Proxy - rich rules on dc2-a-vcprx001
Proxy Solution · Config document · referenced from firewalld rich rules
2001:db8:a2:b96::f:1/128, this host's address, and is listed here with 2001:db8:a1:b96::f:1/128, the address of the datacenter 1 proxy. The fifth line was entered with family=ipv4 and is listed without a family. The listing is reproduced as the notes hold it.The permanent rich rules of zone internal on the datacenter 2 proxy dc2-a-vcprx001 as firewall-cmd printed them after the final reload: twenty-nine rules, in the order they were added, for five purposes. The command set that produced them is the Config document firewalld on dc2-a-vcprx001. It ran as root on dc2-a-vcprx001 and reads only.
| Item | Value |
|---|---|
| Command | firewall-cmd --permanent --zone=internal --list-rich-rules |
| On which host | dc2-a-vcprx001.adm.example.net, RHEL 7.5; zone internal is bound to ens3, 10.12.16.113 and 2001:db8:a2:b96::f:1 |
| Run as | root |
| Rules | 29: 4 proxy port, 1 ICMP, 8 Ansible SSH, 4 management SSH, 12 Sensu SNMP |
| Not in it | the direct rule for ICMPv6, which is not a rich rule; the zones external and public, which listed nothing |
The listing
$ firewall-cmd --permanent --zone=internal --list-rich-rulesoutput 29 lines
rule family="ipv4" source address="192.168.0.0/16" destination address="10.12.16.113/32" port port="3128" protocol="tcp" accept rule family="ipv4" source address="172.16.0.0/12" destination address="10.12.16.113/32" port port="3128" protocol="tcp" accept rule family="ipv4" source address="10.0.0.0/8" destination address="10.12.16.113/32" port port="3128" protocol="tcp" accept rule family="ipv6" source address="2001:db8::/32" destination address="2001:db8:a1:b96::f:1/128" port port="3128" protocol="tcp" accept rule protocol value="icmp" accept rule family="ipv4" source address="10.11.17.241/32" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept rule family="ipv4" source address="10.11.17.242/32" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept rule family="ipv4" source address="10.12.17.241/32" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept rule family="ipv4" source address="10.12.17.242/32" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept rule family="ipv6" source address="2001:db8:a1:b89::f:1/128" destination address="2001:db8:a2:b96::f:1/128" port port="22" protocol="tcp" accept rule family="ipv6" source address="2001:db8:a1:b89::f:2/128" destination address="2001:db8:a2:b96::f:1/128" port port="22" protocol="tcp" accept rule family="ipv6" source address="2001:db8:a2:b89::f:1/128" destination address="2001:db8:a2:b96::f:1/128" port port="22" protocol="tcp" accept rule family="ipv6" source address="2001:db8:a2:b89::f:2/128" destination address="2001:db8:a2:b96::f:1/128" port port="22" protocol="tcp" accept rule family="ipv4" source address="192.168.0.0/16" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept rule family="ipv4" source address="172.16.0.0/12" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept rule family="ipv4" source address="10.0.0.0/8" destination address="10.12.16.113/32" port port="22" protocol="tcp" accept rule family="ipv6" source address="2001:db8::/32" destination address="2001:db8:a2:b96::f:1/128" port port="22" protocol="tcp" accept rule family="ipv4" source address="10.11.16.129/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept rule family="ipv4" source address="10.11.16.130/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept rule family="ipv4" source address="10.11.16.131/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept rule family="ipv4" source address="10.12.16.129/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept rule family="ipv4" source address="10.12.16.130/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept rule family="ipv4" source address="10.12.16.131/32" destination address="10.12.16.113/32" port port="161" protocol="udp" accept rule family="ipv6" source address="2001:db8:a1:bb1::f:1/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept rule family="ipv6" source address="2001:db8:a1:bb1::f:2/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept rule family="ipv6" source address="2001:db8:a1:bb1::f:3/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept rule family="ipv6" source address="2001:db8:a2:bb1::f:1/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept rule family="ipv6" source address="2001:db8:a2:bb1::f:2/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept rule family="ipv6" source address="2001:db8:a2:bb1::f:3/128" destination address="2001:db8:a2:b96::f:1/128" port port="161" protocol="udp" accept
The groups
| Lines | Purpose | Source | Destination | Port |
|---|---|---|---|---|
| 1 to 3 | Proxy port, IPv4 | 192.168.0.0/16, 172.16.0.0/12, 10.0.0.0/8 | 10.12.16.113/32 | TCP 3128 |
| 4 | Proxy port, IPv6 | 2001:db8::/32 | 2001:db8:a1:b96::f:1/128 as listed, the datacenter 1 address | TCP 3128 |
| 5 | ICMP | any | any | protocol icmp |
| 6 to 9 | Ansible SSH, IPv4 | 10.11.17.241, 10.11.17.242 (datacenter 1), 10.12.17.241, 10.12.17.242 (datacenter 2) | 10.12.16.113/32 | TCP 22 |
| 10 to 13 | Ansible SSH, IPv6 | 2001:db8:a1:b89::f:1, ::f:2 (datacenter 1), 2001:db8:a2:b89::f:1, ::f:2 (datacenter 2) | 2001:db8:a2:b96::f:1/128 | TCP 22 |
| 14 to 16 | Management SSH, IPv4 | the three RFC 1918 ranges | 10.12.16.113/32 | TCP 22 |
| 17 | Management SSH, IPv6 | 2001:db8::/32 | 2001:db8:a2:b96::f:1/128 | TCP 22 |
| 18 to 23 | Sensu SNMP, IPv4 | 10.11.16.129 to .131 (datacenter 1), 10.12.16.129 to .131 (datacenter 2) | 10.12.16.113/32 | UDP 161 |
| 24 to 29 | Sensu SNMP, IPv6 | 2001:db8:a1:bb1::f:1 to ::f:3 (datacenter 1), 2001:db8:a2:bb1::f:1 to ::f:3 (datacenter 2) | 2001:db8:a2:b96::f:1/128 | UDP 161 |
The listing prints every value in double quotes, which the commands did not use; that is how firewall-cmd writes rich rules back and means nothing. The order is the order of entry. The four Ansible rules and the six Sensu rules of datacenter 1 (lines 6, 7, 10, 11 and 18 to 20, 24 to 26) make the main difference from the datacenter 1 host, which has only its own Ansible and Sensu hosts; the others are the family=ipv4 on the ICMP rule as entered here, and the direct rule for ICMPv6 that this host has and datacenter 1 does not. Why datacenter 2 was opened to both sets the notes do not say.
Line 4 is doubtful. If the rule had the datacenter 1 address as destination, no packet arriving on ens3 of this host matched it, and IPv6 clients could not reach port 3128 at all; if the listing was edited by hand in the notes and the rule had this host's address, as the command says, everything was fine. That is my reading of the two possibilities; the notes hold nothing that decides between them, no ip6tables -L and no test from an IPv6 client. The management SSH rule on line 17, entered in the same session with the same source, has the right address.
Checked against firewalld 2.5.2
| As built | Today |
|---|---|
Listed by firewalld-0.4.4.4-14.el7 on RHEL 7.5 | firewalld 2.5.2 (September 2026); RHEL 9 ships 1.3.4, RHEL 10 2.3.1 and later 2.4.3. RHEL 7 left Maintenance Support on 30 June 2024 |
rule family="ipv4" source address="…" destination address="…" port port="3128" protocol="tcp" accept | The rich rule grammar is unchanged, so all twenty-nine lines are valid rules today. Added since: a priority= attribute (-32768 to 32767, lower first) and the port protocols sctp and dccp. None of these rules has a priority |
rule protocol value="icmp" accept without a family | Still valid: the man page requires a family only "if source or destination addresses are used in a rule", and this rule has none. Since 1.0.0 a zone with the default target accepts ICMP by itself; on this DROP zone the rule is still needed |
| The ICMPv6 direct rule, not in this listing | The direct interface is deprecated since 1.0.0 and "superseded by policies"; its replacement, the rich rule rule family="ipv6" protocol value="ipv6-icmp" accept, would appear in this listing as a thirtieth line |
--permanent --zone=internal --list-rich-rules | Documented with the same meaning; --add-rich-rule likewise |
The listing would look the same on a current firewalld, with one more line if the ICMPv6 rule were written as a rich rule instead of a direct rule.