Exercise

Move an Interface to Another Zone Exercise

Task

Move servera's network interface from the public zone into dmz, notice the impacts to what is allowed, then reload the firewall and see what is left.

Host
servera, from workstation
Prerequisite
None
  1. Find your interface, then list the zones

    ssh student@servera
    nmcli device status
    sudo firewall-cmd --get-zones
    sudo firewall-cmd --get-active-zones
    sudo firewall-cmd --get-default-zone

    Ten zones exist, one is active, and your Ethernet interface is in public because public is the default zone, not because anyone assigned it.

  2. Inspect what the active zone allows

    sudo firewall-cmd --list-all

    Note the services line: cockpit dhcpv6-client ssh. The ports line is empty, because nothing has been opened by number.

  3. Move enp1s0 into dmz

    sudo firewall-cmd --zone=dmz --change-interface=enp1s0
  4. Confirm the move and the shorter service list

    sudo firewall-cmd --get-active-zones
    sudo firewall-cmd --list-all --zone=dmz

    dmz now holds the interface you moved, and public is still the default. dmz allows ssh alone, where public allowed three services.

  5. Reload the firewall

    sudo firewall-cmd --reload
  6. Look again

    sudo firewall-cmd --get-active-zones
    sudo firewall-cmd --list-all

    The move is gone. enp1s0 is back in public and all three services are back, and nobody undid it by hand. Where the change went is the subject of the next section.