Linux: Firewalls and SELinux

Linux: Firewalls and SELinux

2h 22mIntermediate2017-04-21

Authors

Sean Colins

Sean Colins

Management Consultant, Author, Trainer, and Entrepreneur

Course details

This course takes you through the basics of firewalls on Linux. Sean Colins shows you how to configure Firewalld for local protection, work with SELinux, and troubleshoot firewalls. He also covers iptables, default policies, port blocking, and port forwarding. Learn how to install GUI controls and utilities, manage zones and services, enable servers, set access controls, change ports, move files, and more.

Learning objectives
Working with iptables
Installing Firewalld
Exploring zones and services
Allowing the Apache web server
Allowing FTP and SFTP servers
Installing SELinux utils
Setting discretionary or mandatory access
Installing SELinux man pages
Working with Booleans
Changing context labels
Running sepolicy
Finding SELinux logs
Making domains permissive
Disabling and reenabling SELinux

Skills covered

LinuxNetwork AdministrationNetwork and System AdministrationOpen Source

Concepts

Introduction

  • Welcome to firewalls and SELinux
  • Prerequisites

Firewall Basics on Linux

  • Iptables and Firewalld
  • Installing Firewalld
  • Installing the Firewalld GUI controls
  • Installing GUI controls with no GUI
  • Understand Firewalld zones
  • Understand Firewalld services
  • Zones explored

Configuring Firewalld for Local Protection

  • Firewall-cmd configuration preparation
  • Allowing the Apache web server
  • Allowing any mail server
  • Allowing an XMPP server
  • Allowing an SMB server
  • Allowing an NFS server
  • Allowing an LDAP server
  • Allowing a PostgreSQL server
  • Allowing FTP and SFTP servers
  • VM Port Forwarding
  • ShieldsUP panic mode

SELinux Fundamentals

  • Installing SELinux utils
  • Discretionary vs. mandatory access
  • Understanding contexts
  • Installing SELinux man pages
  • Understanding Booleans

Working with SELinux

  • Enabling SELinux and modes
  • Graphical management tools
  • Changing context labels
  • Changing ports on services
  • Copying files
  • Moving files

SELinux Troubleshooting

  • Running sepolicy
  • Finding SELinux logs
  • Making domains permissive
  • Disabling and reenabling SELinux

Conclusion

  • Next steps
80,000 Toman