Exercise

Serve a Web Page on a Custom Port Exercise

Task

Serve a web page from workstation on port 8484 and read it from servera. Earlier exercises this week each handled one piece of this: the Listen line, the firewall port, and the SELinux port label. This time you set up all three before starting the server, so it works on the first try.

Host
workstation, from servera
  1. Install httpd and write a page

    From servera, connect to workstation:

    ssh student@workstation
    sudo dnf install -y httpd
    echo "<h1>Served from workstation</h1>" | sudo tee /var/www/html/index.html
  2. Point Apache's Listen line at 8484

    sudo vim /etc/httpd/conf/httpd.conf

    Search for the line with /^Listen 80 and press Enter. Press C to change the rest of the line, type Listen 8484, press Esc, then write the file with :wq.

    grep ^Listen /etc/httpd/conf/httpd.conf

    The file should now show Listen 8484 and nothing else on that line.

  3. Open 8484/tcp in the firewall

    sudo firewall-cmd --add-port=8484/tcp --permanent
    sudo firewall-cmd --reload
    sudo firewall-cmd --list-all

    8484/tcp appears on the ports: line. The port is open, but nothing listens on it yet.

  4. Label 8484 for SELinux

    sudo semanage port -l | grep ^http

    8484 is on none of the http lines, so SELinux would deny httpd the port. Add the label, then list your own changes:

    sudo semanage port -a -t http_port_t -p tcp 8484
    sudo semanage port -l -C
  5. Start httpd

    sudo systemctl enable --now httpd.service
    systemctl is-active httpd.service

    The service reports active. There is no failure to diagnose, no sealert report, and no trip into permissive mode, because every piece was in place before the start.

  6. Request the page from servera

    exit
    curl http://workstation:8484

    The page arrives: <h1>Served from workstation</h1>. Apache listens on the port, the firewall allows it, and SELinux labels it. Those are the same three pieces from every exercise this week, done in one pass.

  7. Put workstation back the way you found it

    ssh student@workstation
    sudo systemctl disable --now httpd.service
    sudo semanage port -d -t http_port_t -p tcp 8484
    sudo firewall-cmd --permanent --remove-port=8484/tcp
    sudo firewall-cmd --reload

    Then undo the Listen edit, so the package removal leaves nothing behind in /etc/httpd:

    sudo vim /etc/httpd/conf/httpd.conf

    Search with /^Listen 8484, press C, type Listen 80, press Esc, and save with :wq. Delete the page before removing the package, so the removal leaves nothing behind in /var/www:

    sudo rm -f /var/www/html/index.html
    sudo dnf remove -y httpd