Firewalld & nftables
Configuring firewalld and nftables for Network Security¶
Firewalls are critical for enforcing network security policies on Linux servers. This section covers how to configure firewalld (a high-level tool with zone-based rules) and nftables (a low-level, flexible framework) to restrict inbound/outbound traffic, block unauthorized access, and enforce strict security policies.
Firewalld: Zone-Based Rule Management¶
Firewalld simplifies firewall management through zones (e.g., public, internal, dmz) and services (e.g., SSH, HTTP). It abstracts complex rules into manageable configurations.
Basic Setup¶
Ensure firewalld is installed and active:
Default Zones and Services¶
By default, the public zone blocks all inbound traffic. Add allowed services:
sudo firewall-cmd --zone=public --add-service=http --permanent
sudo firewall-cmd --zone=public --add-service=https --permanent
sudo firewall-cmd --reload
Custom Rules¶
Use rich rules for granular control (e.g., allow traffic from specific IPs):
sudo firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" accept' --permanent
Persistent Rules¶
Always use --permanent flags for rules to survive reboots. Verify active rules:
nftables: Low-Level Rule Configuration¶
nftables replaces iptables and offers more flexibility for complex rules. It uses tables, chains, and rules to filter traffic.
Basic Setup¶
Install and start nftables:
Default Policy: Default Deny¶
Set a default deny policy to block all unmatched traffic:
sudo nft add table ip filter
sudo nft add chain ip filter input { type filter hook input priority 0; policy drop; }
sudo nft add chain ip filter forward { type filter hook forward priority 0; policy drop; }
sudo nft add chain ip filter output { type filter hook output priority 0; policy accept; }
Custom Rules¶
Allow SSH and HTTP traffic:
sudo nft add rule ip filter input tcp dport 22 accept
sudo nft add rule ip filter input tcp dport 80 accept
sudo nft add rule ip filter input tcp dport 443 accept
Persistent Rules¶
Save the configuration to persist across reboots:
Best Practices and Security Considerations¶
- Default Deny Policy: Always start with a strict "drop" policy and explicitly allow only trusted traffic.
- Regular Audits: Use
firewall-cmd --list-allornft list rulesetto review active rules. - Logging: Enable logging for suspicious traffic:
- SELinux Integration: Use
audit2alloworaudit2iptablesto translate SELinux denials into firewall rules. - Monitoring: Tools like
iptables-monitor(for iptables) ornft monitorcan track real-time traffic.
Key takeaways¶
- Use firewalld for simplicity with zone-based rules, ideal for standard services.
- Use nftables for advanced, granular control over traffic filtering.
- Enforce a default deny policy and explicitly allow only necessary traffic.
- Regularly audit and log firewall rules to detect anomalies.
- Combine firewall configurations with SELinux/AppArmor for layered security.