So basically, you are choosing between which method of talking to iptables, via firewalld (dynamic) or iptables-service (static)The firewall daemon on the other hand manages the firewall dynamically and applies changes without restarting the whole firewall. Therefore there is no need to reload all firewall kernel modules. But using a firewall daemon requires that all firewall modifications are done with that daemon to make sure that the state in the daemon and the firewall in kernel are in sync. The firewall daemon can not parse firewall rules added by the ip*tables and ebtables command line tools.
Static Firewall (system-config-firewall/lokkit)
The actual static firewall model with system-config-firewall and lokkit will still be available and usable, but not at the same time as the daemon is running. The user or admin can decide which firewall solution should be used by enabling the corresponding services.
It is planned to add a selector for the firewall solution to be used at install time or in first boot. The configuration of the other solution will stay intact and can be enabled simply by switching to the other model.
The firewall daemon is independent to system-config-firewall, but should not be used at the same time.
yum -q deplist firewalld
package: firewalld.noarch 0.4.3.2-8.1.el7_3
dependency: /bin/bash
provider: bash.x86_64 4.2.46-21.el7_3
dependency: /bin/sh
provider: bash.x86_64 4.2.46-21.el7_3
dependency: /usr/bin/python
provider: python.x86_64 2.7.5-48.el7
dependency: ebtables
provider: ebtables.x86_64 2.0.10-15.el7
dependency: firewalld-filesystem = 0.4.3.2-8.1.el7_3
provider: firewalld-filesystem.noarch 0.4.3.2-8.1.el7_3
dependency: ipset
provider: ipset.x86_64 6.19-6.el7
dependency: iptables
provider: iptables-services.x86_64 1.4.21-17.el7
provider: iptables.x86_64 1.4.21-17.el7
dependency: python-firewall = 0.4.3.2-8.1.el7_3
provider: python-firewall.noarch 0.4.3.2-8.1.el7_3
dependency: systemd
provider: systemd.x86_64 219-30.el7_3.6
yum list iptables* -q | tr -s ' '
Installed Packages
iptables.x86_64 1.4.21-17.el7 @cr
iptables-devel.x86_64 1.4.21-17.el7 @cr
iptables-services.x86_64 1.4.21-17.el7 @cr
iptables-utils.x86_64 1.4.21-17.el7 @cr
yum list firewalld* -q | tr -s ' '
Available Packages
firewalld.noarch 0.4.3.2-8.1.el7_3 updates
firewalld-filesystem.noarch 0.4.3.2-8.1.el7_3 updates
ForumWeb.Hosting is a web hosting forum where you’ll find in-depth discussions and resources to help you find the best hosting providers for your websites or how to manage your hosting whether you are new or experienced. You’ll find it all here. With topics ranging from web hosting, internet marketing, search engine optimization, social networking, make money online, affiliate marketing as well as hands-on technical support for web design, programming and more. We are a growing community of like-minded people that is keen to help and support each other with ambitions and online endeavors. Learn and grow, make friends and contacts for life.
The world's smartest hosting providers come here to discuss & share what's trending in the web hosting world!