LINUXOR.SK ... open source notes ...

Proxy - rich rules on dc2-a-vcprx001

category: solutionz/proxy · date: 2019-12-31 · updated: 2026-10-03 · author: LALA

Proxy Solution · Config document · referenced from firewalld rich rules

noteThe fourth line is not what was entered: the IPv6 rule for port 3128 was added with the destination 2001:db8:a2:b96::f:1/128, this host's address, and is listed here with 2001:db8:a1:b96::f:1/128, the address of the datacenter 1 proxy. The fifth line was entered with family=ipv4 and is listed without a family. The listing is reproduced as the notes hold it.

The permanent rich rules of zone internal on the datacenter 2 proxy dc2-a-vcprx001 as firewall-cmd printed them after the final reload: twenty-nine rules, in the order they were added, for five purposes. The command set that produced them is the Config document firewalld on dc2-a-vcprx001. It ran as root on dc2-a-vcprx001 and reads only.

ItemValue
Commandfirewall-cmd --permanent --zone=internal --list-rich-rules
On which hostdc2-a-vcprx001.adm.example.net, RHEL 7.5; zone internal is bound to ens3, 10.12.16.113 and 2001:db8:a2:b96::f:1
Run asroot
Rules29: 4 proxy port, 1 ICMP, 8 Ansible SSH, 4 management SSH, 12 Sensu SNMP
Not in itthe direct rule for ICMPv6, which is not a rich rule; the zones external and public, which listed nothing

The listing

bash
$ firewall-cmd --permanent --zone=internal --list-rich-rules
output 29 lines
rule family="ipv4" source address="192.168.0.0/16" destination address="10.12.16.113/32" port port="3128" protocol="tcp" accept
rule family="ipv4" source address="172.16.0.0/12" destination address="10.12.16.113/32" port port="3128" protocol="tcp" accept
rule family="ipv4" source address="10.0.0.0/8" destination address="10.12.16.113/32" port port="3128" protocol="tcp" accept
rule family="ipv6" source address="2001:db8::/32" destination address="2001:db8:a1:b96::f:1/128" port port="3128" protocol="tcp" accept
rule protocol value="icmp" accept
rule family="ipv4" source address="10.11.17.241/32" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept
rule family="ipv4" source address="10.11.17.242/32" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept
rule family="ipv4" source address="10.12.17.241/32" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept
rule family="ipv4" source address="10.12.17.242/32" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept
rule family="ipv6" source address="2001:db8:a1:b89::f:1/128" destination address="2001:db8:a2:b96::f:1/128" port port="22" protocol="tcp" accept
rule family="ipv6" source address="2001:db8:a1:b89::f:2/128" destination address="2001:db8:a2:b96::f:1/128" port port="22" protocol="tcp" accept
rule family="ipv6" source address="2001:db8:a2:b89::f:1/128" destination address="2001:db8:a2:b96::f:1/128" port port="22" protocol="tcp" accept
rule family="ipv6" source address="2001:db8:a2:b89::f:2/128" destination address="2001:db8:a2:b96::f:1/128" port port="22" protocol="tcp" accept
rule family="ipv4" source address="192.168.0.0/16" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept
rule family="ipv4" source address="172.16.0.0/12" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept
rule family="ipv4" source address="10.0.0.0/8" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept
rule family="ipv6" source address="2001:db8::/32" destination address="2001:db8:a2:b96::f:1/128" port port="22" protocol="tcp" accept
rule family="ipv4" source address="10.11.16.129/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept
rule family="ipv4" source address="10.11.16.130/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept
rule family="ipv4" source address="10.11.16.131/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept
rule family="ipv4" source address="10.12.16.129/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept
rule family="ipv4" source address="10.12.16.130/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept
rule family="ipv4" source address="10.12.16.131/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept
rule family="ipv6" source address="2001:db8:a1:bb1::f:1/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept
rule family="ipv6" source address="2001:db8:a1:bb1::f:2/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept
rule family="ipv6" source address="2001:db8:a1:bb1::f:3/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept
rule family="ipv6" source address="2001:db8:a2:bb1::f:1/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept
rule family="ipv6" source address="2001:db8:a2:bb1::f:2/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept
rule family="ipv6" source address="2001:db8:a2:bb1::f:3/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept

The groups

LinesPurposeSourceDestinationPort
1 to 3Proxy port, IPv4192.168.0.0/16, 172.16.0.0/12, 10.0.0.0/810.12.16.113/32TCP 3128
4Proxy port, IPv62001:db8::/322001:db8:a1:b96::f:1/128 as listed, the datacenter 1 addressTCP 3128
5ICMPanyanyprotocol icmp
6 to 9Ansible SSH, IPv410.11.17.241, 10.11.17.242 (datacenter 1), 10.12.17.241, 10.12.17.242 (datacenter 2)10.12.16.113/32TCP 22
10 to 13Ansible SSH, IPv62001:db8:a1:b89::f:1, ::f:2 (datacenter 1), 2001:db8:a2:b89::f:1, ::f:2 (datacenter 2)2001:db8:a2:b96::f:1/128TCP 22
14 to 16Management SSH, IPv4the three RFC 1918 ranges10.12.16.113/32TCP 22
17Management SSH, IPv62001:db8::/322001:db8:a2:b96::f:1/128TCP 22
18 to 23Sensu SNMP, IPv410.11.16.129 to .131 (datacenter 1), 10.12.16.129 to .131 (datacenter 2)10.12.16.113/32UDP 161
24 to 29Sensu SNMP, IPv62001:db8:a1:bb1::f:1 to ::f:3 (datacenter 1), 2001:db8:a2:bb1::f:1 to ::f:3 (datacenter 2)2001:db8:a2:b96::f:1/128UDP 161

The listing prints every value in double quotes, which the commands did not use; that is how firewall-cmd writes rich rules back and means nothing. The order is the order of entry. The four Ansible rules and the six Sensu rules of datacenter 1 (lines 6, 7, 10, 11 and 18 to 20, 24 to 26) make the main difference from the datacenter 1 host, which has only its own Ansible and Sensu hosts; the others are the family=ipv4 on the ICMP rule as entered here, and the direct rule for ICMPv6 that this host has and datacenter 1 does not. Why datacenter 2 was opened to both sets the notes do not say.

Line 4 is doubtful. If the rule had the datacenter 1 address as destination, no packet arriving on ens3 of this host matched it, and IPv6 clients could not reach port 3128 at all; if the listing was edited by hand in the notes and the rule had this host's address, as the command says, everything was fine. That is my reading of the two possibilities; the notes hold nothing that decides between them, no ip6tables -L and no test from an IPv6 client. The management SSH rule on line 17, entered in the same session with the same source, has the right address.

Checked against firewalld 2.5.2

As builtToday
Listed by firewalld-0.4.4.4-14.el7 on RHEL 7.5firewalld 2.5.2 (September 2026); RHEL 9 ships 1.3.4, RHEL 10 2.3.1 and later 2.4.3. RHEL 7 left Maintenance Support on 30 June 2024
rule family="ipv4" source address="…" destination address="…" port port="3128" protocol="tcp" acceptThe rich rule grammar is unchanged, so all twenty-nine lines are valid rules today. Added since: a priority= attribute (-32768 to 32767, lower first) and the port protocols sctp and dccp. None of these rules has a priority
rule protocol value="icmp" accept without a familyStill valid: the man page requires a family only "if source or destination addresses are used in a rule", and this rule has none. Since 1.0.0 a zone with the default target accepts ICMP by itself; on this DROP zone the rule is still needed
The ICMPv6 direct rule, not in this listingThe direct interface is deprecated since 1.0.0 and "superseded by policies"; its replacement, the rich rule rule family="ipv6" protocol value="ipv6-icmp" accept, would appear in this listing as a thirtieth line
--permanent --zone=internal --list-rich-rulesDocumented with the same meaning; --add-rich-rule likewise

The listing would look the same on a current firewalld, with one more line if the ICMPv6 rule were written as a rich rule instead of a direct rule.

← solutionz/proxy