LINUXOR.SK ... open source notes ...

Vault - firewalld rules (Vault node)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Network design and firewall flows, Linux hardening

The complete host firewall of a Vault node, as the sequence of firewall-cmd calls that built it. The predefined ssh, cockpit and dhcpv6-client services were removed from the zone first, so these rich rules are the only way in.

ItemValue
Shown hereprod-vault-node1 (10.10.1.34)
Deployed onevery Vault node, with its own address as the destination
Zonepublic
BackendFirewallBackend=iptables, AllowZoneDrifting=no in /etc/firewalld/firewalld.conf

The file

bash
#!/bin/bash
#
# firewalld rich rules, zone "public" - prod-vault-node1
#

# In zone "public" allow access to SSH (TCP/22) from NET_PROD_VAULT_ADMIN (10.10.3.16/29) to VM_PROD_VAULT_NODE1 (10.10.1.34/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.3.16/29 destination address=10.10.1.34/32 port port=22 protocol=tcp accept'

# In zone "public" allow access to Vault-service port (TCP/8200) from NET_PROD_VAULT_LB (10.10.2.8/29) to VM_PROD_VAULT_NODE1 (10.10.1.34/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.2.8/29 destination address=10.10.1.34/32 port port=8200 protocol=tcp accept'

# In zone "public" allow access to Vault-service port (TCP/8200) from NET_PROD_VAULT_SERVICE (10.10.1.32/28) to VM_PROD_VAULT_NODE1 (10.10.1.34/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.1.32/28 destination address=10.10.1.34/32 port port=8200 protocol=tcp accept'

# In zone "public" allow access to Vault-cluster port (TCP/8201) from NET_PROD_VAULT_SERVICE (10.10.1.32/28) to VM_PROD_VAULT_NODE1 (10.10.1.34/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.1.32/28 destination address=10.10.1.34/32 port port=8201 protocol=tcp accept'

# In zone "public" allow access to ZABBIX port (TCP/10050) from NET_ZABBIX (10.40.1.16/28) to NET_PROD_VAULT_SERVICE (10.10.1.32/28)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.40.1.16/28 destination address=10.10.1.32/28 port port=10050 protocol=tcp accept'

# Reload firewallD rules
firewall-cmd --reload

# List of all rich rules in zone "public"
firewall-cmd --zone=public --list-rich-rules

Rules in one table

FromToPortPurpose
Admin network 10.10.3.16/29this nodeTCP 22SSH from the bastion host
Load-balancer network 10.10.2.8/29this nodeTCP 8200Vault API through HAProxy
Service network 10.10.1.32/28this nodeTCP 8200retry_join and API between nodes
Service network 10.10.1.32/28this nodeTCP 8201Raft and request forwarding
Monitoring network 10.40.1.16/28service networkTCP 10050Zabbix agent

A sixth rule, SSH between the Vault nodes themselves, existed while snapshots were copied from node to node with rsync, and was removed with that mechanism; see Raft snapshots, backup and restore.

← solutionz