SYNOPSIS

/etc/firewalld/firewalld.conf

DESCRIPTION

firewalld.conf is loaded by firewalld during the initialization process. The file contains the basic configuration options for firewalld.

OPTIONS

These are the options that can be set in the config file:

DefaultZone

This sets the default zone for connections or interfaces if the zone is not selected or specified by NetworkManager, initscripts or command line tool. The default zone is public.

MinimalMark

For some firewall settings several rules are needed in different tables to be able to handle packets in the correct way. To achieve that these packets are marked using the MARK target iptables(8) and ip6tables(8). With the MinimalMark option a block of marks can be reserved for private use; only marks over this value are used. The default MinimalMark value is 100.

CleanupOnExit

If firewalld stops, it cleans up all firewall rules. Setting this option to no or false leaves the current firewall rules untouched. The default value is yes or true.

Lockdown

If this option is enabled, firewall changes with the D-Bus interface will be limited to applications that are listed in the lockdown whitelist (see firewalld.lockdownwhitelist(5)). The default value is no or false.

IPv6_rpfilter

If this option is enabled (it is by default), reverse path filter test on a packet for IPv6 is performed. If a reply to the packet would be sent via the same interface that the packet arrived on, the packet will match and be accepted, otherwise dropped. For IPv4 the rp_filter is controlled using sysctl.

RELATED TO firewalld.conf…

NOTES

firewalld home page:

\m[blue]http://www.firewalld.org\m[]

More documentation with examples:

\m[blue]http://fedoraproject.org/wiki/FirewallD\m[]

AUTHORS

Thomas Woerner <[email protected]>

Developer

Jiri Popelka <[email protected]>

Developer