OPS535 A1 201603

Network, firewall, and SELinux
* Do not allow DNS queries from any machines in your network to any root name servers in the lab except your caching-only DNS server.
* SELinux must be turned on and run in enforcing mode on all of your VMs. You need to configure the runtime SELinux boolean accordingly.
* You must turn on firewalld as their firewall on all machines. Their interfaces should be placed in the 'work' zone, which should allow ssh traffic. Other than that it should only allow the traffic necessary to fulfil the roles described above.
== Test and evaluation ==

