CompTIA Linux+ (XK0-006)SecurityMedium
A network administrator needs to allow SSH access on a firewalld-managed server, but only from hosts within the 192.168.1.0/24 subnet, while leaving the default zone's SSH service disabled for all other sources. Which command should be used?
- Afirewall-cmd --permanent --add-port=22/tcp
- Bfirewall-cmd --permanent --zone=public --add-service=ssh
- Cfirewall-cmd --permanent --zone=public --add-source=192.168.1.0/24
- Dfirewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" service name="ssh" accept'
Show answer & explanationAnswer & explanation
Correct answer: D. firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" service name="ssh" accept'
Rich rules in firewalld allow granular control combining source restrictions with specific services or ports, something the basic --add-service or --add-port options cannot do alone. This rule permits SSH only from the specified subnet.
Why the other options are wrong
- A. This opens port 22 to all sources without any subnet restriction.
- B. This opens SSH for the entire zone regardless of source, which is too broad.
- C. add-source assigns the entire subnet to the zone but doesn't specifically limit SSH to that source alone.
firewalld Rich Rules
Rich rules provide fine-grained firewalld syntax to combine sources, services, ports, and actions (accept/reject/drop) beyond what basic zone commands allow.
- Syntax: rule family=... source address=... service name=... accept
- Rich rules take priority over zone-wide service settings
- Must reload firewalld or use --permanent then --reload to apply
Memory trick: Rich rules are the 'fine print' firewalld uses for precise targeting.