Exercise
Allow HTTP Traffic Exercise
Task
Install a web server on servera, watch
workstation fail to reach it, open the
http service in the firewall, and keep the
change.
- Host
-
servera, fromworkstation - Prerequisite
- None
-
Install httpd and write a page
ssh student@servera sudo dnf install -y httpd echo "<h1>Welcome to servera</h1>" | sudo tee /var/www/html/index.htmlhttpdis not installed onserverato begin with, in any of the lab environments. -
Enable and start the service
sudo systemctl enable --now httpd systemctl is-active httpd curl http://localhost/The server answers itself, so Apache is running and serving the page. Whether anyone else can reach it is a separate question.
-
Request the page from workstation
exit curl http://servera/It fails straight away:
curl: (7) Failed to connect to servera port 80 after 0 ms: Could not connect to server. The refusal is immediate because thepubliczone rejects the packet rather than dropping it. -
Inspect what the zone allows
ssh student@servera sudo firewall-cmd --list-servicescockpit dhcpv6-client ssh. Nohttp, so nothing is listening as far as the firewall is concerned. -
Allow the http service
sudo firewall-cmd --add-service=http sudo firewall-cmd --list-services -
Request the page again
exit curl http://servera/The page arrives. Same server, same Apache, one service opened.
-
Keep the change
ssh student@servera sudo firewall-cmd --list-services --permanent sudo firewall-cmd --runtime-to-permanent sudo firewall-cmd --list-services --permanentThe permanent configuration still listed three services, so a reload would have undone the work. After
--runtime-to-permanentit lists four, and the change survives a reload and a reboot.