---
title: "SYS: How do I configure the Linux firewall?"
canonical: "https://kb.myframeworks.com.au/space/PROSTIXV48DOC/31099233/SYS%3A%20How%20do%20I%20configure%20the%20Linux%20firewall%3F"
format: markdown
---
|  |  |
| --- | --- |
| <span style="color: #003366">**QUESTION:**</span> | SYS: How do I configure the Linux firewall? |
| <span style="color: #003366">**ANSWER:**</span> | Some Linux systems have the iptables firewall software running, which may prevent access to certain functions on the Linux system from external devices or PCs etc.   
For example, the Progress App Server "ProstixBroker", used by Prostix PDA and Financial Reporting, listen on TCP port 6800.   
If the linux iptbales firewall is active and port 6800 is not configured to allow traffic, the PDA web service and the Finanical Reporting application will not be able to connect to the ProstixBroker.<br>To check and manage the iptables firewall, perform the following:<br>1. To check if the iptables firewall is running, run this command from the linux command line logged in as root:<br>**iptables -n -L**<br>2. If iptables is running, you will see a list showing the accept or deny rules.<br>*For example:*<br>*Chain RH-Firewall-1-INPUT (2 references) **target prot opt source destination *  
*ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 *  
*ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 icmp type 255 *  
*ACCEPT esp -- 0.0.0.0/0 0.0.0.0/0 *  
*ACCEPT ah -- 0.0.0.0/0 0.0.0.0/0 *  
*ACCEPT udp -- 0.0.0.0/0 224.0.0.251 udp dpt:5353 *  
*ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:631 *  
*ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:631*<br>3. The entries we are interested in for the ProstixBroker App Server are those for ports **6700 and 7000 for Live** and **6800 and 7100 for Demo**.<br>*In this example below, we have the 2 entries required for Live, but not for Demo:*<br>*ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:6700*  
*ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:7000*<br>4. To add the new missing entries requires editing the **/etc/sysconfig/iptables** file:<br>Logged in as root, backup the iptables config file then use "**vi**" to edit, as follows:<br>**cd /etc/sysconfig**<br>**cp -p iptables iptables.bak** (back it up first)<br>**vi iptables**<br>*Jump down to the following 2 lines & ****yy**** (yank) then ****p**** (paste), both 6700 & 7000:*<br>**-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 6700 -j ACCEPT**<br>**-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 7000 -j ACCEPT**<br>*Giving this:*<br>**-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 6700 -j ACCEPT**<br>**-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 6700 -j ACCEPT**<br>**-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 7000 -j ACCEPT**<br>**-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 7000 -j ACCEPT**<br>*Then change the 2 duplicates to 6800 & 7100:*<br>**-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 6700 -j ACCEPT**<br>**-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 6800 -j ACCEPT**<br>**-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 7000 -j ACCEPT**<br>**-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 7100 -j ACCEPT**<br>*Save & exit vi.*<br>5. Restart the firewall:* *<br>**service iptables restart**<br>** **<br>6. Display the iptables listing to confirm the new entries exist:<br>**iptables -n -L** |
| <span style="color: #003366">**FOR FURTHER INFORMATION REFER TO:**</span> | Linux iptables firewall configuration tutorial: [http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/](http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/) |
| **<span style="color: #003366">IF THIS FAQ DOESN’T RESOLVE YOUR</span>****<span style="color: #003366"> ISSUE:</span>** | Contact your local linux system administrator<span style="color: #003366"><u> </u></span> |