0Pricing
Linux Command Line Mastery · Ders

Güvenlik Duvarı Yönetimi: `ufw`, `firewalld`, `iptables`

Linux sisteminizi yetkisiz erişime karşı korumak için güvenlik duvarlarını yapılandırmayı ve yönetmeyi öğrenin.

Güvenlik Duvarı Yönetimi: `ufw`, `firewalld`, `iptables`, CoddyKit'te ücretsiz bir Linux Command Line Mastery dersidir. Bu, 4 dersinin 2. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Linux Command Line Mastery öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Linux Command Line Mastery kursu toplamda 4 dersten oluşur.

Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.

What's a Firewall?

A firewall acts as a security guard for your computer or network. It controls incoming and outgoing network traffic by analyzing data packets and deciding whether to allow or block them based on a set of predefined rules.

Think of it as a filter that protects your system from unauthorized access and malicious threats.

Introducing UFW

UFW, which stands for "Uncomplicated Firewall," is a user-friendly front-end for iptables, the complex default firewall utility in Linux. It's designed to make firewall management much simpler, especially for users on Debian-based systems like Ubuntu.

UFW simplifies common tasks like opening or closing ports.

UFW Status & Control

Before making changes, it's good practice to check UFW's current status. You can also easily enable or disable it.

Try running these commands:

sudo ufw status
sudo ufw enable
sudo ufw disable

UFW: Allow Services

UFW allows you to open ports for common services by their name, which is very convenient. For example, to allow SSH or HTTP traffic, you just use the service name.

Let's try allowing SSH and HTTP:

sudo ufw allow ssh
sudo ufw allow http
sudo ufw status verbose

UFW: Allow Custom Ports

Sometimes you need to open a specific port that isn't a named service. You can do this by specifying the port number and the protocol (TCP or UDP).

Here's how to allow port 8080 for TCP and 53 for UDP:

sudo ufw allow 8080/tcp
sudo ufw allow 53/udp
sudo ufw status verbose

Introducing Firewalld

Firewalld is another popular firewall management tool, often found on Red Hat-based systems like CentOS and Fedora. Unlike UFW, Firewalld is a dynamic firewall manager.

It uses zones to define different trust levels for network connections, allowing you to apply rules based on where the connection originates.

Firewalld Status & Zones

With Firewalld, you can check its status and explore the various zones it uses. Zones like public, home, or internal have different default rules.

Check the status and active zones:

sudo systemctl status firewalld
sudo firewall-cmd --get-active-zones
sudo firewall-cmd --get-zones

Firewalld: Manage Services

To manage services with Firewalld, you specify the zone and the service name. Changes are temporary by default; use --permanent to make them stick after a reboot, then --reload to apply.

Let's add HTTP service to the public zone permanently:

sudo firewall-cmd --zone=public --add-service=http --permanent
sudo firewall-cmd --reload
sudo firewall-cmd --list-services --zone=public

Firewalld: Manage Ports

Similar to services, you can open or close specific port numbers in a Firewalld zone. Remember to specify the protocol (TCP or UDP) and use --permanent for lasting changes.

Here's how to open port 8080 for TCP permanently:

sudo firewall-cmd --zone=public --add-port=8080/tcp --permanent
sudo firewall-cmd --reload
sudo firewall-cmd --list-ports --zone=public

Firewall Commands Check

Time for a quick check! Which of the following statements about firewall management in Linux are true?

Recap: Firewall Essentials

In this lesson, we explored how to manage firewalls on Linux systems to enhance security. We covered two main tools:

  • UFW (Uncomplicated Firewall): A simple interface for iptables, popular on Debian/Ubuntu, allowing easy control over services and ports.
  • Firewalld: A dynamic firewall manager used on RHEL/CentOS systems, which organizes rules into zones for flexible security policies.

Understanding these tools is crucial for securing your Linux server or workstation.

Sıkça Sorulan Sorular

“Güvenlik Duvarı Yönetimi: `ufw`, `firewalld`, `iptables`” dersi ücretsiz mi?

Evet — “Güvenlik Duvarı Yönetimi: `ufw`, `firewalld`, `iptables`” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Linux Command Line Mastery kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Linux Command Line Mastery kursu toplamda 4 dersten oluşur.

“Güvenlik Duvarı Yönetimi: `ufw`, `firewalld`, `iptables`” dersinde ne öğreneceğim?

Linux sisteminizi yetkisiz erişime karşı korumak için güvenlik duvarlarını yapılandırmayı ve yönetmeyi öğrenin. Linux Command Line Mastery ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.

Linux Command Line Mastery öğrenmeye başlamak için deneyim gerekli mi?

Önceden deneyim gerekmez. CoddyKit'te Linux Command Line Mastery, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 2. dersidir.

“Güvenlik Duvarı Yönetimi: `ufw`, `firewalld`, `iptables`” dersi ne kadar sürer?

Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.

Bu Linux Command Line Mastery dersinde kod yazıp çalıştırabilir miyim?

Evet. Her Linux Command Line Mastery dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.

Bu kursun tüm dersleri

  1. Ağ Tanılama: `traceroute`, `nslookup`, `dig`
  2. Güvenlik Duvarı Yönetimi: `ufw`, `firewalld`, `iptables`
  3. Güvenli Kabuk Anahtarı Yönetimi
  4. tcpdump ile Trafiği Yakalama ve İnceleme
← Linux Command Line Mastery Sayfasına Dön