Skip to content

Firewalld & nftables

Configuring firewalld and nftables for Network Security

Firewalls are critical for enforcing network security policies on Linux servers. This section covers how to configure firewalld (a high-level tool with zone-based rules) and nftables (a low-level, flexible framework) to restrict inbound/outbound traffic, block unauthorized access, and enforce strict security policies.


Firewalld: Zone-Based Rule Management

Firewalld simplifies firewall management through zones (e.g., public, internal, dmz) and services (e.g., SSH, HTTP). It abstracts complex rules into manageable configurations.

Basic Setup

Ensure firewalld is installed and active:

sudo dnf install firewalld
sudo systemctl enable --now firewalld

Default Zones and Services

By default, the public zone blocks all inbound traffic. Add allowed services:

sudo firewall-cmd --zone=public --add-service=http --permanent
sudo firewall-cmd --zone=public --add-service=https --permanent
sudo firewall-cmd --reload

Custom Rules

Use rich rules for granular control (e.g., allow traffic from specific IPs):

sudo firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" accept' --permanent

Persistent Rules

Always use --permanent flags for rules to survive reboots. Verify active rules:

sudo firewall-cmd --list-all


nftables: Low-Level Rule Configuration

nftables replaces iptables and offers more flexibility for complex rules. It uses tables, chains, and rules to filter traffic.

Basic Setup

Install and start nftables:

sudo dnf install nftables
sudo systemctl enable --now nftables

Default Policy: Default Deny

Set a default deny policy to block all unmatched traffic:

sudo nft add table ip filter
sudo nft add chain ip filter input { type filter hook input priority 0; policy drop; }
sudo nft add chain ip filter forward { type filter hook forward priority 0; policy drop; }
sudo nft add chain ip filter output { type filter hook output priority 0; policy accept; }

Custom Rules

Allow SSH and HTTP traffic:

sudo nft add rule ip filter input tcp dport 22 accept
sudo nft add rule ip filter input tcp dport 80 accept
sudo nft add rule ip filter input tcp dport 443 accept

Persistent Rules

Save the configuration to persist across reboots:

sudo nft list ruleset > /etc/nftables.conf
sudo systemctl restart nftables


Best Practices and Security Considerations

  1. Default Deny Policy: Always start with a strict "drop" policy and explicitly allow only trusted traffic.
  2. Regular Audits: Use firewall-cmd --list-all or nft list ruleset to review active rules.
  3. Logging: Enable logging for suspicious traffic:
    sudo firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" log prefix="Firewalld: " level=info' --permanent
    
  4. SELinux Integration: Use audit2allow or audit2iptables to translate SELinux denials into firewall rules.
  5. Monitoring: Tools like iptables-monitor (for iptables) or nft monitor can track real-time traffic.

Key takeaways

  • Use firewalld for simplicity with zone-based rules, ideal for standard services.
  • Use nftables for advanced, granular control over traffic filtering.
  • Enforce a default deny policy and explicitly allow only necessary traffic.
  • Regularly audit and log firewall rules to detect anomalies.
  • Combine firewall configurations with SELinux/AppArmor for layered security.