From 2b76da0df5f8c8ebd103bdd1d41eb4b5189d7e53 Mon Sep 17 00:00:00 2001 From: johannst Date: Wed, 11 Jan 2023 15:48:12 +0000 Subject: deploy: 0c50a95dc93471cf69f522adfc31ff4c56c53e9d --- network/assets/nf_pkt_flow.ora | Bin 0 -> 2306553 bytes network/assets/nf_pkt_flow.png | Bin 0 -> 774896 bytes network/firewall-cmd.html | 10 +- network/index.html | 3 +- network/nftables.html | 289 +++++++++++++++++++++++++++++++++++++++++ network/tcpdump.html | 2 +- 6 files changed, 299 insertions(+), 5 deletions(-) create mode 100644 network/assets/nf_pkt_flow.ora create mode 100644 network/assets/nf_pkt_flow.png create mode 100644 network/nftables.html (limited to 'network') diff --git a/network/assets/nf_pkt_flow.ora b/network/assets/nf_pkt_flow.ora new file mode 100644 index 0000000..c544898 Binary files /dev/null and b/network/assets/nf_pkt_flow.ora differ diff --git a/network/assets/nf_pkt_flow.png b/network/assets/nf_pkt_flow.png new file mode 100644 index 0000000..74b37e7 Binary files /dev/null and b/network/assets/nf_pkt_flow.png differ diff --git a/network/firewall-cmd.html b/network/firewall-cmd.html index 3db7bdf..45294f9 100644 --- a/network/firewall-cmd.html +++ b/network/firewall-cmd.html @@ -80,7 +80,7 @@ @@ -164,12 +164,16 @@ see all available zones.

firewall-cmd --add-service <SERVICE> # Add a specific port. firewall-cmd --add-port 8000/tcp +# Add a rich rule (eg port forwarding, dnat). +firewall-cmd --add-rich-rule 'rule family="ipv4" forward-port port="80" protocol="tcp" to-port="8080"'

Remove entries

# Remove service.
 firewall-cmd --remove-service <SERVICE>
 # Remove port.
 firewall-cmd --remove-port 8000/tcp
+# Remove rich rule.
+firewall-cmd --remove-rich-rule 'rule family="ipv4" forward-port port="80" protocol="tcp" to-port="8080"'
 

References