalld.conf.
  • ื ื•ืกืฃ ืฉื™ืจื•ืช ืœืงื‘ืœืช ื‘ืงืฉื•ืช SMTP ืฉืœ ืœืงื•ื— ื‘ื™ืฆื™ืืช TCP 587 (ืฉืœื™ื—ืช ื“ื•ืืจ).
  • ื ื•ืกืฃ ืฉื™ืจื•ืช ืœืชืžื™ื›ื” ื‘-ALVR (ื”ื–ืจืžืช ืžืฉื—ืงื™ VR ืžืžื—ืฉื‘ ืœืžื›ืฉื™ืจื™ื ื ื™ื™ื“ื™ื ื‘ืืžืฆืขื•ืช Wi-Fi).
  • ืฉื™ืจื•ืช ื ื•ืกืฃ ืœืชืžื™ื›ื” ื‘-VRRP (ืคืจื•ื˜ื•ืงื•ืœ ื™ืชื™ืจื•ืช ืฉืœ ื ืชื‘ ื•ื™ืจื˜ื•ืืœื™).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”