CompTIA Linux+ (XK0-006)SecurityMedium

A network administrator needs to allow SSH access on a firewalld-managed server, but only from hosts within the 192.168.1.0/24 subnet, while leaving the default zone's SSH service disabled for all other sources. Which command should be used?

  1. Afirewall-cmd --permanent --add-port=22/tcp
  2. Bfirewall-cmd --permanent --zone=public --add-service=ssh
  3. Cfirewall-cmd --permanent --zone=public --add-source=192.168.1.0/24
  4. Dfirewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" service name="ssh" accept'
Show answer & explanation

Correct answer: D. firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" service name="ssh" accept'

Rich rules in firewalld allow granular control combining source restrictions with specific services or ports, something the basic --add-service or --add-port options cannot do alone. This rule permits SSH only from the specified subnet.

Why the other options are wrong

  • A. This opens port 22 to all sources without any subnet restriction.
  • B. This opens SSH for the entire zone regardless of source, which is too broad.
  • C. add-source assigns the entire subnet to the zone but doesn't specifically limit SSH to that source alone.

firewalld Rich Rules

Rich rules provide fine-grained firewalld syntax to combine sources, services, ports, and actions (accept/reject/drop) beyond what basic zone commands allow.

  • Syntax: rule family=... source address=... service name=... accept
  • Rich rules take priority over zone-wide service settings
  • Must reload firewalld or use --permanent then --reload to apply

Memory trick: Rich rules are the 'fine print' firewalld uses for precise targeting.

More Security questions