Exercise

Allow HTTP Traffic Exercise

Task

Install a web server on servera, watch workstation fail to reach it, open the http service in the firewall, and keep the change.

Host
servera, from workstation
Prerequisite
None
  1. Install httpd and write a page

    ssh student@servera
    sudo dnf install -y httpd
    echo "<h1>Welcome to servera</h1>" | sudo tee /var/www/html/index.html

    httpd is not installed on servera to begin with, in any of the lab environments.

  2. Enable and start the service

    sudo systemctl enable --now httpd
    systemctl is-active httpd
    curl http://localhost/

    The server answers itself, so Apache is running and serving the page. Whether anyone else can reach it is a separate question.

  3. Request the page from workstation

    exit
    curl http://servera/

    It fails straight away: curl: (7) Failed to connect to servera port 80 after 0 ms: Could not connect to server. The refusal is immediate because the public zone rejects the packet rather than dropping it.

  4. Inspect what the zone allows

    ssh student@servera
    sudo firewall-cmd --list-services

    cockpit dhcpv6-client ssh. No http, so nothing is listening as far as the firewall is concerned.

  5. Allow the http service

    sudo firewall-cmd --add-service=http
    sudo firewall-cmd --list-services
  6. Request the page again

    exit
    curl http://servera/

    The page arrives. Same server, same Apache, one service opened.

  7. Keep the change

    ssh student@servera
    sudo firewall-cmd --list-services --permanent
    sudo firewall-cmd --runtime-to-permanent
    sudo firewall-cmd --list-services --permanent

    The permanent configuration still listed three services, so a reload would have undone the work. After --runtime-to-permanent it lists four, and the change survives a reload and a reboot.