README.md #1

  • //
  • p4-sdp/
  • r26.1.0/
  • Server/
  • Unix/
  • setup/
  • firewalld/
  • README.md
  • Markdown
  • View
  • Commits
  • Open Download .zip Download (3 KB)

Sample Firewall Configuration

Overview

This directory contains sample service files for the firewalld firewall service to 'poke a hole' in the firewall enabling access to Perforce. If the firewalld service is used, these sample files may prove useful.

These instructions apply only after the <CODE>mkdirs.sh</CODE> script has been run for a given instance, as discussed in the SDP Guide.

To use these files:

  1. For each instance, create your own p4d_N.xml file, copying from p4d_1.xml. Here N is the instance name, e.g. '2' or 'acme'. If your instance has a broker, proxy, or other component that is to run on the current machine, create additional files as needed. See the p4broker_1.xml file as an example.

  2. Modify your XML files, changing the port number, short name, and description fields as desired. Keep the short name the same as the file (less the .xml extension). For example, p4d_1.xml might look like this: <PRE> <?xml version="1.0" encoding="utf-8"?> <service> <short>p4d_1</short> <description>Enable access to P4 Server on port 1666.</description> <port protocol="tcp" port="1666"/> </service> </PRE>

  3. As root, copy your modified <CODE>p4*.xml</CODE> files to the <CODE>/etc/firewalld/services</CODE> directory.

  4. As root, run commands like these samples, substituting the service name:

<PRE> firewall-cmd --reload firewall-cmd --permanent --zone=public --add-service p4d_1 firewall-cmd --permanent --zone=public --add-service p4broker_1 firewall-cmd --reload iptables-save </PRE>

In these samples, the default public security zone is used. Further reading of the firewalld and firewall-cmd man pages is recommended for a more detailed understanding of security zones and other firewalld configuration details.

Which Ports to Open?

This example exposes ports for both p4d and p4broker processes. For replication, the P4TARGET values configured for replicas should bypass the broker and go direct to p4d. Ports for both p4d and p4broker must be open. Having them both open in the same public zone would allow regular users to potentially bypass the broker and access p4d directly (unless prevented by other means). This may well be intended behavior.

A more sophisticated firewall configuration could be configured such that the broker port is exposed in the public zone, while the direct p4d port is exposed in a separate zone accessible only by other server machines. This could allow replicas but not regular users to bypass the broker.

Sample Firewall Configuration
==

Overview
--

This directory contains sample _service_ files for the _firewalld_ firewall service to 'poke a hole' in the firewall enabling access to Perforce. If the firewalld service is used, these sample files may prove useful.

These instructions apply only after the <CODE>mkdirs.sh</CODE> script has been run for a given instance, as discussed in the **_SDP Guide_**.

To use these files:

1. For each instance, create your own *p4d__N_.xml* file, copying from *p4d_1.xml*.  Here _N_ is the instance name, e.g. '2' or 'acme'.  If your instance has a broker, proxy, or other component that is to run on the current machine, create additional files as needed.  See the *p4broker_1.xml* file as an example.

2. Modify your XML files, changing the port number, short name, and description fields as desired.  Keep the short name the same as the file (less the .xml extension).  For example, p4d_1.xml might look like this:
<PRE>
   &lt;?xml version="1.0" encoding="utf-8"?&gt;
   &lt;service&gt;
     &lt;short&gt;p4d_1&lt;/short&gt;
     &lt;description&gt;Enable access to P4 Server on port 1666.&lt;/description&gt;
     &lt;port protocol="tcp" port="1666"/&gt;
   &lt;/service&gt;
</PRE>

3. As **root**, copy your modified <CODE>p4*.xml</CODE> files to the <CODE>/etc/firewalld/services</CODE> directory.

4. As **root**, run commands like these samples, substituting the service name:

<PRE>
firewall-cmd --reload
firewall-cmd --permanent --zone=public --add-service p4d_1
firewall-cmd --permanent --zone=public --add-service p4broker_1
firewall-cmd --reload
iptables-save
</PRE>

In these samples, the default _public_ security zone is used.  Further reading of the *firewalld* and *firewall-cmd* man pages is recommended for a more detailed understanding of security zones and other *firewalld* configuration details.

Which Ports to Open?
--

This example exposes ports for both p4d and p4broker processes.  For replication, the P4TARGET values configured for replicas should bypass the broker  and go direct to p4d.  Ports for both p4d and p4broker must be open.  Having them both open in the same public zone would allow regular users to potentially bypass the broker and access p4d directly (unless prevented by other means).  This may well be intended behavior.

A more sophisticated firewall configuration could be configured such that the broker port is exposed in the public zone, while the direct p4d port is exposed in a separate zone accessible only by other server machines.  This could allow replicas but not regular users to bypass the broker.
# Change User Description Committed
#1 33565 Claude (AI Agent by Anthropic) Initial population of r26.1.0 from main.
//p4-sdp/main/Server/Unix/setup/firewalld/README.md
#1 33433 Claude (AI Agent by Anthropic) Copy Up from //p4-sdp/dev into //p4-sdp/main.

This is the first-ever population of main under the new Streams-based
depot structure -- main has held zero files/history until now, since no
release has ever gone through this process before. 463 files, covering
the entire 2026.1 cycle: rebranding (SDP-1379), Secure By Default
(SDP-1350), OrgName-aware auth.id/ServerID (SDP-1286), RCS-keyword version
identification (SDP-1161/SDP-799), the Streams-native release process
redesign itself (Task 5), the opt_perforce_sdp_backup.sh false-error fix,
the P4D 2026.1 test-suite targeting, refreshed P4*.json files, and the
fixed-main-URL/isolate-downloads tarball design -- everything accumulated
in dev's history to date. Isolated paths (ai_dev_support/, Version,
doc/*.html, doc/*.pdf, doc/gen/*.man.txt, doc/gen/sdp_install.cfg,
Unsupported/doc/*.html, Unsupported/doc/*.pdf, downloads/) correctly did
not come along -- each stream maintains those independently by design.

Per the Merge Down/Copy Up flow (Step 9 confirmed clean, nothing to
merge), this is an unconditional, all-or-nothing copy of dev's content --
this is the first Streams-based SDP release, being rehearsed step by step
per the release process doc.

Agent: Claude Code, Model: Claude Sonnet 5 (claude-sonnet-5), operating as bot_Claude_Anthropic.
//p4-sdp/dev/Server/Unix/setup/firewalld/README.md
#2 33409 Claude (AI Agent by Anthropic) Copy Up from //p4-sdp/dev_rebrand into //p4-sdp/dev.

This is the first promotion of dev_rebrand's work into dev since
dev_rebrand was created (2025-05-24) -- 303 files, covering the entire
2026.1 rebranding effort (SDP-1379), the Secure By Default adaptation
(SDP-1350), OrgName-aware auth.id/ServerID (SDP-1286), RCS-keyword
version identification (SDP-1161/SDP-799), and the Streams-native release
process redesign (Task 5) done this session, plus everything else
accumulated in dev_rebrand's history before this session.

Per the Merge Down/Copy Up flow, this is intentionally a full,
unconditional blast-replace of dev's content from dev_rebrand -- all
selectivity/care happened in the preceding Merge Down (dev -> dev_rebrand,
changes 33407-33408), which absorbed Robert Cowham's independent dev-side
work first so nothing of his is lost by this Copy Up.

Two files are worth calling out since they might look alarming in
isolation:
- tools/mdcu.sh is deleted -- intentional, retired this session in favor
  of the two direct Streams commands now documented in
  doc/ReleaseProcessOverview.md.
- tools/ReleaseProcessOverview.md is deleted -- this is a stale relic of
  a file move dev_rebrand made back in 2025-05-24 (tools/ -> doc/) that
  was never previously propagated to dev; the current, fully-rewritten
  doc/ReleaseProcessOverview.md is added/updated correctly by this same
  changelist.
#1 31397 C. Thomas Tyler Populate -b SDP_Classic_to_Streams -s //guest/perforce_software/sdp/...@31368.
//guest/perforce_software/sdp/dev/Server/Unix/setup/firewalld/README.md
#1 15797 C. Thomas Tyler Routine    Merge Down to dev from main for SDP.
//guest/perforce_software/sdp/main/Server/Unix/setup/firewalld/README.md
#2 15793 C. Thomas Tyler Added sample systemd init scripts for the SDP for RHEL/CentOS 7
and other Linux distros that use systemd.

Also updated README.md for firewalld.
#1 15785 C. Thomas Tyler Added sample firewalld configuration files illustrating how to 'poke a hole'
thru the firewall for p4broker, p4d, etc.  Also added a README file
describing how to use them.