Firewall (firewalld)
firewalld is the default dynamic firewall management tool on CentOS / AlmaLinux / Rocky Linux. It provides zone-based firewall management and supports modifying rules at runtime without restarting the service.
firewalld Basic Concepts
Section titled “firewalld Basic Concepts”Zones are the core concept of firewalld. Each zone defines a set of trust levels and corresponding firewall rules, and network interfaces are assigned to different zones.
Commonly used built-in zones:
| Zone | Description |
|---|---|
public | Default zone. Suitable for public network environments; only selected inbound connections are allowed |
trusted | Allows all inbound traffic |
home | Suitable for home networks; trusts other devices on the network |
work | Suitable for work networks |
internal | Suitable for internal networks |
dmz | Suitable for servers in a DMZ; only specific inbound connections are allowed |
external | Suitable for external networks with NAT masquerading enabled |
block | Rejects all inbound connections and returns an ICMP rejection message |
drop | Drops all inbound packets without returning any response |
Checking firewalld Service Status
Section titled “Checking firewalld Service Status”sudo systemctl status firewalldsudo systemctl enable --now firewalldsudo firewall-cmd --statefirewall-cmd Basic Operations
Section titled “firewall-cmd Basic Operations”Viewing the Current Configuration
Section titled “Viewing the Current Configuration”sudo firewall-cmd --get-default-zonesudo firewall-cmd --get-active-zonessudo firewall-cmd --list-allsudo firewall-cmd --zone=public --list-allsudo firewall-cmd --get-zonesViewing Available Services
Section titled “Viewing Available Services”sudo firewall-cmd --get-servicessudo firewall-cmd --info-service=httpPermanent Rules vs. Runtime Rules
Section titled “Permanent Rules vs. Runtime Rules”firewalld rules come in two types:
- Runtime rules: Take effect immediately but are lost after restarting firewalld or the system
- Permanent rules: Written to configuration files and persist after a restart, but do not take effect immediately
sudo firewall-cmd --permanent --add-service=httpsudo firewall-cmd --reloadYou can also add both runtime and permanent rules simultaneously (no reload needed):
sudo firewall-cmd --add-service=httpsudo firewall-cmd --permanent --add-service=httpAllowing Services
Section titled “Allowing Services”Adding a Service
Section titled “Adding a Service”sudo firewall-cmd --permanent --add-service=httpsudo firewall-cmd --reloadsudo firewall-cmd --permanent --add-service=http --add-service=httpssudo firewall-cmd --reloadRemoving a Service
Section titled “Removing a Service”sudo firewall-cmd --permanent --remove-service=httpsudo firewall-cmd --reloadViewing Allowed Services
Section titled “Viewing Allowed Services”sudo firewall-cmd --list-servicesAllowing Ports
Section titled “Allowing Ports”Adding a Port
Section titled “Adding a Port”sudo firewall-cmd --permanent --add-port=8080/tcpsudo firewall-cmd --reloadsudo firewall-cmd --permanent --add-port=53/udpsudo firewall-cmd --reloadsudo firewall-cmd --permanent --add-port=3000-3100/tcpsudo firewall-cmd --reloadRemoving a Port
Section titled “Removing a Port”sudo firewall-cmd --permanent --remove-port=8080/tcpsudo firewall-cmd --reloadViewing Allowed Ports
Section titled “Viewing Allowed Ports”sudo firewall-cmd --list-portsZone Operations
Section titled “Zone Operations”Changing the Default Zone
Section titled “Changing the Default Zone”sudo firewall-cmd --set-default-zone=internalAssigning an Interface to a Specific Zone
Section titled “Assigning an Interface to a Specific Zone”sudo firewall-cmd --permanent --zone=internal --change-interface=ens33sudo firewall-cmd --reloadAdding Rules to a Specific Zone
Section titled “Adding Rules to a Specific Zone”sudo firewall-cmd --permanent --zone=internal --add-service=mysqlsudo firewall-cmd --reloadRich Rules
Section titled “Rich Rules”Rich rules provide more granular firewall control, allowing you to flexibly set rules based on source addresses, destination addresses, ports, and other conditions.
Basic Syntax
Section titled “Basic Syntax”The basic structure of a rich rule:
rule family="ipv4" source address="source_address" service name="service_name" accept/reject/dropAllowing a Specific IP to Access a Service
Section titled “Allowing a Specific IP to Access a Service”sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" service name="ssh" accept'sudo firewall-cmd --reloadDenying Access from a Specific IP
Section titled “Denying Access from a Specific IP”sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.100" drop'sudo firewall-cmd --reloadAllowing a Specific IP to Access a Given Port
Section titled “Allowing a Specific IP to Access a Given Port”sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="172.16.0.0/16" port port="3306" protocol="tcp" accept'sudo firewall-cmd --reloadRules with Logging
Section titled “Rules with Logging”sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.200" log prefix="BLOCKED: " level="warning" drop'sudo firewall-cmd --reloadViewing Rich Rules
Section titled “Viewing Rich Rules”sudo firewall-cmd --list-rich-rulesDeleting a Rich Rule
Section titled “Deleting a Rich Rule”sudo firewall-cmd --permanent --remove-rich-rule='rule family="ipv4" source address="10.0.0.100" drop'sudo firewall-cmd --reloadCommon Scenario Examples
Section titled “Common Scenario Examples”Web Server
Section titled “Web Server”sudo firewall-cmd --permanent --add-service=httpsudo firewall-cmd --permanent --add-service=httpssudo firewall-cmd --permanent --add-service=sshsudo firewall-cmd --reloadDatabase Server (restricting access sources)
Section titled “Database Server (restricting access sources)”sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.10.0/24" service name="mysql" accept'sudo firewall-cmd --reloadCustom Application Port
Section titled “Custom Application Port”sudo firewall-cmd --permanent --add-port=3000/tcpsudo firewall-cmd --reloadPort Forwarding
Section titled “Port Forwarding”sudo firewall-cmd --permanent --add-forward-port=port=80:proto=tcp:toport=8080sudo firewall-cmd --reloadsudo firewall-cmd --permanent --add-forward-port=port=80:proto=tcp:toport=80:toaddr=192.168.1.50sudo firewall-cmd --permanent --add-masqueradesudo firewall-cmd --reloadEnabling IP Masquerading (NAT)
Section titled “Enabling IP Masquerading (NAT)”sudo firewall-cmd --permanent --add-masqueradesudo firewall-cmd --reloadTroubleshooting and Debugging
Section titled “Troubleshooting and Debugging”Viewing All Firewall Rules
Section titled “Viewing All Firewall Rules”sudo firewall-cmd --list-all-zonesViewing Underlying nftables/iptables Rules
Section titled “Viewing Underlying nftables/iptables Rules”sudo nft list rulesetEL 8 and earlier versions use the iptables backend:
sudo iptables -L -n -vViewing firewalld Logs
Section titled “Viewing firewalld Logs”sudo journalctl -u firewalld --no-pager -n 30Panic Mode (block all network traffic)
Section titled “Panic Mode (block all network traffic)”sudo firewall-cmd --panic-onsudo firewall-cmd --panic-offsudo firewall-cmd --query-panicBackup and Restore
Section titled “Backup and Restore”Backing Up the Current Firewall Configuration
Section titled “Backing Up the Current Firewall Configuration”sudo cp -r /etc/firewalld /etc/firewalld.backup.$(date +%Y%m%d)Restoring Configuration
Section titled “Restoring Configuration”sudo cp -r /etc/firewalld.backup.20260324/* /etc/firewalld/sudo firewall-cmd --reload