SELinux labels network ports as well as files. Policy says which process types may bind to, meaning listen on, which port types. For example, httpd_t may bind to ports labeled http_port_t, which by default include 80, 443 and a few others such as 8008 and 8443 (8080 is labeled http_cache_port_t). If you configure a service to listen on a port that does not carry its type, SELinux blocks the bind and the service fails to start, even though the configuration is otherwise perfect.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.