CompTIA Linux+ (XK0-006)SecurityMedium
A system administrator is hardening a new server and needs to configure firewalld to allow incoming HTTPS traffic only from the internal network (10.0.0.0/8) while blocking it from all other sources. Which of the following firewalld-cmd commands correctly implements this requirement?
- Afirewall-cmd --zone=internal --add-source=10.0.0.0/8 --add-service=https --permanent; firewall-cmd --reload
- Bfirewall-cmd --add-port=443/tcp --permanent; firewall-cmd --reload
- Cfirewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" service name="https" accept' --permanent; firewall-cmd --reload
- Dfirewall-cmd --zone=public --add-service=https --permanent; firewall-cmd --reload
Show answer & explanationAnswer & explanation
Correct answer: C. firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" service name="https" accept' --permanent; firewall-cmd --reload
Rich rules in firewalld are designed for more complex firewall policies, including source-specific restrictions for services or ports. Option B correctly uses a rich rule to allow HTTPS traffic only from the specified source IP range.
Why the other options are wrong
- A. While adding a source to a zone is possible, it doesn't explicitly restrict the *service* to that source within the 'internal' zone in a way that blocks others from 'public' unless other rules are in place.
- B. This command opens port 443/tcp from all sources (in the default zone), not restricted to a specific IP range.
- D. This command allows HTTPS from all sources in the public zone, not restricted to a specific IP range.
firewalld Rich Rules for Source Filtering
firewalld rich rules provide granular control to allow or deny traffic based on source IP, service, port, and other criteria.
- Syntax: 'rule family="ipv4|ipv6" source address="IP/CIDR" service name="svc" accept|reject|drop'.
- Used for complex policies not covered by direct service/port additions.
- Must be applied with '--permanent' for persistence and then '--reload'.
Memory trick: Firewall: Zones, Services, Ports, then Rich for complex.