Exercise
Serve a Web Page on a Custom Port Exercise
Task
Serve a web page from workstation on port
8484 and read it from servera. Earlier
exercises this week each handled one piece of this: the
Listen line, the firewall port, and the
SELinux port label. This time you set up all three
before starting the server, so it works on the first
try.
- Host
-
workstation, fromservera
-
Install httpd and write a page
From
servera, connect toworkstation:ssh student@workstation sudo dnf install -y httpd echo "<h1>Served from workstation</h1>" | sudo tee /var/www/html/index.html -
Point Apache's Listen line at 8484
sudo vim /etc/httpd/conf/httpd.confSearch for the line with
/^Listen 80and press Enter. Press C to change the rest of the line, typeListen 8484, press Esc, then write the file with:wq.grep ^Listen /etc/httpd/conf/httpd.confThe file should now show
Listen 8484and nothing else on that line. -
Open 8484/tcp in the firewall
sudo firewall-cmd --add-port=8484/tcp --permanent sudo firewall-cmd --reload sudo firewall-cmd --list-all8484/tcpappears on theports:line. The port is open, but nothing listens on it yet. -
Label 8484 for SELinux
sudo semanage port -l | grep ^http8484 is on none of the
httplines, so SELinux would denyhttpdthe port. Add the label, then list your own changes:sudo semanage port -a -t http_port_t -p tcp 8484 sudo semanage port -l -C -
Start httpd
sudo systemctl enable --now httpd.service systemctl is-active httpd.serviceThe service reports
active. There is no failure to diagnose, nosealertreport, and no trip into permissive mode, because every piece was in place before the start. -
Request the page from servera
exit curl http://workstation:8484The page arrives:
<h1>Served from workstation</h1>. Apache listens on the port, the firewall allows it, and SELinux labels it. Those are the same three pieces from every exercise this week, done in one pass. -
Put workstation back the way you found it
ssh student@workstation sudo systemctl disable --now httpd.service sudo semanage port -d -t http_port_t -p tcp 8484 sudo firewall-cmd --permanent --remove-port=8484/tcp sudo firewall-cmd --reloadThen undo the
Listenedit, so the package removal leaves nothing behind in/etc/httpd:sudo vim /etc/httpd/conf/httpd.confSearch with
/^Listen 8484, press C, typeListen 80, press Esc, and save with:wq. Delete the page before removing the package, so the removal leaves nothing behind in/var/www:sudo rm -f /var/www/html/index.html sudo dnf remove -y httpd