CompTIA Linux+ (XK0-006)SecurityMedium

A system administrator is hardening a new server and needs to configure firewalld to allow incoming HTTPS traffic only from the internal network (10.0.0.0/8) while blocking it from all other sources. Which of the following firewalld-cmd commands correctly implements this requirement?

  1. Afirewall-cmd --zone=internal --add-source=10.0.0.0/8 --add-service=https --permanent; firewall-cmd --reload
  2. Bfirewall-cmd --add-port=443/tcp --permanent; firewall-cmd --reload
  3. Cfirewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" service name="https" accept' --permanent; firewall-cmd --reload
  4. Dfirewall-cmd --zone=public --add-service=https --permanent; firewall-cmd --reload
Show answer & explanation

Correct answer: C. firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" service name="https" accept' --permanent; firewall-cmd --reload

Rich rules in firewalld are designed for more complex firewall policies, including source-specific restrictions for services or ports. Option B correctly uses a rich rule to allow HTTPS traffic only from the specified source IP range.

Why the other options are wrong

  • A. While adding a source to a zone is possible, it doesn't explicitly restrict the *service* to that source within the 'internal' zone in a way that blocks others from 'public' unless other rules are in place.
  • B. This command opens port 443/tcp from all sources (in the default zone), not restricted to a specific IP range.
  • D. This command allows HTTPS from all sources in the public zone, not restricted to a specific IP range.

firewalld Rich Rules for Source Filtering

firewalld rich rules provide granular control to allow or deny traffic based on source IP, service, port, and other criteria.

  • Syntax: 'rule family="ipv4|ipv6" source address="IP/CIDR" service name="svc" accept|reject|drop'.
  • Used for complex policies not covered by direct service/port additions.
  • Must be applied with '--permanent' for persistence and then '--reload'.

Memory trick: Firewall: Zones, Services, Ports, then Rich for complex.

More Security questions