firewalld on Linux: Zones, Services, Ports and Permanent Rules (RHEL/Alma)

firewalld linux - custom-fwld-featured.png

On AlmaLinux, Rocky, and RHEL, firewalld is the default host firewall front-end. Debian admins often know UFW first — the ideas are the same (default deny, allow only what you need), but the commands are firewall-cmd.

Pair with nftables basics and
Fail2ban on RHEL (banaction = firewallcmd-ipset).

Zones and Services Model

Interfaces land in a zone (usually public). Services like http and ssh are predefined port bundles.

firewalld model
zones

Install and Enable firewalld

Replace legacy iptables-services on new installs if needed.

bashRHEL family
sudo dnf install -y firewalld
sudo systemctl enable --now firewalld
sudo firewall-cmd --state
systemctl
running

Inspect the Active Zone

See what is already allowed before you open more.

bashstatus
sudo firewall-cmd --get-active-zones
sudo firewall-cmd --list-all
list-all
interfaces

Allow Standard Web and SSH

Use services when possible — clearer than raw ports in runbooks.

bashweb + ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --reload
add-service
http https ssh

Open a Custom Port

Node apps, metrics, or alternate SSH need explicit ports.

bashport 8080
sudo firewall-cmd --permanent --add-port=8080/tcp
sudo firewall-cmd --reload
add-port
rich rules

Runtime vs Permanent

Without --permanent, rules disappear on reload/reboot. Always add permanent, then reload.

WarningOpening SSH to 0.0.0.0/0 without key-only auth is risky — harden SSH first.
--permanent
reload

Verify From Another Host

Local ss plus remote nc or curl confirms the full path.

bashlocal listen
sudo ss -lntp | grep -E ':80|:443|:22'
verify
ss and curl

Quick Reference

  • firewall-cmd --list-all before changes
  • Use --permanent then --reload
  • Debian/Ubuntu: see our UFW guide instead

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.