Vault - firewalld rules (load balancer)
Vault Solution · Config document · referenced from Network design and firewall flows, Load balancer
The complete host firewall of a load-balancer node. Clients are admitted to the virtual address one source at a time; there is no rule that opens TCP 443 to a whole network of clients.
| Item | Value |
|---|---|
| Shown here | prod-vault-lb1 (10.10.2.10) |
| Deployed on | both load-balancer nodes, with their own address in the SSH rule |
| Zone | public |
| Virtual address | 10.10.2.14 |
The file
#!/bin/bash # # firewalld rich rules, zone "public" - prod-vault-lb1 # # In zone "public" allow access to SSH (TCP/22) from NET_PROD_VAULT_ADMIN (10.10.3.16/29) to VM_PROD_VAULT_LB1 (10.10.2.10/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.3.16/29 destination address=10.10.2.10/32 port port=22 protocol=tcp accept' # In zone "public" allow VRRP protocol from NET_PROD_VAULT_LB (10.10.2.8/29) to NET_PROD_VAULT_LB (10.10.2.8/29) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.10.2.8/29 destination address=10.10.2.8/29 protocol value=vrrp accept' # In zone "public" allow access to HTTPS port (TCP/443) from IP_PROD_REVPROXY_SNAT (10.42.3.8/32) to VM_PROD_VAULT_LBVIP (10.10.2.14/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.42.3.8/32 destination address=10.10.2.14/32 port port=443 protocol=tcp accept' # In zone "public" allow access to HTTPS port (TCP/443) from IP_PROD_REVPROXY_LB1 (10.42.1.10/32) to VM_PROD_VAULT_LBVIP (10.10.2.14/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.42.1.10/32 destination address=10.10.2.14/32 port port=443 protocol=tcp accept' # In zone "public" allow access to HTTPS port (TCP/443) from IP_PROD_REVPROXY_LB2 (10.42.1.11/32) to VM_PROD_VAULT_LBVIP (10.10.2.14/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.42.1.11/32 destination address=10.10.2.14/32 port port=443 protocol=tcp accept' # In zone "public" allow access to HTTPS port (TCP/443) from NET_ZABBIX (10.40.1.16/28) to NET_PROD_VAULT_LB (10.10.2.8/29) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.40.1.16/28 destination address=10.10.2.8/29 port port=10050 protocol=tcp accept' # In zone "public" allow access to HTTPS port (TCP/443) from MONITORING_PROBE (10.43.1.8/32) to VM_PROD_VAULT_LBVIP (10.10.2.14/32) firewall-cmd --permanent --zone=public --add-rich-rule='rule family=ipv4 source address=10.43.1.8/32 destination address=10.10.2.14/32 port port=443 protocol=tcp accept' # Reload firewallD rules firewall-cmd --reload # List of all rich rules in zone "public" firewall-cmd --zone=public --list-rich-rules
Rules in one table
| From | To | Port | Purpose |
|---|---|---|---|
Admin network 10.10.3.16/29 | this node | TCP 22 | SSH from the bastion host |
Load-balancer network 10.10.2.8/29 | the same network | VRRP | Keepalived between the two nodes |
Reverse-proxy SNAT address 10.42.3.8 | virtual address | TCP 443 | API clients arriving from the Internet-facing reverse proxy |
Reverse-proxy load balancers 10.42.1.10, 10.42.1.11 | virtual address | TCP 443 | Liveness probes of that reverse proxy |
Monitoring network 10.40.1.16/28 | load-balancer network | TCP 10050 | Zabbix agent |
Monitoring probe 10.43.1.8 | virtual address | TCP 443 | Availability and certificate-expiry check |
As-built quirk
Rule 06 is described as HTTPS in its comment and opens TCP 10050, the Zabbix agent port. On the second node the same rule opens TCP 443. The Zabbix notes show 10050 as the intended port; the two nodes were not identical on this rule.