03-02-2010
Is there any way to add an exception for a port in the firewall setting, permanently?
Hello,
I want to add a port in the firewall exception list so that my application can be accessed over network even if firewall is disabled. I am using iptables command to add exception.
The problem is, after setting the rule if I change the firewall setting i.e. on/off then it is overwriting all the existing rules.
Let me give you two scenarios to help you understand the problem better:
Scenario 1) Firewall is On. I have added a rule in the iptables to allow an input access to a particular port. Now my (Web based) application can be accessed from other systems over the network. Now I disable the firewall. Still my app can be accessed over network but the rule is gone.
Scenario 2) Firewall is Off. I have added a rule in the iptables to allow an input access to a particular port. Now my (Web based) application can be accessed from other systems over the network. I enable the firewall. Now the app cannot be accessed over network because all the existing rules have been overwritten.
Is there any way to add an exception for a particular port in the firewall setting so that disabling or enabling the firewall (any number of times) won't affect the existing rule set.
Note: I can only use 'commands'. Doing changes using graphical interface won't be helpful in my case as I am using a script to install my app and configure the port settings.
9 More Discussions You Might Find Interesting
1. Solaris
Hi,
So that potential responders will have an idea of what they're dealing with let me say that while I am a UNIX newbie I have been in IT for over 10 years.
We have several SUN boxes running ver 5 of the OS that have been sitting dormant for some time as they were part of a now defunct... (3 Replies)
Discussion started by: pjewett
3 Replies
2. Linux
Well, since I wrote the below, I've learned a little more about Samba, and got them to at least acknowledge each other. Still can't use Gaurd dog. Still cant print from one to the other.
I'm learning I'm learning
I recently installed mepis 7 on both my laptop and laptop. (I came... (0 Replies)
Discussion started by: Sonshyne5
0 Replies
3. Linux
Hi,
I will like to allow access to the mysql port (3306) to certain IP address. All other IP's should be automatically blocked. What is the best way to do this? (8 Replies)
Discussion started by: shantanuo
8 Replies
4. Shell Programming and Scripting
I'm trying to set the path permanently through a shell script. (/opt/quest/bin:/usr/bin/lab to /.profile.) I tired using echo option like below but it doesn't work. Please suggest me the right way to do so.
echo "PATH=$PATH:/opt/quest/bin:/usr/bin/lab" >> /.profile (6 Replies)
Discussion started by: pjeedu2247
6 Replies
5. UNIX for Dummies Questions & Answers
hi guys
I doing some collocation for a customer, customer requested to use other port for ssh not the default one. OK no problem
and customer will be using rsync to sync backups among other things
I know we have to open port let's say port 5999 for ssh since we are using that one now but I... (1 Reply)
Discussion started by: karlochacon
1 Replies
6. Shell Programming and Scripting
Hi,
I need to know what kind of firewall settings does the linux box have? Is port 25 blocked in any way?
Linux techx 3.10.0-514.10.2.el7.x86_64 #1 SMP Fri Mar 3 00:04:05 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
I'm coming from this thread. (1 Reply)
Discussion started by: mohtashims
1 Replies
7. Shell Programming and Scripting
I have my firewall process running
# ps -ef | grep firewall
root 21169 1 0 08:50 ? 00:00:00 /usr/bin/python -Es /usr/sbin/firewalld --nofork --nopid
I wish to know what ip : port number it is using. Can you please tell me how can i find out ?
I tried the below command... (4 Replies)
Discussion started by: mohtashims
4 Replies
8. Red Hat
I ssh in and am trying to add a directory permanently to $PATH in centos 7 and having issues. My current $PATH is
echo $PATH
/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/root/bin
but when I do a sudo nano ~/.bashrc
# .bashrc
# User specific aliases and functions
alias... (7 Replies)
Discussion started by: cmccabe
7 Replies
9. Shell Programming and Scripting
Below is what i did to open the firewall port on
# sudo firewall-cmd --zone=public --add-port=27012/tcp --permanent
Warning: ALREADY_ENABLED: 27012:tcp
success
# sudo firewall-cmd --reload
success
# firewall-cmd --list-all
public
target: default
icmp-block-inversion: no
... (10 Replies)
Discussion started by: mohtashims
10 Replies
LEARN ABOUT CENTOS
firewall-applet
FIREWALL-APPLET(1) firewall-applet FIREWALL-APPLET(1)
NAME
firewall-applet - firewalld applet
SYNOPSIS
firewall-applet [OPTIONS...]
DESCRIPTION
firewall-applet is a tray applet for firewalld.
OPTIONS
firewall-applet does not support any special options. The only options that can be used are the general options that Gtk uses for Gtk
application initialization. For more information on these options, please have a look at the runtime documentation for Gtk.
The following options are supported:
-h, --help
Prints a short help text and exists.
GSETTINGS
firewall-applet has additional settings to adapt the look and feel. The used backend depends on the distribution and can be either dconf or
GConf. The path to the settings is org.fedoraproject.FirewallApplet. You can use dconf-editor or gconf-editor to see and modify them.
The following settings are supported:
notifications
The applet shows notifications if enabled. This setting can be enabled also in the applet with the "Enable Notifications" checkbox in
the right mouse menu.
This setting defaults to false.
If notifications are shown for these actions if enabled:
o Connection to firewalld established
o Connection to firewalld lost
o Firewall has been reloaded
o Default zone has been changed
o Panic mode has been enabled or disabled
o Activation, deactivation or change of zones bound to interfaces
o Activation, deactivation or change of zones bound to sources addresses
show-inactive
Show applet also if firewalld is not running. If firewalld has been stopped or is not running the applet will be hidden and not visible
in the applet tray. Enable this setting to see the applet all the time for example to be sure that the firewall is active.
This setting defaults to false.
shields-up
The shields-up zone name to be used if shields-up is enabled.
This setting defaults to 'block'.
shields-down
The shields-down zone name to be used if shields-up has been deactivated again.
This setting defaults to 'public'.
blink
If enabled, the applet icon blinks in these cases:
o Connection to firewalld lost
o Panic mode has been enabled or disabled
This setting defaults to false.
blink-count
The number of blinks if blink is enabled.
This setting defaults to 5.
SEE ALSO
firewall-applet(1), firewalld(1), firewall-cmd(1), firewall-config(1), firewalld.conf(5), firewalld.direct(5), firewalld.icmptype(5),
firewalld.lockdown-whitelist(5), firewall-offline-cmd(1), firewalld.richlanguage(5), firewalld.service(5), firewalld.zone(5),
firewalld.zones(5)
NOTES
firewalld home page at fedorahosted.org:
http://fedorahosted.org/firewalld/
More documentation with examples:
http://fedoraproject.org/wiki/FirewallD
AUTHORS
Thomas Woerner <twoerner@redhat.com>
Developer
Jiri Popelka <jpopelka@redhat.com>
Developer
firewalld 0.3.9 FIREWALL-APPLET(1)