LINUXOR.SK ... open source notes ...

Vault - firewalld rules (load balancer)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Network design and firewall flows, Load balancer

The complete host firewall of a load-balancer node. Clients are admitted to the virtual address one source at a time; there is no rule that opens TCP 443 to a whole network of clients.

ItemValue
Shown hereprod-vault-lb1 (10.10.2.10)
Deployed onboth load-balancer nodes, with their own address in the SSH rule
Zonepublic
Virtual address10.10.2.14

The file

bash
#!/bin/bash
#
# firewalld rich rules, zone "public" - prod-vault-lb1
#

# In zone "public" allow access to SSH (TCP/22) from NET_PROD_VAULT_ADMIN (10.10.3.16/29) to VM_PROD_VAULT_LB1 (10.10.2.10/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.3.16/29 destination address=10.10.2.10/32 port port=22 protocol=tcp accept'

# In zone "public" allow VRRP protocol from NET_PROD_VAULT_LB (10.10.2.8/29) to NET_PROD_VAULT_LB (10.10.2.8/29)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.2.8/29 destination address=10.10.2.8/29 protocol value=vrrp accept'

# In zone "public" allow access to HTTPS port (TCP/443) from IP_PROD_REVPROXY_SNAT (10.42.3.8/32) to VM_PROD_VAULT_LBVIP (10.10.2.14/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.42.3.8/32 destination address=10.10.2.14/32 port port=443 protocol=tcp accept'

# In zone "public" allow access to HTTPS port (TCP/443) from IP_PROD_REVPROXY_LB1 (10.42.1.10/32) to VM_PROD_VAULT_LBVIP (10.10.2.14/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.42.1.10/32 destination address=10.10.2.14/32 port port=443 protocol=tcp accept'

# In zone "public" allow access to HTTPS port (TCP/443) from IP_PROD_REVPROXY_LB2 (10.42.1.11/32) to VM_PROD_VAULT_LBVIP (10.10.2.14/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.42.1.11/32 destination address=10.10.2.14/32 port port=443 protocol=tcp accept'

# In zone "public" allow access to HTTPS port (TCP/443) from NET_ZABBIX (10.40.1.16/28) to NET_PROD_VAULT_LB (10.10.2.8/29)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.40.1.16/28 destination address=10.10.2.8/29 port port=10050 protocol=tcp accept'

# In zone "public" allow access to HTTPS port (TCP/443) from MONITORING_PROBE (10.43.1.8/32) to VM_PROD_VAULT_LBVIP (10.10.2.14/32)
firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.43.1.8/32 destination address=10.10.2.14/32 port port=443 protocol=tcp accept'

# Reload firewallD rules
firewall-cmd --reload

# List of all rich rules in zone "public"
firewall-cmd --zone=public --list-rich-rules

Rules in one table

FromToPortPurpose
Admin network 10.10.3.16/29this nodeTCP 22SSH from the bastion host
Load-balancer network 10.10.2.8/29the same networkVRRPKeepalived between the two nodes
Reverse-proxy SNAT address 10.42.3.8virtual addressTCP 443API clients arriving from the Internet-facing reverse proxy
Reverse-proxy load balancers 10.42.1.10, 10.42.1.11virtual addressTCP 443Liveness probes of that reverse proxy
Monitoring network 10.40.1.16/28load-balancer networkTCP 10050Zabbix agent
Monitoring probe 10.43.1.8virtual addressTCP 443Availability and certificate-expiry check

As-built quirk

Rule 06 is described as HTTPS in its comment and opens TCP 10050, the Zabbix agent port. On the second node the same rule opens TCP 443. The Zabbix notes show 10050 as the intended port; the two nodes were not identical on this rule.

← solutionz