Vault - firewalld rules (bastion host)
Vault Solution · Config document · referenced from Network design and firewall flows, Linux hardening
The complete host firewall of the bastion host, the only server administrators can reach from outside the three Vault networks.
| Item | Value |
|---|---|
| Shown here | prod-vault-bastion1 (10.10.3.18) |
| Deployed on | the bastion host of every environment |
| Zone | public |
The file
#!/bin/bash # # firewalld rich rules, zone "public" - prod-vault-bastion1 # # In zone "public" allow access to SSH (TCP/22) from NET_ADMIN_ACCESS_1 (10.41.1.16/28) to VM_PROD_VAULT_BASTION1 (10.10.3.18/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.41.1.16/28 destination address=10.10.3.18/32 port port=22 protocol=tcp accept' # In zone "public" allow access to SSH (TCP/22) from NET_ADMIN_ACCESS_2 (10.41.1.32/28) to VM_PROD_VAULT_BASTION1 (10.10.3.18/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.41.1.32/28 destination address=10.10.3.18/32 port port=22 protocol=tcp accept' # In zone "public" allow access to ZABBIX port (TCP/10050) from NET_ZABBIX (10.40.1.16/28) to NET_PROD_VAULT_ADMIN (10.10.3.16/29) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.40.1.16/28 destination address=10.10.2.8/29 port port=10050 protocol=tcp accept' # Reload firewallD rules firewall-cmd --reload # List of all rich rules in zone "public" firewall-cmd --zone=public --list-rich-rules
Rules in one table
| From | To | Port | Purpose |
|---|---|---|---|
Administrator access networks 10.41.1.16/28, 10.41.1.32/28 | this host | TCP 22 | SSH for administrators, after the corporate access gateway |
Monitoring network 10.40.1.16/28 | admin network | TCP 10050 | Zabbix agent |
As-built quirk
The comment of rule 3 names the admin network 10.10.3.16/29 as the destination, and the command opens the load-balancer network 10.10.2.8/29. On the bastion host only the admin network is local, so the rule as written did not cover the bastion host itself; the monitoring notes add the rule for the admin network separately.