Vault - firewalld rules (Vault node)
Vault Solution · Config document · referenced from Network design and firewall flows, Linux hardening
The complete host firewall of a Vault node, as the sequence of firewall-cmd calls that built it. The predefined ssh, cockpit and dhcpv6-client services were removed from the zone first, so these rich rules are the only way in.
| Item | Value |
|---|---|
| Shown here | prod-vault-node1 (10.10.1.34) |
| Deployed on | every Vault node, with its own address as the destination |
| Zone | public |
| Backend | FirewallBackend=iptables, AllowZoneDrifting=no in /etc/firewalld/firewalld.conf |
The file
#!/bin/bash # # firewalld rich rules, zone "public" - prod-vault-node1 # # In zone "public" allow access to SSH (TCP/22) from NET_PROD_VAULT_ADMIN (10.10.3.16/29) to VM_PROD_VAULT_NODE1 (10.10.1.34/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.3.16/29 destination address=10.10.1.34/32 port port=22 protocol=tcp accept' # In zone "public" allow access to Vault-service port (TCP/8200) from NET_PROD_VAULT_LB (10.10.2.8/29) to VM_PROD_VAULT_NODE1 (10.10.1.34/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.2.8/29 destination address=10.10.1.34/32 port port=8200 protocol=tcp accept' # In zone "public" allow access to Vault-service port (TCP/8200) from NET_PROD_VAULT_SERVICE (10.10.1.32/28) to VM_PROD_VAULT_NODE1 (10.10.1.34/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.1.32/28 destination address=10.10.1.34/32 port port=8200 protocol=tcp accept' # In zone "public" allow access to Vault-cluster port (TCP/8201) from NET_PROD_VAULT_SERVICE (10.10.1.32/28) to VM_PROD_VAULT_NODE1 (10.10.1.34/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.1.32/28 destination address=10.10.1.34/32 port port=8201 protocol=tcp accept' # In zone "public" allow access to ZABBIX port (TCP/10050) from NET_ZABBIX (10.40.1.16/28) to NET_PROD_VAULT_SERVICE (10.10.1.32/28) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.40.1.16/28 destination address=10.10.1.32/28 port port=10050 protocol=tcp accept' # Reload firewallD rules firewall-cmd --reload # List of all rich rules in zone "public" firewall-cmd --zone=public --list-rich-rules
Rules in one table
| From | To | Port | Purpose |
|---|---|---|---|
Admin network 10.10.3.16/29 | this node | TCP 22 | SSH from the bastion host |
Load-balancer network 10.10.2.8/29 | this node | TCP 8200 | Vault API through HAProxy |
Service network 10.10.1.32/28 | this node | TCP 8200 | retry_join and API between nodes |
Service network 10.10.1.32/28 | this node | TCP 8201 | Raft and request forwarding |
Monitoring network 10.40.1.16/28 | service network | TCP 10050 | Zabbix agent |
A sixth rule, SSH between the Vault nodes themselves, existed while snapshots were copied from node to node with rsync, and was removed with that mechanism; see Raft snapshots, backup and restore.