TEXT 12
Fix Issabel PBX Firewall persistence on CentOS7 Guest on 24th September 2020 12:08:51 AM
  1.  
  2. # One of the errors you might get: "iptables-restore v1.4.21: Set issabel_whitelist doesn't exist."
  3. # On CentOS7 iptables is depercated in favor of firewalld, but Issabel still uses iptables + ipset.
  4. # We need to configure iptables and ipset persistence.
  5.  
  6.  
  7. # 1.0 Make sure that the Firewall from Issabel is on Deactivated.
  8. # 1.1 Add all the rules that you need.
  9. # 1.2 Add all the whitelists that you need.
  10.  
  11. # 2.0 Activate the Firewall from the Issabel GUI
  12.  
  13.  
  14. # 3.0 Save the ipset and iptable rules
  15. /usr/sbin/ipset -file /etc/sysconfig/ipset save
  16. service iptables save
  17.  
  18. # 4.0 Allow persistance for iptable rules
  19. chkconfig iptables on
  20.  
  21. # 5.0 Create a new service unit file for ipset "persistance"
  22. nano /etc/systemd/system/ipset.service
  23.  
  24.  
  25. # 5.1 Add the following content in the file and save it (CTRL + X, Y, ENTER):
  26. [Unit]
  27. Description=ipset persistent rule service
  28. Before=iptables.service
  29. ConditionFileNotEmpty=/etc/sysconfig/ipset
  30.  
  31. [Service]
  32. Type=oneshot
  33. RemainAfterExit=yes
  34. ExecStart=/usr/sbin/ipset -exist -file /etc/sysconfig/ipset restore
  35. ExecStop=/usr/sbin/ipset -file /etc/sysconfig/ipset save
  36.  
  37. [Install]
  38. WantedBy=multi-user.target
  39.  
  40.  
  41. # 6.0 Enable/disable our services
  42. systemctl daemon-reload
  43. systemctl disable firewalld
  44. systemctl enable iptables
  45. systemctl enable ipset
  46.  
  47. # 7.0 Reboot and see how the Firewall in Issabel gets "activated"
  48. # Remember to always whitelist yourself and allow traffic, because you can lock yourself out.

RSO cPaste е място за публикуване на код или текст за по-лесно отстраняване на грешки.

Влез или се Регистрай за да редактираш, изтриваш или преглеждаш хронология на твоето публикувано съдържание

Необработен текст

Влез или се Регистрирай за да редактираш или задържиш това съдържание.