aboutsummaryrefslogtreecommitdiffhomepage
path: root/src/network
diff options
context:
space:
mode:
Diffstat (limited to 'src/network')
-rw-r--r--src/network/README.md1
-rw-r--r--src/network/firewall-cmd.md39
2 files changed, 40 insertions, 0 deletions
diff --git a/src/network/README.md b/src/network/README.md
index 80ecc7b..0869e11 100644
--- a/src/network/README.md
+++ b/src/network/README.md
@@ -2,3 +2,4 @@
# Network
- [tcpdump](./tcpdump.md)
+- [firewall-cmd](./firewall-cmd.md)
diff --git a/src/network/firewall-cmd.md b/src/network/firewall-cmd.md
new file mode 100644
index 0000000..315bbd8
--- /dev/null
+++ b/src/network/firewall-cmd.md
@@ -0,0 +1,39 @@
+# firewall-cmd(1)
+
+Command line interface to the [firewalld(1)][man-firewalld] daemon.
+
+## List current status of the firewall
+```sh
+# List all services and ports for all zones.
+firewall-cmd --list-all
+# List all services.
+firewall-cmd --list-services
+# List all ports.
+firewall-cmd --list-ports
+```
+> Add `--zone <ZONE>` to limit output to a given `ZONE`. Use `--get-zones` to
+> see all available zones.
+
+## Add entries
+```sh
+# Add a service to the firewall, use `--get-services` to list all available
+# service names.
+firewall-cmd --add-service <SERVICE>
+# Add a specific port.
+firewall-cmd --add-port 8000/tcp
+```
+
+## Remove entries
+```sh
+# Remove service.
+firewall-cmd --remove-service <SERVICE>
+# Remove port.
+firewall-cmd --remove-port 8000/tcp
+```
+
+## References
+- man [firewall-cmd(1)][man-firewall-cmd]
+- man [firewalld(1)][man-firewalld]
+
+[man-firewalld]: https://firewalld.org/documentation/man-pages/firewalld.html
+[man-firewall-cmd]: https://firewalld.org/documentation/man-pages/firewall-cmd.html