{"id":100821,"date":"2021-07-23T10:22:39","date_gmt":"2021-07-23T08:22:39","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vypusk-firewalld-1-0"},"modified":"2021-07-23T10:22:39","modified_gmt":"2021-07-23T08:22:39","slug":"vypusk-firewalld-1-0","status":"publish","type":"post","link":"https:\/\/prohoster.info\/pl\/blog\/news\/vypusk-firewalld-1-0","title":{"rendered":"Wydanie firewalld 1.0","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Wydano wydanie dynamicznie zarz\u0105dzanego zapory sieciowej firewalld 1.0, zrealizowanego w formie nak\u0142adki nad filtrami pakiet\u00f3w nftables i iptables. Firewalld dzia\u0142a jako proces w tle, pozwalaj\u0105cy na dynamiczn\u0105 zmian\u0119 zasad filtracji pakiet\u00f3w przez D-Bus, bez potrzeby ponownego \u0142adowania zasad filtracji i bez zrywania aktywnych po\u0142\u0105cze\u0144. Projekt jest ju\u017c stosowany w wielu dystrybucjach Linux, w tym RHEL 7+, Fedora 18+ oraz SUSE\/openSUSE 15+. Kod firewalld napisany jest w j\u0119zyku Python i jest udost\u0119pniany na licencji GPLv2.      <\/p>\n<p>Do zarz\u0105dzania zapor\u0105 sieciow\u0105 s\u0142u\u017cy narz\u0119dzie firewall-cmd, kt\u00f3re przy tworzeniu regu\u0142 opiera si\u0119 nie na <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/pl\/lir\/ipv4\/\"   title=\"adres\u00f3w IP\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"837\">adres\u00f3w IP<\/a>, interfejs\u00f3w sieciowych i numer\u00f3w port\u00f3w, a tak\u017ce nazw us\u0142ug (na przyk\u0142ad, aby umo\u017cliwi\u0107 dost\u0119p do SSH, nale\u017cy wykona\u0107 &#171;firewall-cmd &#8212;add &#8212;service=ssh&#187;, aby zablokowa\u0107 SSH &#8212; &#171;firewall-cmd &#8212;remove &#8212;service=ssh&#187;). Do zmiany konfiguracji zapory sieciowej mo\u017cna r\u00f3wnie\u017c u\u017cywa\u0107 graficznego interfejsu firewall-config (GTK) oraz apletu firewall-applet (Qt). Obs\u0142uga zarz\u0105dzania zapor\u0105 sieciow\u0105 przez D-BUS API firewalld jest dost\u0119pna w takich projektach jak NetworkManager, libvirt, podman, docker i fail2ban.    <\/p>\n<p>Znacz\u0105ca zmiana numeru wersji wi\u0105\u017ce si\u0119 z wprowadzeniem zmian \u0142ami\u0105cych zgodno\u015b\u0107 wstecz oraz zmieniaj\u0105cych zachowanie pracy z obszarami. Wszystkie parametry filtrowania okre\u015blone w obszarze s\u0105 teraz stosowane tylko do ruchu adresowanego do hosta, na kt\u00f3rym dzia\u0142a firewalld, a do filtrowania ruchu tranzytowego wymagana jest konfiguracja polityk. Najbardziej zauwa\u017calne zmiany:  <\/p>\n<ul>\n<li class=\"l\"> Og\u0142oszono przestarza\u0142ym backend, kt\u00f3ry pozwala\u0142 na dzia\u0142anie nad iptables. Wsparcie dla iptables b\u0119dzie zachowane w przewidywalnej przysz\u0142o\u015bci, ale ten backend nie b\u0119dzie rozwijany.\n<li class=\"l\"> Intra-zone-forwarding mode is enabled and activated by default for all new zones, allowing free movement of packets between network interfaces or traffic sources within one zone (public, block, trusted, internal, etc.). To revert to the old behavior and prohibit packet forwarding within one zone, the command &#171;firewall-cmd &#8212;permanent &#8212;zone public &#8212;remove-forward&#187; can be used.\n<li class=\"l\"> Rules related to address translation (NAT) have been moved to the &#171;inet&#187; protocol family (previously added to &#171;ip&#187; and &#171;ip6&#187; families, which necessitated the duplication of rules for IPv4 and IPv6). This change eliminated duplicates when using ipset \u2014 instead of three copies of ipset entries, now only one is used.\n<li class=\"l\"> The action &#171;default&#187;, specified in the &#171;&#8212;set-target&#187; parameter, is now equivalent to &#171;reject&#187;, meaning all packets not falling under specific rules in the zone will be blocked by default. An exception is made for ICMP packets, which are still allowed. To revert to the old behavior for the publicly accessible &#171;trusted&#187; zone, the following rules can be used: firewall-cmd &#8212;permanent &#8212;new-policy allowForward firewall-cmd &#8212;permanent &#8212;policy allowForward &#8212;set-target ACCEPT firewall-cmd &#8212;permanent &#8212;policy allowForward &#8212;add-ingress-zone public firewall-cmd &#8212;permanent &#8212;policy allowForward &#8212;add-egress-zone trusted firewall-cmd &#8212;reload.\n<li class=\"l\"> Policies with a positive priority are now executed directly before the &#171;&#8212;set-target catch-all&#187; rule is applied, i.e., at the moment preceding the addition of final drop, reject, or accept rules, including for zones where &#171;&#8212;set-target drop|reject|accept&#187; is used.\n<li class=\"l\"> Blokada ICMP jest teraz stosowana tylko do pakiet\u00f3w przychodz\u0105cych adresowanych do bie\u017c\u0105cego hosta (input) i nie dotyczy pakiet\u00f3w przekazywanych mi\u0119dzy strefami (forward).\n<li class=\"l\"> Usuni\u0119to us\u0142ug\u0119 tftp-client, przeznaczon\u0105 do \u015bledzenia po\u0142\u0105cze\u0144 dla protoko\u0142u TFTP, kt\u00f3ra by\u0142a jednak w stanie nieprzydatnym do u\u017cytku.\n<li class=\"l\"> The &#171;direct&#187; interface, which allowed direct insertion of prepared packet filtering rules, has been deprecated. The need for this interface has diminished after the addition of the ability to filter redirected and outgoing packets.\n<li class=\"l\"> A parameter CleanupModulesOnExit has been added, which is set to &#171;no&#187; by default. This parameter allows control over the unloading of kernel modules after firewalld has been shut down.\n<li class=\"l\"> Zezwolono na u\u017cycie ipset przy definiowaniu celu (destination).\n<li class=\"l\"> Dodano definicje us\u0142ug WireGuard, Kubernetes i netbios-ns.\n<li class=\"l\"> Zrealizowano regu\u0142y autouzupe\u0142niania dla zsh.\n<li class=\"l\"> Wsparcie dla Pythona 2 zosta\u0142o zako\u0144czone.\n<li class=\"l\"> Skr\u00f3cono list\u0119 zale\u017cno\u015bci. Aby dzia\u0142a\u0142 firewalld, poza j\u0105drem Linux, wymagane s\u0105 teraz tylko biblioteki python dbus, gobject oraz nftables, a pakiety ebtables, ipset i iptables zosta\u0142y uznane za opcjonalne. Z listy zale\u017cno\u015bci usuni\u0119to biblioteki python decorator oraz slip.    <\/ul>\n<p>\u0179r\u00f3d\u0142o: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55537\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables. Firewalld \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u0432 \u0432\u0438\u0434\u0435 \u0444\u043e\u043d\u043e\u0432\u043e\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0438\u0437\u043c\u0435\u043d\u044f\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 D-Bus, \u0431\u0435\u0437 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043f\u0440\u0430\u0432\u0438\u043b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 \u0438 \u0431\u0435\u0437 \u0440\u0430\u0437\u0440\u044b\u0432\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439. \u041f\u0440\u043e\u0435\u043a\u0442 \u0443\u0436\u0435 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux, \u0432\u043a\u043b\u044e\u0447\u0430\u044f RHEL 7+, Fedora 18+ [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100821","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/pl\/blog\/news\/vypusk-firewalld-1-0\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"pl_PL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a firewalld 1.0 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/pl\/blog\/news\/vypusk-firewalld-1-0\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-07-23T08:22:39+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-07-23T08:22:39+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Wydanie firewalld 1.0 | ProHoster","description":"Wprowadzono wydanie dynamicznie zarz\u0105dzanego zapory ogniowej firewalld 1.0, wdro\u017conego w formie obudowy nad filtrami pakiet\u00f3w nftables i iptables.","canonical_url":"https:\/\/prohoster.info\/pl\/blog\/news\/vypusk-firewalld-1-0","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"pl_PL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a firewalld 1.0 | ProHoster","og:description":"\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 firewalld 1.0, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0431\u0432\u044f\u0437\u043a\u0438 \u043d\u0430\u0434 \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u043c\u0438 nftables \u0438 iptables.","og:url":"https:\/\/prohoster.info\/pl\/blog\/news\/vypusk-firewalld-1-0","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-07-23T08:22:39+00:00","article:modified_time":"2021-07-23T08:22:39+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100821","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-07-24 00:03:32","updated":"2026-02-08 20:40:15","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/100821","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/comments?post=100821"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/100821\/revisions"}],"predecessor-version":[{"id":158028,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/100821\/revisions\/158028"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/media?parent=100821"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/categories?post=100821"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/tags?post=100821"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}