firewall-cmd.md 1.5 KB

firewall-cmd

firewalld ๋ช…๋ น์ค„ ํด๋ผ์ด์–ธํŠธ. ๋Ÿฐํƒ€์ž„ ๋˜๋Š” ์˜๊ตฌ ๋ฐฉํ™”๋ฒฝ ๊ตฌ์„ฑ ์ƒํƒœ๋ฅผ ์กฐํšŒ ๋ฐ ์ˆ˜์ •. ๋” ๋งŽ์€ ์ •๋ณด: https://firewalld.org/documentation/man-pages/firewall-cmd.

  • ๋Ÿฐํƒ€์ž„ ๊ตฌ์„ฑ ์ƒํƒœ์—์„œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๋ชจ๋“  ๋ฐฉํ™”๋ฒฝ ์˜์—ญ๊ณผ ๊ทœ์น™ ์กฐํšŒ:

firewall-cmd --list-all-zones

  • ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ block ์˜์—ญ์œผ๋กœ ์˜๊ตฌ์ ์œผ๋กœ ์ด๋™ํ•˜์—ฌ ๋ชจ๋“  ํ†ต์‹  ์ฐจ๋‹จ:

firewall-cmd --permanent --zone={{block}} --change-interface={{enp1s0}}

  • ์ง€์ •๋œ ์˜์—ญ์—์„œ ์„œ๋น„์Šค์˜ ํฌํŠธ๋ฅผ ์˜๊ตฌ์ ์œผ๋กœ ์—ด๊ธฐ (์˜ˆ: public ์˜์—ญ์—์„œ ํฌํŠธ 443):

firewall-cmd --permanent --zone={{public}} --add-service={{https}}

  • ์ง€์ •๋œ ์˜์—ญ์—์„œ ์„œ๋น„์Šค์˜ ํฌํŠธ๋ฅผ ์˜๊ตฌ์ ์œผ๋กœ ๋‹ซ๊ธฐ (์˜ˆ: public ์˜์—ญ์—์„œ ํฌํŠธ 80):

firewall-cmd --permanent --zone={{public}} --remove-service={{http}}

  • ์ง€์ •๋œ ์˜์—ญ์—์„œ ๋“ค์–ด์˜ค๋Š” ํŒจํ‚ท์˜ ํฌํŠธ๋ฅผ ์˜๊ตฌ์ ์œผ๋กœ ํฌ์›Œ๋”ฉ (์˜ˆ: public ์˜์—ญ์—์„œ ํฌํŠธ 443์„ 8443์œผ๋กœ):

firewall-cmd --permanent --zone={{public}} --add-rich-rule='rule family="{{ipv4|ipv6}}" forward-port port="{{443}}" protocol="{{udp|tcp}}" to-port="{{8443}}"'

  • firewalld๋ฅผ ๋‹ค์‹œ ๋กœ๋“œํ•˜์—ฌ ๋Ÿฐํƒ€์ž„ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ์ œ๊ฑฐํ•˜๊ณ  ์˜๊ตฌ ๊ตฌ์„ฑ์„ ์ฆ‰์‹œ ์ ์šฉ:

firewall-cmd --reload

  • ๋Ÿฐํƒ€์ž„ ๊ตฌ์„ฑ ์ƒํƒœ๋ฅผ ์˜๊ตฌ ๊ตฌ์„ฑ์œผ๋กœ ์ €์žฅ:

firewall-cmd --runtime-to-permanent

  • ๋น„์ƒ์‹œ ํŒจ๋‹‰ ๋ชจ๋“œ ํ™œ์„ฑํ™”. ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ์ด ์ฐจ๋‹จ๋˜๊ณ  ํ™œ์„ฑ ์—ฐ๊ฒฐ์ด ์ข…๋ฃŒ๋จ:

firewall-cmd --panic-on