CompTIA Linux+ (XK0-006)TroubleshootingMedium
A user reports that they are unable to connect to a web application running on a Linux server via SSH, even though they can `ping` the server's IP address. The application is confirmed to be listening on TCP port 2222. The administrator discovers that the server's firewall (using `firewalld`) is currently configured to allow only SSH (port 22) and HTTP (port 80) services. Which `firewall-cmd` command would allow access to the web application without permanently opening port 2222 for all services?
- A`firewall-cmd --zone=public --add-service=http --permanent && firewall-cmd --reload`
- B`firewall-cmd --add-port=2222/tcp --permanent && firewall-cmd --reload`
- C`firewall-cmd --add-service=ssh --permanent && firewall-cmd --reload`
- D`firewall-cmd --zone=public --add-port=2222/tcp --permanent && firewall-cmd --reload`
Show answer & explanationAnswer & explanation
Correct answer: D. `firewall-cmd --zone=public --add-port=2222/tcp --permanent && firewall-cmd --reload`
To allow access to a specific port for a service that doesn't have a predefined `firewalld` service (or if you want to be explicit), you use `--add-port`. Specifying `--zone=public` ensures it applies to the default external zone, `--permanent` makes the change persist across reboots, and `--reload` applies the changes to the running firewall.
Why the other options are wrong
- A. This command adds the `http` service (port 80), not the custom port 2222 for the web application.
- B. This command is missing the `--zone` parameter, which is good practice to explicitly define the zone.
- C. This command adds the `ssh` service (port 22), which is already allowed and not the target web application port.
firewall-cmd --add-port
The `firewall-cmd --add-port` command is used to open a specific TCP or UDP port through the `firewalld` firewall, optionally specifying a zone and making the change permanent.
- Syntax: `firewall-cmd --zone=<zone> --add-port=<port>/<protocol> --permanent`.
- Requires `--reload` to apply permanent changes immediately.
- Used when a service doesn't have a predefined `firewalld` service or for custom ports.
Memory trick: To add a 'P'ort, you need to 'P'ermanently 'P'ut it in the 'P'ublic zone and then 'R'eload.