RHCSA Firewalld and Network Configuration Flashcards
6 cards from real RHCSA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 RHCSA Firewalld and Network Configuration flashcards as text
A system administrator adds a new firewalld rule to allow HTTP traffic using `firewall-cmd --zone=public --add-service=http`. After a system reboot, they discover that HTTP traffic is no longer allowed. What is the correct procedure to ensure the rule persists across reboots?
Answer: Add the `--permanent` flag to the command and then run `firewall-cmd --reload`.
Firewalld maintains separate runtime and permanent configurations. Rules added without the `--permanent` flag only apply to the current runtime and are lost on reboot or service reload. To make a rule persistent, it must be added to the permanent configuration using the `--permanent` flag. For the permanent rule to become active in the running configuration, the firewalld service must be reloaded using `firewall-cmd --reload`.
A server has two network interfaces, `eno1` connected to an internal network and `eno2` connected to the public internet. The administrator wants to assign `eno1` to the 'internal' firewalld zone and `eno2` to the 'public' zone. Which of the following commands will correctly and persistently assign the interfaces to their respective zones?
Answer: nmcli con modify eno1 connection.zone internal && nmcli con modify eno2 connection.zone public
While `firewall-cmd` can change an interface's zone for the current session (`--change-interface`), the persistent and recommended method for assigning an interface to a zone is by modifying the NetworkManager connection profile. The command `nmcli connection modify connection.zone ` permanently associates the network connection with the specified firewalld zone.
Which of the following `nmcli` commands correctly configures a static IPv4 address, gateway, and DNS server for a connection named 'eth0'?
Answer: nmcli con mod eth0 ipv4.addresses 192.168.1.100/24 ipv4.gateway 192.168.1.1 ipv4.dns 8.8.8.8 ipv4.method manual
The correct command to modify an existing NetworkManager connection is `nmcli connection modify` (or `con mod`). The static IP address and subnet mask are set with `ipv4.addresses`, the gateway with `ipv4.gateway`, and the DNS server with `ipv4.dns`. Crucially, `ipv4.method` must be set to `manual` to disable DHCP and use the static configuration.
What is the primary function of the 'default zone' in firewalld?
Answer: It is the zone assigned to any network interface that is not explicitly assigned to a different zone.
The default zone in firewalld is the zone that is used for any network interface or connection that has not been explicitly bound to a different zone. This acts as a catch-all to ensure that all network interfaces are covered by a defined firewall policy.
A system administrator needs to allow access to a web server from a specific subnet (10.10.50.0/24) but deny it from all other sources. Which firewalld command will achieve this most effectively?
Answer: firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="10.10.50.0/24" service name="http" accept'
Rich rules provide the flexibility to create more specific and conditional firewall rules. This command creates a permanent rule that specifically accepts traffic for the 'http' service only when it originates from the '10.10.50.0/24' source address. The other options are either syntactically incorrect or do not create the required conditional link between the source and the service.
After making several changes to the permanent firewalld configuration, a sysadmin wants to activate them. What is the key difference between running `firewall-cmd --reload` and `systemctl restart firewalld`?
Answer: `--reload` keeps existing stateful connections alive, while `restart` drops all active connections.
The `firewall-cmd --reload` command loads the permanent configuration into the running firewall without losing the state information of current network connections. In contrast, `systemctl restart firewalld` stops and then starts the entire daemon, which will drop all active connections as the stateful firewall information is lost. For applying new permanent rules without interrupting service, `--reload` is the preferred method.