Ravindra Bagale · AWSसर्व coursesया course चे lessonsशोधाEnglish

AWS · मराठी आवृत्ती

6.6 CentOS Stream 9: firewalld आणि SELinux

रवींद्र बागले यांच्या course वर आधारित · सहज मराठीत explanation

या page मध्ये

Package commands AL2023 सारखे वाटतील, पण firewalld आणि SELinux चा context वेगळा असू शकतो. दोन्हींची स्थिती तपासा.

Nginx

sudo yum install -y nginx
sudo service nginx start
sudo systemctl enable nginx
sudo service nginx status
sudo nginx -t
curl -I http://localhost

Apache

Nginx stop करून Apache test करा:

sudo yum install -y httpd
sudo service httpd start
sudo systemctl enable httpd
sudo service httpd status
sudo apachectl configtest
curl -I http://localhost          # shows the CentOS test page until you add index.html

स्वतःचं index.html नसताना test page दिसू शकतो.

firewalld active असेल तर

sudo systemctl is-active firewalld
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

पहिल्या command ने status पाहा. Active असेल तेव्हाच HTTP/HTTPS rules आणि reload करा. Inactive असल्यास ते commands चालतीलच असं नाही; SG आणि इतर host firewall rules तपासा.

SELinux

SELinux mandatory access control देतो. सामान्य enforcing policy मध्ये web processes च्या domain ला योग्य labels असलेलं content वाचता येतं; static content साठी httpd_sys_content_t वापरला जातो.

getenforce                                  # Enforcing / Permissive / Disabled
ls -Z /usr/share/nginx/html /var/www/html   # view SELinux labels
sudo restorecon -Rv /var/www/html           # fix labels after copying/moving files
sudo setsebool -P httpd_can_network_connect 1      # allow reverse proxy to apps (Node/Flask)
sudo setsebool -P httpd_can_network_connect_db 1   # allow web server/PHP to reach a remote DB
sudo ausearch -m avc -ts recent             # see recent SELinux denials (package audit)

getenforce स्थिती, ls -Z labels, restorecon default labels, setsebool निवडक permissions आणि ausearch recent denials दाखवतात. Reverse proxy/remote DB booleans गरज असेल तेवढेच enable करा.

SELinux कायम बंद करून error लपवू नका. Labels/booleans आणि denial logs तपासा. फक्त isolated diagnostic test मध्ये तात्पुरतं permissive करून कारण ओळखलं तर लगेच enforcing परत करा; live security बदल विचारपूर्वक करा.

Lab

getenforce आणि sudo systemctl is-active firewalld नोंदवा. Active असेल तर HTTP allow करा. ls -Z /var/www/html labels तपासा.