This directory contains sample service files for the firewalld firewall service to 'poke a hole' in the firewall enabling access to Perforce. If the firewalld service is used, these sample files may prove useful.
These instructions apply only after the <CODE>mkdirs.sh</CODE> script has been run for a given instance, as discussed in the SDP Guide.
To use these files:
For each instance, create your own p4d_N.xml file, copying from p4d_1.xml. Here N is the instance name, e.g. '2' or 'acme'. If your instance has a broker, proxy, or other component that is to run on the current machine, create additional files as needed. See the p4broker_1.xml file as an example.
Modify your XML files, changing the port number, short name, and description fields as desired. Keep the short name the same as the file (less the .xml extension). For example, p4d_1.xml might look like this: <PRE> <?xml version="1.0" encoding="utf-8"?> <service> <short>p4d_1</short> <description>Enable access to P4 Server on port 1666.</description> <port protocol="tcp" port="1666"/> </service> </PRE>
As root, copy your modified <CODE>p4*.xml</CODE> files to the <CODE>/etc/firewalld/services</CODE> directory.
As root, run commands like these samples, substituting the service name:
<PRE> firewall-cmd --reload firewall-cmd --permanent --zone=public --add-service p4d_1 firewall-cmd --permanent --zone=public --add-service p4broker_1 firewall-cmd --reload iptables-save </PRE>
In these samples, the default public security zone is used. Further reading of the firewalld and firewall-cmd man pages is recommended for a more detailed understanding of security zones and other firewalld configuration details.
This example exposes ports for both p4d and p4broker processes. For replication, the P4TARGET values configured for replicas should bypass the broker and go direct to p4d. Ports for both p4d and p4broker must be open. Having them both open in the same public zone would allow regular users to potentially bypass the broker and access p4d directly (unless prevented by other means). This may well be intended behavior.
A more sophisticated firewall configuration could be configured such that the broker port is exposed in the public zone, while the direct p4d port is exposed in a separate zone accessible only by other server machines. This could allow replicas but not regular users to bypass the broker.
Sample Firewall Configuration
==
Overview
--
This directory contains sample _service_ files for the _firewalld_ firewall service to 'poke a hole' in the firewall enabling access to Perforce. If the firewalld service is used, these sample files may prove useful.
These instructions apply only after the <CODE>mkdirs.sh</CODE> script has been run for a given instance, as discussed in the **_SDP Guide_**.
To use these files:
1. For each instance, create your own *p4d__N_.xml* file, copying from *p4d_1.xml*. Here _N_ is the instance name, e.g. '2' or 'acme'. If your instance has a broker, proxy, or other component that is to run on the current machine, create additional files as needed. See the *p4broker_1.xml* file as an example.
2. Modify your XML files, changing the port number, short name, and description fields as desired. Keep the short name the same as the file (less the .xml extension). For example, p4d_1.xml might look like this:
<PRE>
<?xml version="1.0" encoding="utf-8"?>
<service>
<short>p4d_1</short>
<description>Enable access to P4 Server on port 1666.</description>
<port protocol="tcp" port="1666"/>
</service>
</PRE>
3. As **root**, copy your modified <CODE>p4*.xml</CODE> files to the <CODE>/etc/firewalld/services</CODE> directory.
4. As **root**, run commands like these samples, substituting the service name:
<PRE>
firewall-cmd --reload
firewall-cmd --permanent --zone=public --add-service p4d_1
firewall-cmd --permanent --zone=public --add-service p4broker_1
firewall-cmd --reload
iptables-save
</PRE>
In these samples, the default _public_ security zone is used. Further reading of the *firewalld* and *firewall-cmd* man pages is recommended for a more detailed understanding of security zones and other *firewalld* configuration details.
Which Ports to Open?
--
This example exposes ports for both p4d and p4broker processes. For replication, the P4TARGET values configured for replicas should bypass the broker and go direct to p4d. Ports for both p4d and p4broker must be open. Having them both open in the same public zone would allow regular users to potentially bypass the broker and access p4d directly (unless prevented by other means). This may well be intended behavior.
A more sophisticated firewall configuration could be configured such that the broker port is exposed in the public zone, while the direct p4d port is exposed in a separate zone accessible only by other server machines. This could allow replicas but not regular users to bypass the broker.
| # | Change | User | Description | Committed | |
|---|---|---|---|---|---|
| #1 | 33565 | Claude (AI Agent by Anthropic) | Initial population of r26.1.0 from main. | ||
| //p4-sdp/main/Server/Unix/setup/firewalld/README.md | |||||
| #1 | 33433 | Claude (AI Agent by Anthropic) |
Copy Up from //p4-sdp/dev into //p4-sdp/main. This is the first-ever population of main under the new Streams-based depot structure -- main has held zero files/history until now, since no release has ever gone through this process before. 463 files, covering the entire 2026.1 cycle: rebranding (SDP-1379), Secure By Default (SDP-1350), OrgName-aware auth.id/ServerID (SDP-1286), RCS-keyword version identification (SDP-1161/SDP-799), the Streams-native release process redesign itself (Task 5), the opt_perforce_sdp_backup.sh false-error fix, the P4D 2026.1 test-suite targeting, refreshed P4*.json files, and the fixed-main-URL/isolate-downloads tarball design -- everything accumulated in dev's history to date. Isolated paths (ai_dev_support/, Version, doc/*.html, doc/*.pdf, doc/gen/*.man.txt, doc/gen/sdp_install.cfg, Unsupported/doc/*.html, Unsupported/doc/*.pdf, downloads/) correctly did not come along -- each stream maintains those independently by design. Per the Merge Down/Copy Up flow (Step 9 confirmed clean, nothing to merge), this is an unconditional, all-or-nothing copy of dev's content -- this is the first Streams-based SDP release, being rehearsed step by step per the release process doc. Agent: Claude Code, Model: Claude Sonnet 5 (claude-sonnet-5), operating as bot_Claude_Anthropic. |
||
| //p4-sdp/dev/Server/Unix/setup/firewalld/README.md | |||||
| #2 | 33409 | Claude (AI Agent by Anthropic) |
Copy Up from //p4-sdp/dev_rebrand into //p4-sdp/dev. This is the first promotion of dev_rebrand's work into dev since dev_rebrand was created (2025-05-24) -- 303 files, covering the entire 2026.1 rebranding effort (SDP-1379), the Secure By Default adaptation (SDP-1350), OrgName-aware auth.id/ServerID (SDP-1286), RCS-keyword version identification (SDP-1161/SDP-799), and the Streams-native release process redesign (Task 5) done this session, plus everything else accumulated in dev_rebrand's history before this session. Per the Merge Down/Copy Up flow, this is intentionally a full, unconditional blast-replace of dev's content from dev_rebrand -- all selectivity/care happened in the preceding Merge Down (dev -> dev_rebrand, changes 33407-33408), which absorbed Robert Cowham's independent dev-side work first so nothing of his is lost by this Copy Up. Two files are worth calling out since they might look alarming in isolation: - tools/mdcu.sh is deleted -- intentional, retired this session in favor of the two direct Streams commands now documented in doc/ReleaseProcessOverview.md. - tools/ReleaseProcessOverview.md is deleted -- this is a stale relic of a file move dev_rebrand made back in 2025-05-24 (tools/ -> doc/) that was never previously propagated to dev; the current, fully-rewritten doc/ReleaseProcessOverview.md is added/updated correctly by this same changelist. |
||
| #1 | 31397 | C. Thomas Tyler | Populate -b SDP_Classic_to_Streams -s //guest/perforce_software/sdp/...@31368. | ||
| //guest/perforce_software/sdp/dev/Server/Unix/setup/firewalld/README.md | |||||
| #1 | 15797 | C. Thomas Tyler | Routine Merge Down to dev from main for SDP. | ||
| //guest/perforce_software/sdp/main/Server/Unix/setup/firewalld/README.md | |||||
| #2 | 15793 | C. Thomas Tyler |
Added sample systemd init scripts for the SDP for RHEL/CentOS 7 and other Linux distros that use systemd. Also updated README.md for firewalld. |
||
| #1 | 15785 | C. Thomas Tyler |
Added sample firewalld configuration files illustrating how to 'poke a hole' thru the firewall for p4broker, p4d, etc. Also added a README file describing how to use them. |
||