Update firewallcmd-common.conf

pull/1424/head
TorontoMedia 2016-05-13 22:38:10 -04:00
parent 810d5996b5
commit 07de83e04a
1 changed files with 14 additions and 4 deletions

View File

@ -10,6 +10,16 @@
# Values: STRING # Values: STRING
name = default name = default
# Option port
# Notes Can also use port numbers separated by a comma and in rich-rules comma and/or space.
# Value STRING Default: 1:65535
port = 1:65535
# Option: protocol
# Notes [ tcp | udp | icmp | all ]
# Values: STRING Default: tcp
protocol = tcp
# Option: family(ipv4) # Option: family(ipv4)
# Notes specifies the socket address family type # Notes specifies the socket address family type
# Values: STRING # Values: STRING
@ -28,7 +38,7 @@ zone = public
# Option: service # Option: service
# Notes use command firewall-cmd --get-services to see a list of services available # Notes use command firewall-cmd --get-services to see a list of services available
# Examples zones: amanda-client amanda-k5-client bacula bacula-client dhcp dhcpv6 dhcpv6-client dns freeipa-ldap freeipa-ldaps # Examples services: amanda-client amanda-k5-client bacula bacula-client dhcp dhcpv6 dhcpv6-client dns freeipa-ldap freeipa-ldaps
# freeipa-replication ftp high-availability http https imaps ipp ipp-client ipsec iscsi-target kadmin kerberos # freeipa-replication ftp high-availability http https imaps ipp ipp-client ipsec iscsi-target kadmin kerberos
# kpasswd ldap ldaps libvirt libvirt-tls mdns mosh mountd ms-wbt mysql nfs ntp openvpn pmcd pmproxy pmwebapi pmwebapis pop3s # kpasswd ldap ldaps libvirt libvirt-tls mdns mosh mountd ms-wbt mysql nfs ntp openvpn pmcd pmproxy pmwebapi pmwebapis pop3s
# postgresql privoxy proxy-dhcp puppetmaster radius rpc-bind rsyncd samba samba-client sane smtp squid ssh synergy # postgresql privoxy proxy-dhcp puppetmaster radius rpc-bind rsyncd samba samba-client sane smtp squid ssh synergy
@ -37,18 +47,18 @@ zone = public
service = ssh service = ssh
# Option: rejecttype (ipv4) # Option: rejecttype (ipv4)
# Note: See iptables/firewalld man pages for ipv4 reject types. # Notes See iptables/firewalld man pages for ipv4 reject types.
# Values: STRING # Values: STRING
rejecttype = icmp-port-unreachable rejecttype = icmp-port-unreachable
# Option: blocktype (ipv4/ipv6) # Option: blocktype (ipv4/ipv6)
# Note: See iptables/firewalld man pages for jump targets. Common values are REJECT, # Notes See iptables/firewalld man pages for jump targets. Common values are REJECT,
# REJECT --reject-with icmp-port-unreachable, DROP # REJECT --reject-with icmp-port-unreachable, DROP
# Values: STRING # Values: STRING
blocktype = REJECT --reject-with <rejecttype> blocktype = REJECT --reject-with <rejecttype>
# Option: rich-blocktype (ipv4/ipv6) # Option: rich-blocktype (ipv4/ipv6)
# Note: See firewalld man pages for jump targets. Common values are reject, # Notes See firewalld man pages for jump targets. Common values are reject,
# reject type="icmp-port-unreachable", drop # reject type="icmp-port-unreachable", drop
# Values: STRING # Values: STRING
rich-blocktype = reject type='<rejecttype>' rich-blocktype = reject type='<rejecttype>'