

+ A user can easily see which rules are applied and which rules should be applied by comparing /etc/sysconfig/ip*tables with the output of ip*tables-save. system-config-firewall is handling these services to apply new firewalls or firewall changes. These files are applied with the iptables and ip6tables services. The files contain the full firewall configuration. System-config-firewall and lokkit are creating the /etc/sysconfig/ip*tables files.


The -config files contain the service configuration for the services iptables and ip6tables. Analog for /etc/sysconfig/ip6tables and ip6tables for IPv6. etc/sysconfig/iptables is the iptables configuration file and contains the rules in iptables-save format for IPv4. The initial firewall configuration is created at install time by anaconda and can be altered later on by the user with system-config-firewall, system-config-firewall-tui or the command line tool lokkit. The standard firewall configuration for IPv4 and IPv6 are created by lokkit. System-config-firewall is a graphical user interface for setting basic firewall rules. System-config-firewall What is system-config-firewall? 1.4 Other firewall configuration options.
