
IP Port Number Protocol Component
5404, 5405 UDP corosync / cman (Cluster Manager)
11111 TCP ricci (part of Conga remote agent)
21064 TCP dlm (distributed lock manager)
50006, 50008, 50009 TCP ccsd (Cluster Configuration System Daemon)
50007 UDP ccsd Cluster Configuration System Daemon)
22 TCP / UDP Secure Shell Access
80 TCP / UDP HyperText Transport Protocol
443 TCP / UDP HyperText Transport Protocol over TLS / SSL
Table 6: Iptables for Cluster Services
# ./firewall-config.sh
Please put the ports you would like to firewall here, separated by a space:
21064 22 443 80 50006 50008 50009 50007
Please put the protocols you would like to firewall here, separated by a
space:
tcp udp
iptables: Chain already exists.
iptables --append RHCF --protocol tcp --destination-port 21064 --jump ACCEPT
iptables --append RHCF --protocol tcp --destination-port 22 --jump ACCEPT
iptables --append RHCF --protocol tcp --destination-port 443 --jump ACCEPT
iptables --append RHCF --protocol tcp --destination-port 80 --jump ACCEPT
iptables --append RHCF --protocol tcp --destination-port 50006 --jump ACCEPT
iptables --append RHCF --protocol tcp --destination-port 50008 --jump ACCEPT
iptables --append RHCF --protocol tcp --destination-port 50009 --jump ACCEPT
iptables --append RHCF --protocol tcp --destination-port 50007 --jump ACCEPT
iptables --append RHCF --protocol udp --destination-port 21064 --jump ACCEPT
iptables --append RHCF --protocol udp --destination-port 22 --jump ACCEPT
iptables --append RHCF --protocol udp --destination-port 443 --jump ACCEPT
iptables --append RHCF --protocol udp --destination-port 80 --jump ACCEPT
iptables --append RHCF --protocol udp --destination-port 50006 --jump ACCEPT
iptables --append RHCF --protocol udp --destination-port 50008 --jump ACCEPT
iptables --append RHCF --protocol udp --destination-port 50009 --jump ACCEPT
iptables --append RHCF --protocol udp --destination-port 50007 --jump ACCEPT
Remember to "service iptables save"
www.redhat.com 34
Comentarios a estos manuales