LINUXOR.SK ... open source notes ...

Vault - firewalld rules (bastion host)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Network design and firewall flows, Linux hardening

The complete host firewall of the bastion host, the only server administrators can reach from outside the three Vault networks.

ItemValue
Shown hereprod-vault-bastion1 (10.10.3.18)
Deployed onthe bastion host of every environment
Zonepublic

The file

bash
#!/bin/bash
#
# firewalld rich rules, zone "public" - prod-vault-bastion1
#

# In zone "public" allow access to SSH (TCP/22) from NET_ADMIN_ACCESS_1 (10.41.1.16/28) to VM_PROD_VAULT_BASTION1 (10.10.3.18/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.41.1.16/28 destination address=10.10.3.18/32 port port=22 protocol=tcp accept'

# In zone "public" allow access to SSH (TCP/22) from NET_ADMIN_ACCESS_2 (10.41.1.32/28) to VM_PROD_VAULT_BASTION1 (10.10.3.18/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.41.1.32/28 destination address=10.10.3.18/32 port port=22 protocol=tcp accept'

# In zone "public" allow access to ZABBIX port (TCP/10050) from NET_ZABBIX (10.40.1.16/28) to NET_PROD_VAULT_ADMIN (10.10.3.16/29)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.40.1.16/28 destination address=10.10.2.8/29 port port=10050 protocol=tcp accept'

# Reload firewallD rules
firewall-cmd --reload

# List of all rich rules in zone "public"
firewall-cmd --zone=public --list-rich-rules

Rules in one table

FromToPortPurpose
Administrator access networks 10.41.1.16/28, 10.41.1.32/28this hostTCP 22SSH for administrators, after the corporate access gateway
Monitoring network 10.40.1.16/28admin networkTCP 10050Zabbix agent

As-built quirk

The comment of rule 3 names the admin network 10.10.3.16/29 as the destination, and the command opens the load-balancer network 10.10.2.8/29. On the bastion host only the admin network is local, so the rule as written did not cover the bastion host itself; the monitoring notes add the rule for the admin network separately.

← solutionz