#bPNG
IHDR Ÿ f Õ†C1 sRGB ®Îé gAMA ±üa pHYs à ÃÇo¨d GIDATx^íÜL”÷ð÷Yçªö("Bh_ò«®¸¢§q5kÖ*:þ0AºšÖ¥]VkJ¢M»¶f¸±8\k2íll£1]q®ÙÔ‚ÆT
p0
zones/work.xml 0000644 00000000540 15147707641 0007421 0 ustar 00
Work
For use in work areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.
zones/trusted.xml 0000644 00000000257 15147707641 0010136 0 ustar 00
Trusted
All network connections are accepted.
zones/external.xml 0000644 00000000475 15147707641 0010270 0 ustar 00
External
For use on external networks. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.
zones/drop.xml 0000644 00000000460 15147707641 0007404 0 ustar 00
Drop
Unsolicited incoming network packets are dropped. Incoming packets that are related to outgoing network connections are accepted. Outgoing network connections are allowed.
zones/nm-shared.xml 0000644 00000001331 15147707641 0010314 0 ustar 00
NetworkManager Shared
This zone is used internally by NetworkManager when activating a
profile that uses connection sharing and doesn't have an explicit
firewall zone set.
Block all traffic to the local machine except ICMP, ICMPv6, DHCP
and DNS. Allow all forwarded traffic.
Note that future package updates may change the definition of the
zone unless you overwrite it with your own definition.
zones/home.xml 0000644 00000000632 15147707641 0007371 0 ustar 00
Home
For use in home areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.
zones/block.xml 0000644 00000000470 15147707641 0007533 0 ustar 00
Block
Unsolicited incoming network packets are rejected. Incoming packets that are related to outgoing network connections are accepted. Outgoing network connections are allowed.
zones/internal.xml 0000644 00000000651 15147707641 0010256 0 ustar 00
Internal
For use on internal networks. You mostly trust the other computers on the networks to not harm your computer. Only selected incoming connections are accepted.
zones/public.xml 0000644 00000000544 15147707641 0007721 0 ustar 00
Public
For use in public areas. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.
zones/dmz.xml 0000644 00000000462 15147707641 0007234 0 ustar 00
DMZ
For computers in your demilitarized zone that are publicly-accessible with limited access to your internal network. Only selected incoming connections are accepted.
policies/allow-host-ipv6.xml 0000644 00000001211 15147707641 0012057 0 ustar 00
Allow host IPv6
Allows basic IPv6 functionality for the host running firewalld.
icmptypes/source-quench.xml 0000644 00000000370 15147707641 0012100 0 ustar 00
Source Quench
This error message is generated to tell a host to reduce the pace at which it is sending packets.
icmptypes/packet-too-big.xml 0000644 00000000510 15147707641 0012120 0 ustar 00
Packet Too Big
This error message is sent by a router in response to a packet that it cannot forward because the packet is larger than the MTU of the outgoing link.
icmptypes/host-prohibited.xml 0000644 00000000401 15147707641 0012416 0 ustar 00
Host Prohibited
This error message is sent if access from a host administratively prohibited.
icmptypes/host-unknown.xml 0000644 00000000357 15147707641 0011776 0 ustar 00
Host Unknown
This error message is sent if the destination host is unknown.
icmptypes/network-unreachable.xml 0000644 00000000367 15147707641 0013265 0 ustar 00
Network Unreachable
This message is sent if the destination network is unreachable.
icmptypes/neighbour-solicitation.xml 0000644 00000000711 15147707641 0013777 0 ustar 00
Neighbour Solicitation (Neighbor Solicitation)
This informational message is sent by a node to determine the link-layer address of a neighbor, or to verify that a neighbor is still reachable via a cached link-layer address. Neighbor Solicitations are also used for Duplicate Address Detection.
icmptypes/ttl-zero-during-reassembly.xml 0000644 00000000445 15147707641 0014534 0 ustar 00
TTL Zero During Reassembly
This error message is sent if a host fails to reassemble a fragmented datagram within its time limit.
icmptypes/neighbour-advertisement.xml 0000644 00000000543 15147707641 0014153 0 ustar 00
Neighbour Advertisement (Neighbor Advertisement)
This informational message is sent in response to a neighbour-solicitation message in order to (unreliably) propagate new information quickly.
icmptypes/redirect.xml 0000644 00000000271 15147707641 0011120 0 ustar 00
Redirect
This error message informs a host to send packets on another route.
icmptypes/ttl-zero-during-transit.xml 0000644 00000000400 15147707641 0014041 0 ustar 00
TTL Zero During Transit
This error message is sent if the time to live exceeded in transit.
icmptypes/time-exceeded.xml 0000644 00000000375 15147707641 0012026 0 ustar 00
Time Exceeded
This error message is generated if the time-to-live was exceeded either of a packet or of the reassembling of a fragmented packet.
icmptypes/mld-listener-report.xml 0000644 00000000463 15147707641 0013232 0 ustar 00
MLD Listener Report
ICMPv6 Link-Local Multicast Listener Discovery (MDL) of type Multicast Listener Report (type 131) (RFC 4890 section 4.4.1).
icmptypes/timestamp-reply.xml 0000644 00000000351 15147707641 0012452 0 ustar 00
Timestamp Reply
This message is used to reply to a timestamp message.
icmptypes/failed-policy.xml 0000644 00000000405 15147707641 0012037 0 ustar 00
Failed Policy
This error message is generated if the source address failed ingress/egress policy.
icmptypes/mld2-listener-report.xml 0000644 00000000501 15147707641 0013305 0 ustar 00
MLDv2 Multicast Listener Report
ICMPv6 Link-Local Multicast Listener Discovery (MDLv2) of type Multicast Listener Report (type 143) (RFC 4890 section 4.4.1).
icmptypes/address-unreachable.xml 0000644 00000000601 15147707641 0013210 0 ustar 00
Address Unreachable
This error message is generated by a router, or by the IPv6 layer in the originating node, in response to a packet that cannot be delivered to its destination address for reasons other than congestion.
icmptypes/echo-reply.xml 0000644 00000000255 15147707641 0011370 0 ustar 00
Echo Reply (pong)
This message is the answer to an Echo Request.
icmptypes/no-route.xml 0000644 00000000357 15147707641 0011074 0 ustar 00
No Route
This error message is set if there is no route to the destination.
icmptypes/host-precedence-violation.xml 0000644 00000000412 15147707641 0014366 0 ustar 00
Host Precedence Violation
This error message is sent if the communication administratively prohibited.
icmptypes/required-option-missing.xml 0000644 00000000361 15147707641 0014114 0 ustar 00
Required Option Missing
This message is sent if a required option is missing.
icmptypes/router-solicitation.xml 0000644 00000000337 15147707641 0013341 0 ustar 00
Router Solicitation
This message is used by a host attached to a multicast link to request a Router Advertisement.
icmptypes/network-prohibited.xml 0000644 00000000372 15147707641 0013141 0 ustar 00
Network Prohibited
This message is sent if the network is administratively prohibited.
icmptypes/network-redirect.xml 0000644 00000000370 15147707641 0012607 0 ustar 00
Network Redirect
This message is sent if the datagram is redirected for the network.
icmptypes/port-unreachable.xml 0000644 00000000351 15147707641 0012551 0 ustar 00
Port Unreachable
This error message is sent if the port unreachable.
icmptypes/ip-header-bad.xml 0000644 00000000345 15147707641 0011703 0 ustar 00
Ip Header Bad
This error message is sent if the IP header is bad.
icmptypes/unknown-header-type.xml 0000644 00000000403 15147707641 0013220 0 ustar 00
Unknown Header Type
This error message is sent if an unrecognized Next Header type encountered.
icmptypes/source-route-failed.xml 0000644 00000000354 15147707641 0013177 0 ustar 00
Source Route Failed
This message is sent if the source route has failed.
icmptypes/mld-listener-query.xml 0000644 00000000461 15147707641 0013062 0 ustar 00
MLD Listener Query
ICMPv6 Link-Local Multicast Listener Discovery (MDL) of type Multicast Listener Query (type 130) (RFC 4890 section 4.4.1).
icmptypes/tos-network-unreachable.xml 0000644 00000000415 15147707641 0014062 0 ustar 00
TOS Network Unreachable
This error message is sent if the network is unreachable for the type of service.
icmptypes/host-unreachable.xml 0000644 00000000367 15147707641 0012551 0 ustar 00
Host Unreachable
This error message is sent if the destination host is unreachable.
icmptypes/fragmentation-needed.xml 0000644 00000000430 15147707641 0013374 0 ustar 00
Fragmentation Needed
This error message is sent if fragmentation is required, and Don not Fragment (DF) flag is set.
icmptypes/echo-request.xml 0000644 00000000322 15147707641 0011720 0 ustar 00
Echo Request (ping)
This message is used to test if a host is reachable mostly with the ping utility.
icmptypes/router-advertisement.xml 0000644 00000000343 15147707641 0013507 0 ustar 00
Router Advertisement
This message is used by routers to periodically announce the IP address of a multicast interface.
icmptypes/tos-host-unreachable.xml 0000644 00000000401 15147707641 0013341 0 ustar 00
TOS Host Unreachable
This message is sent if the host is unreachable for the type of service.
icmptypes/network-unknown.xml 0000644 00000000357 15147707641 0012512 0 ustar 00
Network Unknown
This message is sent if the destination network is unknown.
icmptypes/destination-unreachable.xml 0000644 00000000336 15147707641 0014111 0 ustar 00
Destination Unreachable
This error message is generated by a host or gateway if the destination is not reachable.
icmptypes/parameter-problem.xml 0000644 00000000341 15147707641 0012733 0 ustar 00
Parameter Problem
This error message is generated if the IP header is bad, either by a missing option or bad length.
icmptypes/timestamp-request.xml 0000644 00000000344 15147707641 0013011 0 ustar 00
Timestamp Request
This message is used for time synchronization.
icmptypes/unknown-option.xml 0000644 00000000371 15147707641 0012325 0 ustar 00
Unknown Option
This error message is sent if an unrecognized IPv6 option encountered.
icmptypes/reject-route.xml 0000644 00000000364 15147707641 0011732 0 ustar 00
Reject Route
This error message is sent if the route to destination is rejected.
icmptypes/precedence-cutoff.xml 0000644 00000000400 15147707641 0012672 0 ustar 00
Precedence Cutoff
This message is sent if the precedence is lower than the required minimum.
icmptypes/mld-listener-done.xml 0000644 00000000534 15147707641 0012643 0 ustar 00
MLD Listener Done
ICMPv6 Link-Local Multicast Listener Discovery (MDL) of type Multicast Listener Done (type 132) (RFC 4890 section 4.4.1). Also known as mld-listener-reduction to nft.
icmptypes/host-redirect.xml 0000644 00000000362 15147707641 0012074 0 ustar 00
Host Redirect
This message is sent if the datagram is redirected for the host.
icmptypes/tos-host-redirect.xml 0000644 00000000402 15147707641 0012672 0 ustar 00
TOS Host Redirect
This message is the datagram is redirected for the type of service and host.
icmptypes/communication-prohibited.xml 0000644 00000000427 15147707641 0014316 0 ustar 00
Communication Prohibited
This error message is sent if communication with destination administratively prohibited.
icmptypes/protocol-unreachable.xml 0000644 00000000371 15147707641 0013430 0 ustar 00
Protocol Unreachable
This message is sent if the destination protocol is unreachable.
icmptypes/tos-network-redirect.xml 0000644 00000000420 15147707641 0013406 0 ustar 00
TOS Network Redirect
This message is sent if the datagram is redirected for the type of service and network.
icmptypes/beyond-scope.xml 0000644 00000000445 15147707641 0011711 0 ustar 00
Beyond Scope
This error message is sent if transmitting a package would cross a zone boundary of the scope of the source address.
icmptypes/bad-header.xml 0000644 00000000402 15147707641 0011267 0 ustar 00
Bad Header
This error message is created if there has been an error in the header of a packet.
helpers/netbios-ns.xml 0000644 00000000215 15147707641 0011023 0 ustar 00
helpers/pptp.xml 0000644 00000000210 15147707641 0007720 0 ustar 00
helpers/proto-gre.xml 0000644 00000000132 15147707641 0010656 0 ustar 00
helpers/ftp.xml 0000644 00000000167 15147707641 0007541 0 ustar 00
helpers/h323.xml 0000644 00000000125 15147707641 0007421 0 ustar 00
helpers/irc.xml 0000644 00000000206 15147707641 0007517 0 ustar 00
helpers/sip.xml 0000644 00000000236 15147707641 0007540 0 ustar 00
helpers/tftp.xml 0000644 00000000170 15147707641 0007717 0 ustar 00
helpers/RAS.xml 0000644 00000000172 15147707641 0007371 0 ustar 00
helpers/Q.931.xml 0000644 00000000172 15147707641 0007457 0 ustar 00
helpers/amanda.xml 0000644 00000000175 15147707641 0010170 0 ustar 00
helpers/snmp.xml 0000644 00000000207 15147707641 0007720 0 ustar 00
helpers/sane.xml 0000644 00000000172 15147707641 0007672 0 ustar 00
services/memcache.xml 0000644 00000000365 15147707641 0010673 0 ustar 00
memcache
memcache is a high-performance object caching system.
services/xdmcp.xml 0000644 00000000511 15147707641 0010235 0 ustar 00
XDMCP
The X Display Manager Control Protocol (XDMCP) allows to remotely log in to an X desktop environment from any X Window System compatible client.
services/kdeconnect.xml 0000644 00000000420 15147707641 0011236 0 ustar 00
KDE Connect
KDE Connect is an application to connect your phone to your computer.
services/kshell.xml 0000644 00000000362 15147707641 0010410 0 ustar 00
kshell
Kerberized rshell server accepts rshell commands authenticated and encrypted with Kerberos 5
services/ceph-mon.xml 0000644 00000000446 15147707641 0010637 0 ustar 00
ceph-mon
Ceph is a distributed object store and file system. Enable this option to support Ceph's Monitor Daemon.
services/netbios-ns.xml 0000644 00000000406 15147707641 0011206 0 ustar 00
NetBIOS NS
This allows you to find Windows (Samba) servers that share files and printers.
services/audit.xml 0000644 00000000455 15147707641 0010237 0 ustar 00
Audit
The Linux Audit subsystem is used to log security events. Enable this option, if you plan to aggregate audit events to/from a remote server/client.
services/bb.xml 0000644 00000000655 15147707641 0007516 0 ustar 00
Big Brother
Big Brother is a plain text protocol for sending and receiving client data, reports, and queries to a BB-compatible monitoring server or proxy. The standard IANA port for a listening Big Brother service is 1984, because of course it is.
services/matrix.xml 0000644 00000000660 15147707641 0010433 0 ustar 00
Matrix
Matrix is an ambitious new ecosystem for open federated Instant Messaging and VoIP. Port 443 is the 'client' port, whereas port 8448 is the Federation port. Federation is the process by which users on different servers can participate in the same room.
services/zabbix-agent.xml 0000644 00000000472 15147707641 0011503 0 ustar 00
Zabbix Agent
Zabbix is a mature and effortless enterprise-class open source monitoring solution for network monitoring and application monitoring of millions of metrics.
services/pulseaudio.xml 0000644 00000000636 15147707641 0011304 0 ustar 00
PulseAudio
A PulseAudio server provides an ability to stream audio over network. You want to enable this service in case you are using module-native-protocol-tcp in the PulseAudio configuration. If you are using module-zeroconf-publish you want also enable mdns service.
services/smtp-submission.xml 0000644 00000000347 15147707641 0012305 0 ustar 00
Mail (SMTP-Submission)
SMTP-Submission allows remote users to submit mail over port 587.
services/quassel.xml 0000644 00000000421 15147707641 0010577 0 ustar 00
Quassel IRC
Quassel is a distributed IRC client, meaning that one or more clients can attach to and detach from the central core.
services/high-availability.xml 0000644 00000001140 15147707641 0012510 0 ustar 00
Red Hat High Availability
This allows you to use the Red Hat High Availability (previously named Red Hat Cluster Suite). Ports are opened for corosync, pcsd, pacemaker_remote, dlm and corosync-qnetd.
services/smtp.xml 0000644 00000001046 15147707641 0010111 0 ustar 00
Mail (SMTP)
This option allows incoming SMTP mail delivery. If you need to allow remote hosts to connect directly to your machine to deliver mail, enable this option. You do not need to enable this if you collect your mail from your ISP's server by POP3 or IMAP, or if you use a tool such as fetchmail. Note that an improperly configured SMTP server can allow remote machines to use your server to send spam.
services/jenkins.xml 0000644 00000000325 15147707641 0010566 0 ustar 00
jenkins
Jenkins is an open source automation server written in Java.
services/zabbix-server.xml 0000644 00000000473 15147707641 0011714 0 ustar 00
Zabbix Server
Zabbix is a mature and effortless enterprise-class open source monitoring solution for network monitoring and application monitoring of millions of metrics.
services/bareos-director.xml 0000644 00000000606 15147707641 0012213 0 ustar 00
Bareos Director Daemon (bareos-dir)
This option allows connections to a local Bareos Director. These connections are typically initiated by Bareos consoles (bconsole). Bareos WebUI and Bareos File Daemon (when using Client Initiated Connections).
services/rsyncd.xml 0000644 00000000467 15147707641 0010436 0 ustar 00
Rsync in daemon mode
Rsync in daemon mode works as a central server, in order to house centralized files and keep them synchronized.
services/freeipa-trust.xml 0000644 00000001221 15147707641 0011713 0 ustar 00
FreeIPA trust setup
FreeIPA is an LDAP and Kerberos domain controller for Linux systems. Enable this option of you plan to deploy cross-forest trusts with FreeIPA and Active Directory
services/minidlna.xml 0000644 00000000516 15147707641 0010722 0 ustar 00
MiniDLNA
MiniDLNA is a simple media server software with the aim to be fully compliant with DLNA/UPNP-AV clients. Enable this service if you run minidlna service.
services/ws-discovery-udp.xml 0000644 00000000567 15147707641 0012361 0 ustar 00
WS-Discovery (UDP)
Web Services Dynamic Discovery (WS-Discovery) is a technical specification that defines a multicast discovery protocol to locate services on a local network.
services/xmpp-server.xml 0000644 00000001041 15147707641 0011411 0 ustar 00
XMPP (Jabber) server
Extensible Messaging and Presence Protocol (XMPP) server connection protocols allows multiple XMPP (Jabber) servers to work in a federated fashion. Users on one server will be able to see the presence of and communicate with users on another servers. Enable this if you run an XMPP (Jabber) server and you wish users on your server to communicate with users on other XMPP servers.
services/opentelemetry.xml 0000644 00000000612 15147707641 0012020 0 ustar 00
OTLP
OpenTelemetry Protocol (OTLP) specification describes the encoding, transport, and delivery mechanism of telemetry data between telemetry sources, intermediate nodes such as collectors and telemetry backends.
services/ssh.xml 0000644 00000000717 15147707641 0007727 0 ustar 00
SSH
Secure Shell (SSH) is a protocol for logging into and executing commands on remote machines. It provides secure encrypted communications. If you plan on accessing your machine remotely via SSH over a firewalled interface, enable this option. You need the openssh-server package installed for this option to be useful.
services/bitcoin.xml 0000644 00000000364 15147707641 0010557 0 ustar 00
Bitcoin
The default port used by Bitcoin. Enable this option if you plan to be a full Bitcoin node.
services/pmcd.xml 0000644 00000000661 15147707641 0010053 0 ustar 00
Performance metrics collector (pmcd)
This option allows PCP (Performance Co-Pilot) monitoring. If you need to allow remote hosts to connect directly to your machine to monitor aspects of its performance, enable this option. You need the pcp package installed for this option to be useful.
services/cfengine.xml 0000644 00000000250 15147707641 0010700 0 ustar 00
CFEngine
CFEngine server
services/dds-unicast.xml 0000644 00000001663 15147707641 0011351 0 ustar 00
OMG DDS
Open Management Group (OMG) Data Distribution Service (DDS) is protocol supporting various applications. It is usally found in control systems. This is the unicast service for domains with ID 0 ito 10 and maximal possible applications (120). Please see https://community.rti.com/content/forum-topic/statically-configure-firewall-let-omg-dds-traffic-through for details.
services/ipsec.xml 0000644 00000001577 15147707641 0010242 0 ustar 00
IPsec
Internet Protocol Security (IPsec) is the standardized IETF VPN architecture defined in RFC 4301. IPsec is negotiated using the IKEv1 (RFC 2409) or IKEv2 (RFC 7296) protocol, which in itself uses encryption and authentication. IPsec provides Internet Protocol (IP) packet encryption and authentication. Both IKE and IPsec can be encapsulated in UDP (RFC 3948) or TCP (RFC 8229 to make it easier to traverse NAT. Enabling this service will enable IKE, IPsec and their encapsulation protocols and ports. Note that IKE and IPsec can also be configured to use non-default ports, but this is not common practice.
services/klogin.xml 0000644 00000000371 15147707641 0010411 0 ustar 00
klogin
The kerberized rlogin server accepts BSD-style rlogin sessions, but uses Kerberos 5 authentication.
services/rtsp.xml 0000644 00000000536 15147707641 0010121 0 ustar 00
RTSP
The Real Time Streaming Protocol (RTSP) is a network control protocol designed for use in entertainment and communications systems to control streaming media servers.
services/http3.xml 0000644 00000000520 15147707641 0010164 0 ustar 00
WWW (HTTP/3)
HTTP/3 is a protocol used to serve Web pages that uses QUIC as the transport protocol. If you plan to make your HTTP/3 compatible Web server publicly available, enable this option.
services/llmnr-tcp.xml 0000644 00000000632 15147707641 0011036 0 ustar 00
LLMNR (TCP)
Link-Local Multicast Name Resolution (LLMNR) allows both IPv4 and IPv6
hosts to perform name resolution for hosts on the same local network. This
service matches incoming queries; it will allow this host to be resolved
by other hosts.
services/tinc.xml 0000644 00000000520 15147707641 0010057 0 ustar 00
tinc VPN
tinc is a Virtual Private Network (VPN) daemon that uses tunnelling and encryption to create a secure private network between hosts on the Internet.
services/dns-over-tls.xml 0000644 00000000476 15147707641 0011471 0 ustar 00
DNS over TLS
DNS over TLS (DoT) is a security protocol for encrypting and wrapping Domain Name System (DNS) queries and answers via the Transport Layer Security (TLS) protocol
services/syncthing-relay.xml 0000644 00000000636 15147707641 0012252 0 ustar 00
Syncthing Relay
Syncthing is a peer-to-peer file synchronization service. Only enable this option if you run a Syncthing relay server. This separate program (syncthing-relaysrv or relaysrv) is not needed for normal Syncthing usage.
services/distcc.xml 0000644 00000000315 15147707641 0010375 0 ustar 00
distcc
Distcc is a protocol used for distributed compilation.
services/netdata-dashboard.xml 0000644 00000000363 15147707641 0012474 0 ustar 00
Netdata Dashboard
Netdata dashboard is a place to view the results of the netdata monitoring agent
services/wbem-http.xml 0000644 00000000540 15147707641 0011033 0 ustar 00
wbem-http
Web-Based Enterprise Management (WBEM) is a set of systems management technologies developed to unify the management of distributed computing environments. This is the unencrypted protocol variant.
services/svn.xml 0000644 00000000347 15147707641 0007737 0 ustar 00
Subversion
The custom, unencrypted protocol used the Subversion Version Control System.
services/ws-discovery-tcp.xml 0000644 00000000500 15147707641 0012342 0 ustar 00
WS-Discovery (TCP)
Web Services Dynamic Discovery (WS-Discovery) is a technical specification that defines a multicast discovery protocol to locate services on a local network.
services/isns.xml 0000644 00000000546 15147707641 0010106 0 ustar 00
iSNS
The Internet Storage Name Service (iSNS) is a protocol that allows automated discovery, management and configuration of iSCSI and Fibre Channel devices on a TCP/IP network.
services/kubelet.xml 0000644 00000000357 15147707641 0010565 0 ustar 00
Kubernetes Kubelet
The kubelet API is used to communicate between kube-scheduler and the node.
services/http.xml 0000644 00000000541 15147707641 0010104 0 ustar 00
WWW (HTTP)
HTTP is the protocol used to serve Web pages. If you plan to make your Web server publicly available, enable this option. This option is not required for viewing pages locally or developing Web pages.
services/amqp.xml 0000644 00000000421 15147707641 0010060 0 ustar 00
amqp
The Advanced Message Queuing Protocol (AMQP) is an open standard application layer protocol for message-oriented middleware.
services/ovirt-imageio.xml 0000644 00000000404 15147707641 0011676 0 ustar 00
oVirt Image I/O
oVirt Image I/O simplifies the workflow of introducing new oVirt images into the oVirt environment.
services/managesieve.xml 0000644 00000000535 15147707641 0011414 0 ustar 00
ManageSieve
The ManageSieve Protocol allows a local client to manage eMail sieve scripts on a remote server. If you plan to provide a ManageSieve service (e.g. with dovecot pigeonhole), enable this option.
services/condor-collector.xml 0000644 00000000404 15147707641 0012373 0 ustar 00
HT Condor Collector
The HT Condor Collector is needed to organize the condor worker nodes.
services/nut.xml 0000644 00000000560 15147707641 0007734 0 ustar 00
NUT
Network UPS Tools (NUT) is a protocol that allows to monitor and control power devices like uninterruptible power supplies.
services/freeipa-replication.xml 0000644 00000000362 15147707641 0013050 0 ustar 00
FreeIPA replication (deprecated)
This service is deprecated. Please use freeipa-4 service instead.
services/zerotier.xml 0000644 00000000362 15147707641 0010771 0 ustar 00
ZeroTier
ZeroTier creates secure networks between on-premise, cloud, desktop, and mobile devices.
services/xmpp-client.xml 0000644 00000000750 15147707641 0011367 0 ustar 00
XMPP (Jabber) client
Extensible Messaging and Presence Protocol (XMPP) client connection protocol allows XMPP (Jabber) clients such as Empathy, Pidgin, Kopete and Jitsi to connect to an XMPP (Jabber) server. Enable this if you run an XMPP (Jabber) server and you wish clients to be able to connect to the server and communicate with each other.
services/tentacle.xml 0000644 00000000374 15147707641 0010730 0 ustar 00
tentacle
Tentacle is a protocol for monitoring computer networks. Pandora FMS is one server implementation.
services/transmission-client.xml 0000644 00000000364 15147707641 0013135 0 ustar 00
Transmission
Transmission is a lightweight BitTorrent client.
services/ftp.xml 0000644 00000000551 15147707641 0007717 0 ustar 00
FTP
FTP is a protocol used for remote file transfer. If you plan to make your FTP server publicly available, enable this option. You need the vsftpd package installed for this option to be useful.
services/openvpn.xml 0000644 00000000517 15147707641 0010615 0 ustar 00
OpenVPN
OpenVPN is a virtual private network (VPN) solution. It is used to create encrypted point-to-point tunnels between computers. If you plan to provide a VPN service, enable this option.
services/ovirt-storageconsole.xml 0000644 00000000527 15147707641 0013321 0 ustar 00
oVirt Storage-Console
oVirt Storage Console is a web-based storage management platform specially designed to efficiently manage oVirt's storage-defined storage.
services/vdsm.xml 0000644 00000001121 15147707641 0010071 0 ustar 00
oVirt's Virtual Desktop and Server Manager
The VDSM service is required by a Virtualization Manager to manage the Linux hosts. VDSM manages and monitors the host's storage, memory and networks as well as virtual machine creation, other host administration tasks, statistics gathering, and log collection.
services/cockpit.xml 0000644 00000000323 15147707641 0010557 0 ustar 00
Cockpit
Cockpit lets you access and configure your server remotely.
services/warpinator.xml 0000644 00000000673 15147707641 0011321 0 ustar 00
Warpinator
Warpinator is a file sharing app developed by Linux Mint. Warpinator allows you to send and receive files between computers that are on the same network without the need for any servers or special configuration.
services/libvirt-tls.xml 0000644 00000000601 15147707641 0011375 0 ustar 00
Virtual Machine Management (TLS)
Enable this option if you want to allow remote virtual machine management with TLS encryption, x509 certificates and optional SASL authentication. The libvirtd service is needed for this option to be useful.
services/syncthing.xml 0000644 00000000536 15147707641 0011137 0 ustar 00
Syncthing
Syncthing is a peer-to-peer file synchronization service. Enable this option, if you plan to run the Syncthing service.
services/pmwebapi.xml 0000644 00000000714 15147707641 0010733 0 ustar 00
Performance metrics web API (pmwebapi)
This option allows web clients to use PCP (Performance Co-Pilot) monitoring services. If you need to allow remote web clients to connect to your machine to monitor aspects of its performance, enable this option. You need the pcp package installed for this option to be useful.
services/kprop.xml 0000644 00000000266 15147707641 0010264 0 ustar 00
kprop
Kerberos KDC Propagation Protocol
services/syncthing-gui.xml 0000644 00000000451 15147707641 0011715 0 ustar 00
Syncthing GUI
Enable this option in addition to the Syncthing option to allow traffic to the Syncthing web interface. (Be sure to secure it accordingly).
services/kadmin.xml 0000644 00000000266 15147707641 0010374 0 ustar 00
kadmin
Kerberos Administration Protocol
services/wsman.xml 0000644 00000000474 15147707641 0010257 0 ustar 00
wsman
Web Services for Management (WSMAN) is a protocol for managing PCs, servers, devices, Web services and other applications. This variant of the protocol is unencrypted
services/plex.xml 0000644 00000001545 15147707641 0010102 0 ustar 00
PLEX
Plex Media Server (PMS) is the back-end media server component of Plex. It organizes content from personal media libraries and streams it to the network.
services/collectd.xml 0000644 00000000450 15147707641 0010715 0 ustar 00
Collectd
Collectd is a monitoring system that allows metrics to be sent over the network. This rule allows incoming collectd traffic from remote boxes.
services/ws-discovery.xml 0000644 00000000545 15147707641 0011567 0 ustar 00
WS-Discovery
Web Services Dynamic Discovery (WS-Discovery) is a technical specification that defines a multicast discovery protocol to locate services on a local network.
services/pmwebapis.xml 0000644 00000001040 15147707641 0011107 0 ustar 00
Secure performance metrics web API (pmwebapis)
This option allows web clients to use PCP (Performance Co-Pilot) monitoring services over a secure connection. If you need to allow remote web clients to connect to your machine to monitor aspects of its performance, and you consider that information to be sensitive, enable this option. You need the pcp package installed for this option to be useful.
services/ovirt-vmconsole.xml 0000644 00000000353 15147707641 0012274 0 ustar 00
oVirt VM Console
oVirt VM Consoles enables secure access to virtual machine serial console.
services/nebula.xml 0000644 00000000465 15147707641 0010400 0 ustar 00
Nebula
Nebula is a scalable overlay networking tool with a focus on performance, simplicity and security. The port needs to be open if the host is set as lighthouse.
services/ps2link.xml 0000644 00000000406 15147707641 0010507 0 ustar 00
ps2link
ps2link is a protocol used for interacting with a PlayStation 2 system.
services/freeipa-4.xml 0000644 00000001305 15147707641 0010700 0 ustar 00
FreeIPA 4 server
FreeIPA is an integrated identity and authentication solution with Kerberos, LDAP, PKI, and web UI. Enable this option if you plan to provide a FreeIPA server. Enable the 'dns' service if this FreeIPA server provides DNS services, 'ntp' service if this FreeIPA server provides NTP services, and 'freeipa-trust' for cross-forest trusts with Active Directory.
services/git.xml 0000644 00000000324 15147707641 0007707 0 ustar 00
git
The git daemon for supporting git:// access to git repositories.
services/kube-nodeport-services.xml 0000644 00000000340 15147707641 0013521 0 ustar 00
Kubernetes Kubelet
Services of type NodePort expose a port on each worker
services/postgresql.xml 0000644 00000000265 15147707641 0011333 0 ustar 00
PostgreSQL
PostgreSQL Database Server
services/wbem-https.xml 0000644 00000000466 15147707641 0011225 0 ustar 00
wbem-https
Web-Based Enterprise Management (WBEM) is a set of systems management technologies developed to unify the management of distributed computing environments
services/pmproxy.xml 0000644 00000000732 15147707641 0010645 0 ustar 00
Performance metrics proxy (pmproxy)
This option allows indirect PCP (Performance Co-Pilot) monitoring via a proxy. If you need to allow remote hosts to connect through your machine to monitor aspects of performance of one or more proxied hosts, enable this option. You need the pcp package installed for this option to be useful.
services/kibana.xml 0000644 00000000600 15147707641 0010346 0 ustar 00
Kibana
Kibana is an open source data visualization platform that allows you to interact with your data through stunning, powerful graphics that can be combined into custom dashboards that help you share insights from your data far and wide.
services/llmnr-client.xml 0000644 00000000724 15147707641 0011530 0 ustar 00
LLMNR Client
Link-Local Multicast Name Resolution (LLMNR) allows both IPv4 and IPv6
hosts to perform name resolution for hosts on the same local network. This
service allows incoming LLMNR responses. Due to protocol details the
service matches by source port and thus allows unsolicited responses.
services/nfs3.xml 0000644 00000000526 15147707641 0010001 0 ustar 00
NFS3
The NFS3 protocol is used to share files. You will need to have the NFS tools installed and properly configure your NFS server for this option to be useful.
services/lightning-network.xml 0000644 00000000415 15147707641 0012577 0 ustar 00
Lightning Network
The default port used by Lightning Network. Enable this option if you plan to be a Lightning Network node.
services/apcupsd.xml 0000644 00000000435 15147707641 0010566 0 ustar 00
apcupsd
The American Power Conversion (APC) uninterruptible power supply (UPS) daemon protocol allows to monitor and control APC UPS devices.
services/gpsd.xml 0000644 00000000626 15147707641 0010066 0 ustar 00
gpsd
gpsd is a service daemon that monitors one or more GPSes or AIS receivers attached to a host computer through serial or USB ports, making all data on the location/course/velocity of the sensors available to be queried on TCP port 2947 of the host computer.
services/rpc-bind.xml 0000644 00000000326 15147707641 0010624 0 ustar 00
rpc-bind
Remote Procedure Call Bind
services/kerberos.xml 0000644 00000000351 15147707641 0010740 0 ustar 00
Kerberos
Kerberos network authentication protocol server
services/privoxy.xml 0000644 00000000775 15147707641 0010656 0 ustar 00
Privoxy - A Privacy Enhancing Proxy Server
Privoxy is a web proxy for enhancing privacy by filtering web page content, managing cookies, controlling access, removing ads, banners, pop-ups and other obnoxious Internet junk. It does not cache web content. Enable this if you run Privoxy and would like to configure your web browser to browse the Internet via Privoxy.
services/bacula-client.xml 0000644 00000000500 15147707641 0011623 0 ustar 00
Bacula Client
This option allows a Bacula server to connect to the local machine to schedule backups. You need the bacula-client package installed for this option to be useful.
services/samba.xml 0000644 00000000576 15147707641 0010220 0 ustar 00
Samba
This option allows you to access and participate in Windows file and printer sharing networks. You need the samba package installed for this option to be useful.
services/irc.xml 0000644 00000000367 15147707641 0007710 0 ustar 00
IRC
An IRCd, short for Internet Relay Chat daemon, is server software that implements the IRC protocol.
services/sip.xml 0000644 00000000760 15147707641 0007723 0 ustar 00
SIP
The Session Initiation Protocol (SIP) is a communications protocol for signaling and controlling multimedia communication sessions. The most common applications of SIP are in Internet telephony for voice and video calls, as well as instant messaging, over Internet Protocol (IP) networks.
services/ctdb.xml 0000644 00000000450 15147707641 0010040 0 ustar 00
CTDB
CTDB is a cluster implementation of the TDB database used by Samba and other projects to store temporary data.
services/https.xml 0000644 00000000700 15147707641 0010264 0 ustar 00
Secure WWW (HTTPS)
HTTPS is a modified HTTP used to serve Web pages when security is important. Examples are sites that require logins like stores or web mail. This option is not required for viewing pages locally or developing Web pages. You need the httpd package installed for this option to be useful.
services/tftp.xml 0000644 00000000650 15147707641 0010103 0 ustar 00
TFTP
The Trivial File Transfer Protocol (TFTP) is a protocol used to transfer files to and from a remote machine in a simple way. It is normally used only for booting diskless workstations and also to transfer data in the Preboot eXecution Environment (PXE).
services/proxy-dhcp.xml 0000644 00000000405 15147707641 0011221 0 ustar 00
Proxy DHCP
PXE redirection service (Proxy DHCP) responds to PXE clients and provides redirection to PXE boot servers.
services/squid.xml 0000644 00000000255 15147707641 0010254 0 ustar 00
squid
Squid HTTP proxy server
services/dhcpv6.xml 0000644 00000000352 15147707641 0010317 0 ustar 00
DHCPv6
This allows a DHCPv6 server to accept messages from DHCPv6 clients and relay agents.
services/steam-streaming.xml 0000644 00000001167 15147707641 0012232 0 ustar 00
Steam In-Home Streaming
Steam in-home streaming allows you to play a game on one computer when the game process is actually running on another computer elsewhere in your home. Through Steam, game audio and video is captured on the remote computer and sent to the player's computer. The game input (keyboard, mouse or gamepad) is sent from the player's computer to the game process on the remote computer.
services/wireguard.xml 0000644 00000000435 15147707641 0011120 0 ustar 00
WireGuard
WireGuard is the simple, fast and modern VPN. The port needs to be open if a peer has this host explicitly configured as endpoint.
services/murmur.xml 0000644 00000000362 15147707641 0010455 0 ustar 00
Murmur
Murmur is the server of the Mumble VoIP chat system.
services/kube-scheduler-secure.xml 0000644 00000000510 15147707641 0013307 0 ustar 00
Kubernetes Scheduler - secure
The Kubernetes scheduler is a policy-rich, topology-aware, workload-specific function that significantly impacts availability, performance, and capacity.
services/cratedb.xml 0000644 00000000527 15147707641 0010535 0 ustar 00
CrateDB
CrateDB is a distributed SQL database management system that integrates a fully searchable document oriented data store.
services/kube-worker.xml 0000644 00000000566 15147707641 0011371 0 ustar 00
Kubernetes Worker Node
The Kubernetes Worker Node runs some (or sometimes all) of the workloads of the Kubernetes cluster. There might be NodoPort services associated with these workloads.
services/ceph.xml 0000644 00000000511 15147707641 0010041 0 ustar 00
ceph
Ceph is a distributed object store and file system. Enable this option to support Ceph's Object Storage Daemons (OSD), Metadata Server Daemons (MDS), or Manager Daemons (MGR).
services/snmptls.xml 0000644 00000000606 15147707641 0010627 0 ustar 00
Secure SNMP (TLS)
Simple Network Management Protocol over TLS/DTLS is an "Internet-standard protocol for managing devices on IP networks" protected by TLS. Enable this service if you run SNMP agent (server).
services/finger.xml 0000644 00000000340 15147707641 0010374 0 ustar 00
finger
Finger is a protocol for obtaining information about users on remote hosts.
services/kube-apiserver.xml 0000644 00000000464 15147707641 0012055 0 ustar 00
Kubernetes Api Server
The Kubernetes API server validates and configures data for the api objects which include pods, services, replicationcontrollers, and others.
services/ntp.xml 0000644 00000000605 15147707641 0007727 0 ustar 00
Network Time Protocol (NTP) Server
The Network Time Protocol (NTP) allows to synchronize computers to a time server. Enable this option, if you are providing a NTP server. You need the ntp or chrony package installed for this option to be useful.
services/bacula.xml 0000644 00000000532 15147707641 0010354 0 ustar 00
Bacula
Bacula is a network backup solution. Enable this option, if you plan to provide Bacula backup, file and storage services.
services/bitcoin-rpc.xml 0000644 00000000423 15147707641 0011335 0 ustar 00
Bitcoin RPC
Enable this option if you need access to the Bitcoin RPC interface. This is not required when connecting on localhost.
services/dds.xml 0000644 00000001076 15147707641 0007703 0 ustar 00
OMG DDS
Open Management Group (OMG) Data Distribution Service (DDS) is protocol supporting various applications. It is usally found in control systems. This is the unicast and multicast service for domains with ID 0 through 10 and maximal possible applications (120). Please see https://community.rti.com/content/forum-topic/statically-configure-firewall-let-omg-dds-traffic-through for details.
services/dds-multicast.xml 0000644 00000001725 15147707641 0011707 0 ustar 00
OMG DDS
Open Management Group (OMG) Data Distribution Service (DDS) is protocol supporting various applications. It is usally found in control systems. This is the unicast service for domains with ID 0 to 10 and maximal possible applications (120). Please see https://community.rti.com/content/forum-topic/statically-configure-firewall-let-omg-dds-traffic-through for details.
services/redis.xml 0000644 00000000414 15147707641 0010232 0 ustar 00
redis
Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache and message broker.
services/imap.xml 0000644 00000000507 15147707641 0010055 0 ustar 00
IMAP
The Internet Message Access Protocol(IMAP) allows a local client to access email on a remote server. If you plan to provide a IMAP service (e.g. with dovecot), enable this option.
services/rquotad.xml 0000644 00000000325 15147707641 0010604 0 ustar 00
rquotad
Remote Quota Server Daemon
services/rdp.xml 0000644 00000000267 15147707641 0007717 0 ustar 00
rdp
Microsoft's Remote Desktop Protocol
services/bareos-storage.xml 0000644 00000000474 15147707641 0012047 0 ustar 00
Bareos Storage Daemon (bareos-sd)
This option allows Bareos Director and File Daemons to connect to the local Bareos Storage Daemon to send/receive data and manage volumes.
services/syslog.xml 0000644 00000000511 15147707641 0010442 0 ustar 00
syslog
Syslog is a client/server protocol: a logging application transmits a text message to the syslog receiver. The receiver is commonly called syslogd, syslog daemon or syslog server.
services/bgp.xml 0000644 00000000523 15147707641 0007675 0 ustar 00
BGP service listen
Border Gateway Protocol (BGP) is a standardized exterior gateway protocol designed to exchange routing and reachability information among autonomous systems (AS) on the Internet
services/imaps.xml 0000644 00000000564 15147707641 0010243 0 ustar 00
IMAP over SSL
The Internet Message Access Protocol over SSL (IMAPs) allows a local client to access email on a remote server in a secure way. If you plan to provide a IMAP over SSL service (e.g. with dovecot), enable this option.
services/ceph-exporter.xml 0000644 00000000336 15147707641 0011714 0 ustar 00
ceph-exporter
The Prometheus module running on Ceph manager to expose metrics.
services/grafana.xml 0000644 00000000332 15147707641 0010522 0 ustar 00
grafana
Grafana is an open platform for beautiful analytics and monitoring
services/snmptls-trap.xml 0000644 00000000547 15147707641 0011577 0 ustar 00
Secure SNMPTRAP (TLS)
Secure SNMP traps enable an agent to notify the management station of significant events by way of an unsolicited SNMP message. This port is protected by TLS.
services/tile38.xml 0000644 00000000335 15147707641 0010236 0 ustar 00
tile38
Tile38 is a geospatial database, spatial index, and realtime geofence.
services/sips.xml 0000644 00000000433 15147707641 0010103 0 ustar 00
SIP-TLS (SIPS)
SIP-TLS is a modified SIP (Session Initiation Protocol) using TLS for secure signaling.
services/kube-control-plane-secure.xml 0000644 00000001060 15147707641 0014107 0 ustar 00
Kubernetes Control-plane Node - secure
The Kubernetes Control-plane Node runs all the services of the Kubernetes Control Plane. This includes kube-apiserver, etcd, kube-schedule, kube-controller-manager, cloud-controller-manager, and others
services/amanda-k5-client.xml 0000644 00000000653 15147707641 0012143 0 ustar 00
Amanda Backup Client (kerberized)
The Amanda backup client option allows you to connect to a Amanda backup and archiving server. You need the amanda-client package installed for this option to be useful. This service specifically allows krb5 authentication
services/kpasswd.xml 0000644 00000000335 15147707641 0010602 0 ustar 00
Kpasswd
Kerberos password (Kpasswd) server
services/nfs.xml 0000644 00000000504 15147707641 0007712 0 ustar 00
NFS4
The NFS4 protocol is used to share files via TCP networking. You will need to have the NFS tools installed and properly configure your NFS server for this option to be useful.
services/bitcoin-testnet.xml 0000644 00000000431 15147707641 0012236 0 ustar 00
Bitcoin testnet
The default port used by Bitcoin testnet. Enable this option if you plan to be a Bitcoin full node on the test network.
services/ausweisapp2.xml 0000644 00000000664 15147707641 0011376 0 ustar 00
AusweisApp2
AusweisApp2 is an official government application to provide electronic identification services (eID) in conjunction with an approved electronic identification document such as the german nPA. In order to use your Smartphone as a card reader enable this service.
services/ps3netsrv.xml 0000644 00000000255 15147707641 0011076 0 ustar 00
ps3netsrv
PS3 Network Server
services/dhcp.xml 0000644 00000000343 15147707641 0010043 0 ustar 00
DHCP
This allows a DHCP server to accept messages from DHCP clients and relay agents.
services/pop3.xml 0000644 00000000534 15147707641 0010010 0 ustar 00
POP-3
The Post Office Protocol version 3 (POP3) is a protocol to retrieve email from a remote server over a TCP/IP connection. Enable this option, if you plan to provide a POP3 service (e.g. with dovecot).
services/RH-Satellite-6.xml 0000644 00000001054 15147707641 0011525 0 ustar 00
Red Hat Satellite 6
Red Hat Satellite 6 is a systems management server that can be used to configure new systems, subscribe to updates, and maintain installations in distributed environments.
services/rootd.xml 0000644 00000000516 15147707641 0010256 0 ustar 00
rootd
The (x)rootd server was developed for the root analysis framework to serve root files. However, the server is agnostic to file types and provides POSIX-like access to any type of file.
services/upnp-client.xml 0000644 00000000410 15147707641 0011356 0 ustar 00
UPnP Client
Universal Plug and Play client for auto-configuration of network routers (use only in trusted zones).
services/freeipa-ldaps.xml 0000644 00000000751 15147707641 0011644 0 ustar 00
FreeIPA with LDAPS (deprecated)
This service is deprecated. Please use freeipa-4 service instead.
services/syslog-tls.xml 0000644 00000000674 15147707641 0011254 0 ustar 00
syslog-tls
Syslog is a client/server protocol: a logging application transmits a text message to the syslog receiver. The receiver is commonly called syslogd, syslog daemon or syslog server. Syslog-tls uses TLS encryption to protect the messages during transport.
services/foreman-proxy.xml 0000644 00000000416 15147707641 0011734 0 ustar 00
foreman-proxy
The Smart Proxy is a project which provides a restful API to various sub-systems.
services/foreman.xml 0000644 00000000630 15147707641 0010553 0 ustar 00
foreman
Foreman is a complete lifecycle management tool for physical and virtual servers.
services/kube-scheduler.xml 0000644 00000000477 15147707641 0012037 0 ustar 00
Kubernetes Scheduler
The Kubernetes scheduler is a policy-rich, topology-aware, workload-specific function that significantly impacts availability, performance, and capacity.
services/wsmans.xml 0000644 00000000503 15147707641 0010433 0 ustar 00
wsmans
Web Services for Management (WSMAN) is a protocol for managing PCs, servers, devices, Web services and other applications. This variant of the protocol uses TLS encryption.
services/galera.xml 0000644 00000000444 15147707641 0010362 0 ustar 00
Galera
MariaDB-Galera Database Server
services/elasticsearch.xml 0000644 00000000522 15147707641 0011736 0 ustar 00
Elasticsearch
Elasticsearch is a distributed, open source search and analytics engine, designed for horizontal scalability, reliability, and easy management.
services/synergy.xml 0000644 00000000760 15147707641 0010630 0 ustar 00
Synergy
Synergy lets you easily share your mouse and keyboard between multiple computers, where each computer has its own display. No special hardware is required, all you need is a local area network. Synergy is supported on Windows, Mac OS X and Linux. Redirecting the mouse and keyboard is as simple as moving the mouse off the edge of your screen.
services/bareos-filedaemon.xml 0000644 00000000377 15147707641 0012510 0 ustar 00
Bareos File Daemon (bareos-fd)
This option allows a Bareos Director to connect to the local Bareos File Daemon.
services/mssql.xml 0000644 00000000252 15147707641 0010263 0 ustar 00
mssql
Microsoft SQL Server
services/xmpp-bosh.xml 0000644 00000000775 15147707641 0011053 0 ustar 00
XMPP (Jabber) web client
Extensible Messaging and Presence Protocol (XMPP) web client protocol allows web based chat clients such as JWChat to connect to the XMPP (Jabber) server. This is also known as the Bidirectional-streams Over Synchronous HTTP (BOSH) protocol. Enable this if you run an XMPP (Jabber) server and you wish web clients to connect to your server.
services/mysql.xml 0000644 00000000253 15147707641 0010272 0 ustar 00
MySQL
MySQL Database Server
services/bittorrent-lsd.xml 0000644 00000000632 15147707641 0012102 0 ustar 00
BitTorrent Local Peer Discovery (LSD)
Local Peer Discovery is a protocol designed to support the discovery of BitTorrent peers on a local area network. Enable this service if you run a BitTorrent client.
services/gre.xml 0000644 00000000167 15147707641 0007706 0 ustar 00
services/prometheus-node-exporter.xml 0000644 00000000342 15147707641 0014110 0 ustar 00
prometheus-node-exporter
The node-exporter agent for Prometheus monitoring system.
services/checkmk-agent.xml 0000644 00000000352 15147707641 0011626 0 ustar 00
checkmk agent
The checkmk monitoring agent runs on clients to provide detailed host state.
services/mqtt-tls.xml 0000644 00000000450 15147707641 0010711 0 ustar 00
mqtt-tls
The Message Queuing Telemetry Transport (MQTT) is a machine-to-machine connectivity protocol. This variant of the protocol uses TLS encryption.
services/ldap.xml 0000644 00000000307 15147707641 0010045 0 ustar 00
LDAP
Lightweight Directory Access Protocol (LDAP) server
services/afp.xml 0000644 00000000540 15147707641 0007672 0 ustar 00
AFP
The Apple Filing Protocol (AFP), formerly AppleTalk Filing Protocol, is a proprietary network protocol, and part of the Apple File Service (AFS), that offers file services for macOS and the classic Mac OS.
services/kubelet-worker.xml 0000644 00000000324 15147707641 0012066 0 ustar 00
Kubernetes Worker Node
Backwards compatibility after service renaming
services/ptp.xml 0000644 00000000650 15147707641 0007731 0 ustar 00
Precision Time Protocol (PTP) Master
The Precision Time Protocol (PTP) allows to synchronize computers to a time master. Enable this option, if you are providing a PTP master. You need the linuxptp package installed for this option to be useful.
services/etcd-server.xml 0000644 00000000460 15147707641 0011350 0 ustar 00
etcd Server
etcd implements a distributed key value store that provides a reliably way to store data across a cluster of machines. This is the server side port.
services/ircs.xml 0000644 00000000377 15147707641 0010074 0 ustar 00
IRC TLS/SSL
An IRCd, short for Internet Relay Chat daemon, is server software that implements the IRC protocol.
services/kube-api.xml 0000644 00000000314 15147707641 0010620 0 ustar 00
Kubernetes Kubelet
Backwards compatibility after service renaming
services/bitcoin-testnet-rpc.xml 0000644 00000000463 15147707641 0013025 0 ustar 00
Bitcoin testnet RPC
Enable this option if you need access to the Bitcoin RPC interface running on the testnet. This is not required when connecting on localhost.
services/RH-Satellite-6-capsule.xml 0000644 00000000575 15147707641 0013166 0 ustar 00
Red Hat Satellite 6 Capsule
Red Hat Satellite 6 is a systems management server that can be used to configure new systems, subscribe to updates, and maintain installations in distributed environments.
services/mqtt.xml 0000644 00000000437 15147707641 0010116 0 ustar 00
mqtt
The Message Queuing Telemetry Transport (MQTT) is a machine-to-machine connectivity protocol. This variant of the protocol is unencrypted.
services/telnet.xml 0000644 00000000611 15147707641 0010416 0 ustar 00
Telnet
Telnet is a protocol for logging into remote machines. It is unencrypted, and provides little security from network snooping attacks. Enabling telnet is not recommended. You need the telnet-server package installed for this option to be useful.
services/spideroak-lansync.xml 0000644 00000000625 15147707641 0012556 0 ustar 00
SpiderOak ONE LAN-Sync
SpiderOak ONE is online backup and file hosting service that allows users to access, synchronize and share data using a cloud-based server. Enable this option if you use LAN-Sync option of SpiderOak.
services/ipp-client.xml 0000644 00000000706 15147707641 0011174 0 ustar 00
Network Printing Client (IPP)
The Internet Printing Protocol (IPP) is used for distributed printing. IPP (over udp) provides the ability to get information about a printer (e.g. capability and status) and to control printer jobs. If you plan to use a remote network printer via cups, do not disable this option.
services/xmpp-local.xml 0000644 00000000410 15147707641 0011174 0 ustar 00
XMPP Link-Local Messaging
Serverless XMPP-like communication over local networks based on zero-configuration networking.
services/ws-discovery-client.xml 0000644 00000000543 15147707641 0013041 0 ustar 00
WS-Discovery Client
Web Services Dynamic Discovery (WS-Discovery) is a technical specification that defines a multicast discovery protocol to locate services on a local network. Use only in trusted zones.
services/docker-swarm.xml 0000644 00000000607 15147707641 0011526 0 ustar 00
Docker integrated swarm mode
Natively managed cluster of Docker Engines (>=1.12.0), where you deploy services.
services/svdrp.xml 0000644 00000000437 15147707641 0010267 0 ustar 00
SVDRP
The Simple Video Disk Recorder Protocol (SVDRP) allows to control video disk recorder functionality.
services/snmp.xml 0000644 00000000526 15147707641 0010105 0 ustar 00
SNMP
Simple Network Management Protocol is an "Internet-standard protocol for managing devices on IP networks". Enable this service if you run SNMP agent (server).
services/llmnr.xml 0000644 00000001007 15147707641 0010247 0 ustar 00
LLMNR
Link-Local Multicast Name Resolution (LLMNR) allows both IPv4 and IPv6
hosts to perform name resolution for hosts on the same local network. This
service matches incoming queries; it will allow this host to be resolved
by other hosts. In order to allow this host to resolve other hosts, use
the llmnr-client service.
services/ganglia-master.xml 0000644 00000000260 15147707641 0012016 0 ustar 00
ganglia-master
Ganglia collector
services/ssdp.xml 0000644 00000000645 15147707641 0010103 0 ustar 00
Simple Service Discovery Protocol (SSDP)
The Simple Service Discovery Protocol (SSDP) is a network protocol based on the Internet protocol suite for advertisement and discovery of network services and presence information.
services/llmnr-udp.xml 0000644 00000000717 15147707641 0011044 0 ustar 00
LLMNR (UDP)
Link-Local Multicast Name Resolution (LLMNR) allows both IPv4 and IPv6
hosts to perform name resolution for hosts on the same local network. This
service matches incoming queries; it will allow this host to be resolved
by other hosts.
services/freeipa-ldap.xml 0000644 00000000750 15147707641 0011460 0 ustar 00
FreeIPA with LDAP (deprecated)
This service is deprecated. Please use freeipa-4 service instead.
services/nrpe.xml 0000644 00000000367 15147707641 0010077 0 ustar 00
NRPE
NRPE allows you to execute Nagios plugins on a remote host in as transparent a manner as possible.
services/ms-wbt.xml 0000644 00000000264 15147707641 0010340 0 ustar 00
ms-wbt
Microsoft Windows-based Terminal Server
services/radius.xml 0000644 00000001010 15147707641 0010404 0 ustar 00
RADIUS
The Remote Authentication Dial In User Service (RADIUS) is a protocol for user authentication over networks. It is mostly used for modem, DSL or wireless user authentication. If you plan to provide a RADIUS service (e.g. with freeradius), enable this option.
services/mdns.xml 0000644 00000000650 15147707641 0010067 0 ustar 00
Multicast DNS (mDNS)
mDNS provides the ability to use DNS programming interfaces, packet formats and operating semantics in a small network without a conventional DNS server. If you plan to use Avahi, do not disable this option.
services/dropbox-lansync.xml 0000644 00000000344 15147707641 0012250 0 ustar 00
dropboxlansync
Dropbox LAN sync
services/ipp.xml 0000644 00000000653 15147707641 0007721 0 ustar 00
Network Printing Server (IPP)
The Internet Printing Protocol (IPP) is used for distributed printing. IPP (over tcp) provides the ability to share printers over the network. Enable this option if you plan to share printers via cups over the network.
services/prometheus.xml 0000644 00000000325 15147707641 0011320 0 ustar 00
prometheus
The Prometheus monitoring system and time series database.
services/redis-sentinel.xml 0000644 00000000324 15147707641 0012051 0 ustar 00
redis-sentinel
Redis Sentinel provides high availability for Redis.
services/docker-registry.xml 0000644 00000000566 15147707641 0012251 0 ustar 00
Docker Registry
Docker Registry is the protocol used to serve Docker images. If you plan to make your Docker Registry server publicly available, enable this option. This option is not required for developing Docker images locally.
services/mountd.xml 0000644 00000000323 15147707641 0010431 0 ustar 00
mountd
NFS Mount Lock Daemon
services/kube-controller-manager-secure.xml 0000644 00000000441 15147707641 0015127 0 ustar 00
Kubernetes Controller Manager - Secure
The Kubernetes controller manager is a daemon that embeds the core control loops shipped with Kubernetes.
services/snmptrap.xml 0000644 00000000464 15147707641 0010775 0 ustar 00
SNMPTRAP
SNMP traps enable an agent to notify the management station of significant events by way of an unsolicited SNMP message.
services/tor-socks.xml 0000644 00000001403 15147707641 0011047 0 ustar 00
Tor - SOCKS Proxy
Tor enables online anonymity and censorship resistance by directing Internet traffic through a network of relays. It conceals user's location from anyone conducting network surveillance and traffic analysis. A user wishing to use Tor for anonymity can configure a program such as a web browser to direct traffic to a Tor client using its SOCKS proxy port. Enable this if you run Tor and would like to configure your web browser or other programs to channel their traffic through the Tor SOCKS proxy port. It is recommended that you make this service available only for your computer or your internal networks.
services/puppetmaster.xml 0000644 00000000451 15147707641 0011656 0 ustar 00
Puppet Master
Puppet is a network tool for managing many disparate systems. Puppet Master is a server which Puppet Agents pull their configurations from.
services/rsh.xml 0000644 00000000466 15147707641 0007727 0 ustar 00
rsh
Rsh is a protocol for logging into remote machines. It is unencrypted, and provides little security from network snooping attacks. Enabling rsh is not recommended.
services/nmea-0183.xml 0000644 00000000445 15147707641 0010441 0 ustar 00
nmea-0183
NMEA-0183 Navigational Data server for use with Global Navigation Satellite System (GNSS) devices.
services/iscsi-target.xml 0000644 00000000410 15147707641 0011516 0 ustar 00
iSCSI target
Internet SCSI target is a storage resource located on an iSCSI server.
services/kube-controller-manager.xml 0000644 00000000430 15147707641 0013641 0 ustar 00
Kubernetes Controller Manager
The Kubernetes controller manager is a daemon that embeds the core control loops shipped with Kubernetes.
services/dhcpv6-client.xml 0000644 00000000461 15147707641 0011574 0 ustar 00
DHCPv6 Client
This option allows a DHCP for IPv6 (DHCPv6) client to obtain addresses and other IPv6 settings from DHCPv6 server.
services/pop3s.xml 0000644 00000000545 15147707641 0010175 0 ustar 00
POP-3 over SSL
The Post Office Protocol version 3 (POP3) is a protocol to retrieve email from a remote server over a TCP/IP connection. Enable this option, if you plan to provide a POP3 service (e.g. with dovecot).
services/libvirt.xml 0000644 00000000605 15147707641 0010601 0 ustar 00
Virtual Machine Management
Enable this option if you want to allow remote virtual machine management with SASL authentication and encryption (digest-md5 passwords or GSSAPI/Kerberos). The libvirtd service is needed for this option to be useful.
services/slp.xml 0000644 00000000453 15147707641 0007725 0 ustar 00
SLP
The Service Location Protocol (SLP) is used for discovering services in a local network without prior configuration.
services/amqps.xml 0000644 00000000433 15147707641 0010246 0 ustar 00
amqps
The Advanced Message Queuing Protocol (AMQP) over SSL is an open standard application layer protocol for message-oriented middleware.
services/mosh.xml 0000644 00000000731 15147707641 0010074 0 ustar 00
Mobile shell that supports roaming and intelligent local echo.
Mosh is a remote terminal application that supports intermittent network connectivity, roaming to different IP address without dropping the connection, intelligent local echo and line editing to reduct the effects of "network lag" on high-latency connections.
services/etcd-client.xml 0000644 00000000460 15147707641 0011320 0 ustar 00
etcd Client
etcd implements a distributed key value store that provides a reliably way to store data across a cluster of machines. This is the client side port.
services/samba-client.xml 0000644 00000000523 15147707641 0011464 0 ustar 00
Samba Client
This option allows you to access Windows file and printer sharing networks. You need the samba-client package installed for this option to be useful.
services/vnc-server.xml 0000644 00000000733 15147707641 0011222 0 ustar 00
Virtual Network Computing Server (VNC)
A VNC server provides an external accessible X session. Enable this option if you plan to provide a VNC server with direct access. The access will be possible for displays :0 to :3. If you plan to provide access with SSH, do not open this option and use the via option of the VNC viewer.
services/nbd.xml 0000644 00000000372 15147707641 0007672 0 ustar 00
NBD
Network Block Device (NBD) is a high-performance protocol for exporting disk images between machines.
services/ident.xml 0000644 00000000445 15147707641 0010233 0 ustar 00
Ident Protocol
The Identification Protocol as specified in RFC 1413, which is used to determine the identity of a user of a particular TCP connection.
services/mongodb.xml 0000644 00000000355 15147707641 0010555 0 ustar 00
mongodb
MongoDB is a free and open-source cross-platform document-oriented database program.
services/ldaps.xml 0000644 00000000350 15147707641 0010226 0 ustar 00
LDAPS
Lightweight Directory Access Protocol (LDAP) over Secure Sockets Layer (SSL) server
services/smtps.xml 0000644 00000001101 15147707641 0010264 0 ustar 00
Mail (SMTP over SSL)
This option allows incoming SMTPs mail delivery. If you need to allow remote hosts to connect directly to your machine to deliver mail in a secure way, enable this option. You do not need to enable this if you collect your mail from your ISP's server by POP3 or IMAP, or if you use a tool such as fetchmail. Note that an improperly configured SMTP server can allow remote machines to use your server to send spam.
services/ganglia-client.xml 0000644 00000000270 15147707641 0012002 0 ustar 00
ganglia-client
Ganglia monitoring daemon
services/salt-master.xml 0000644 00000000511 15147707641 0011356 0 ustar 00
Salt Master
Salt is a protocol used for infrastructure management via a dynamic communication bus. These ports are required on the salt master node.
services/amanda-client.xml 0000644 00000000617 15147707641 0011626 0 ustar 00
Amanda Backup Client
The Amanda backup client option allows you to connect to a Amanda backup and archiving server. You need the amanda-client package installed for this option to be useful.
services/kubelet-readonly.xml 0000644 00000000364 15147707641 0012376 0 ustar 00
Kubernetes Kubelet read
The kubelet API is used to communicate between kube-scheduler and the node.
services/dns.xml 0000644 00000000532 15147707641 0007711 0 ustar 00
DNS
The Domain Name System (DNS) is used to provide and request host and domain names. Enable this option, if you plan to provide a domain name service (e.g. with bind).
services/spotify-sync.xml 0000644 00000000423 15147707641 0011573 0 ustar 00
Spotify Client Sync
The Spotify Client allows you to sync local music files with your phone.
services/samba-dc.xml 0000644 00000001416 15147707641 0010576 0 ustar 00
Samba DC
This option allows you to use this computer as a Samba Active Directory Domain Controller. You need the samba-dc package installed for this option to be useful.
services/kube-control-plane.xml 0000644 00000001031 15147707641 0012621 0 ustar 00
Kubernetes Control-plane Node
The Kubernetes Control-plane Node runs all the services of the Kubernetes Control Plane. This includes kube-apiserver, etcd, kube-schedule, kube-controller-manager, cloud-controller-manager, and others
services/sane.xml 0000644 00000000504 15147707641 0010052 0 ustar 00
SANE network daemon (saned)
The SANE (Scanner Access Now Easy) daemon allows remote clients to access image acquisition devices available on the local host.
services/ipfs.xml 0000644 00000000473 15147707641 0010072 0 ustar 00
IPFS
The InterPlanetary File System (IPFS) is a peer-to-peer hypermedia protocol designed to make the web faster, safer, and more open
ipsets/README.md 0000644 00000000035 15147707641 0007344 0 ustar 00 Location for built-in ipsets