Exercise
Move an Interface to Another Zone Exercise
Task
Move servera's network interface from the
public zone into dmz, notice
the impacts to what is allowed, then reload the firewall
and see what is left.
- Host
-
servera, fromworkstation - Prerequisite
- None
-
Find your interface, then list the zones
ssh student@servera nmcli device status sudo firewall-cmd --get-zones sudo firewall-cmd --get-active-zones sudo firewall-cmd --get-default-zoneTen zones exist, one is active, and your Ethernet interface is in
publicbecausepublicis the default zone, not because anyone assigned it. -
Inspect what the active zone allows
sudo firewall-cmd --list-allNote the services line:
cockpit dhcpv6-client ssh. The ports line is empty, because nothing has been opened by number. -
Move enp1s0 into dmz
sudo firewall-cmd --zone=dmz --change-interface=enp1s0 -
Confirm the move and the shorter service list
sudo firewall-cmd --get-active-zones sudo firewall-cmd --list-all --zone=dmzdmznow holds the interface you moved, andpublicis still the default.dmzallowssshalone, wherepublicallowed three services. -
Reload the firewall
sudo firewall-cmd --reload -
Look again
sudo firewall-cmd --get-active-zones sudo firewall-cmd --list-allThe move is gone.
enp1s0is back inpublicand all three services are back, and nobody undid it by hand. Where the change went is the subject of the next section.