Post Date: October 22, 2018
Last Updated: September 29, 2026
Introduction
firewall-cmd is the command-line client used to manage firewalld, a dynamic firewall management service commonly available on Linux systems.
It provides a convenient way to configure:
- Firewall zones
- Services
- TCP/UDP ports
- Network interfaces
- Source IP addresses
- Rich rules
- Masquerading
- Port forwarding
- Runtime and permanent firewall configurations
One of the most important concepts when working with firewalld is the difference between runtime and permanent configuration.
The runtime configuration is currently active. Changes made without --permanent can be lost when firewalld is reloaded or restarted. Permanent configuration is stored and becomes active after a reload, restart, or system boot.
Prerequisites
You should have:
- A Linux server with
firewalldinstalled rootorsudoaccess- Basic Linux command-line knowledge
- Knowledge of the ports and services that your application actually requires
The commands below are applicable to modern firewalld-based Linux systems. Package installation commands may differ depending on the distribution.
Implemenation
1. Install firewalld
On systems using DNF:
sudo dnf install firewalld
Start and enable the service:
sudo systemctl enable --now firewalld
Check the service:
sudo systemctl status firewalld
Check whether firewalld is running:
sudo firewall-cmd --state
Expected output:
running
You can also check the installed version:
sudo firewall-cmd --version
firewall-cmd is the primary command-line utility for querying and modifying firewalld configuration.
2. Understand Runtime and Permanent Configuration
This is one of the most important concepts in firewalld.
Runtime Configuration
Runtime configuration represents the rules currently active on the system.
For example:
sudo firewall-cmd --zone=public --add-service=http
This immediately allows HTTP traffic in the public zone.
However, the change is not automatically saved to the permanent configuration.
A firewalld reload can therefore remove a runtime-only change.
Permanent Configuration
To save a rule permanently:
sudo firewall-cmd --permanent --zone=public --add-service=http
The permanent configuration must then be loaded into the runtime configuration:
sudo firewall-cmd --reload
Alternatively, you can apply a change both immediately and permanently with two commands:
sudo firewall-cmd --zone=public --add-service=http sudo firewall-cmd --permanent --zone=public --add-service=http
The official firewalld documentation recommends understanding this distinction before making production changes.
Recommended Workflow
For production systems, a useful approach is:
- Make the change in runtime.
- Test connectivity.
- If everything works correctly, save it permanently.
You can save the complete working runtime configuration with:
sudo firewall-cmd --runtime-to-permanent
This overwrites the existing permanent configuration with the current runtime configuration.
3. List Available Firewall Zones
Firewalld uses zones to apply different firewall policies based on the trust level of a network connection.
List the available zones:
sudo firewall-cmd --get-zones
Typical zones include:
block dmz drop external home internal public trusted work
The exact list can vary by firewalld installation.
Check the default zone:
sudo firewall-cmd --get-default-zone
Check currently active zones:
sudo firewall-cmd --get-active-zones
You can also inspect the complete configuration of a zone:
sudo firewall-cmd --zone=public --list-all
Example:
public interfaces: eth0 services: ssh http https ports: protocols: forward: masquerade: no rich rules:
Firewalld zones provide a logical way to associate interfaces or source addresses with different firewall policies.
4. Change the Default Zone
To change the default zone:
sudo firewall-cmd --set-default-zone=work
Verify:
sudo firewall-cmd --get-default-zone
Be careful when changing the default zone on a remote production server. A zone change can alter which firewall rules apply to an interface and may affect remote access.
5. Add a Service to a Zone
Firewalld provides predefined services such as:
- SSH
- HTTP
- HTTPS
- DNS
- SMTP
- FTP
List available services:
sudo firewall-cmd --get-services
For example, to allow HTTP in the public zone:
sudo firewall-cmd --zone=public --add-service=http
To make it permanent:
sudo firewall-cmd --permanent --zone=public --add-service=http sudo firewall-cmd --reload
Allow HTTPS:
sudo firewall-cmd --permanent --zone=public --add-service=https sudo firewall-cmd --reload
Verify:
sudo firewall-cmd --zone=public --list-services
Using a predefined service is generally preferable when the required service already exists because you do not need to manually specify its standard ports.
6. Remove a Service
To remove a service from the runtime configuration:
sudo firewall-cmd --zone=public --remove-service=http
To remove it permanently:
sudo firewall-cmd --permanent --zone=public --remove-service=http sudo firewall-cmd --reload
Verify:
sudo firewall-cmd --zone=public --list-services
7. Open a Specific Port
If a predefined service is not appropriate, you can open a specific port.
For example, to allow TCP port 8080:
sudo firewall-cmd --zone=public --add-port=8080/tcp
To make it permanent:
sudo firewall-cmd --permanent --zone=public --add-port=8080/tcp sudo firewall-cmd --reload
Verify:
sudo firewall-cmd --zone=public --list-ports
For UDP:
sudo firewall-cmd --permanent --zone=public --add-port=51820/udp sudo firewall-cmd --reload
You can also specify a port range:
sudo firewall-cmd --permanent --zone=public --add-port=5000-5010/tcp
The official firewalld documentation supports both individual ports and port ranges.
8. Remove an Open Port
To remove port 8080/tcp:
sudo firewall-cmd --permanent --zone=public --remove-port=8080/tcp sudo firewall-cmd --reload
Verify:
sudo firewall-cmd --zone=public --list-ports
9. Create a Custom Zone
You can create a custom zone when the predefined zones do not match your network requirements.
Create a zone named application:
sudo firewall-cmd --permanent --new-zone=application
Reload firewalld:
sudo firewall-cmd --reload
Verify:
sudo firewall-cmd --get-zones
You can then add services or ports to the new zone:
sudo firewall-cmd --permanent --zone=application --add-port=8080/tcp
Reload:
sudo firewall-cmd --reload
Custom zones can be useful when different interfaces, applications, or source networks require different firewall policies.
10. Associate a Network Interface with a Zone
First identify the available network interfaces:
ip addr
Check the zone associated with an interface:
sudo firewall-cmd --get-zone-of-interface=eth0
To associate an interface with a zone:
sudo firewall-cmd --permanent --zone=internal --add-interface=eth0
Reload:
sudo firewall-cmd --reload
Verify:
sudo firewall-cmd --get-active-zones
Firewalld uses interface and source bindings to determine which zone’s rules apply to traffic.
Warning: On a remote server, changing the zone associated with the active network interface can disconnect your SSH session. Confirm that SSH access is permitted in the target zone before applying the change.
11. Associate a Source IP or Network with a Zone
Instead of assigning an entire interface to a zone, you can associate traffic from a specific source network.
For example:
sudo firewall-cmd --permanent --zone=internal --add-source=192.168.10.0/24
Reload:
sudo firewall-cmd --reload
Verify:
sudo firewall-cmd --zone=internal --list-sources
This can be useful when internal applications should receive different access from trusted network ranges.
12. Delete a Custom Zone
Before deleting a custom zone, verify its configuration:
sudo firewall-cmd --permanent --zone=application --list-all
Delete it:
sudo firewall-cmd --permanent --delete-zone=application
Reload:
sudo firewall-cmd --reload
Only delete custom zones after confirming that no required interfaces or source networks depend on them.
13. Rich Rules
For more advanced firewall conditions, firewalld supports rich rules.
Rich rules allow conditions such as:
- Source IP restrictions
- Specific services
- Specific ports
- Accept, reject, or drop actions
- Logging
- Rate limiting
- More detailed traffic conditions
For example, to reject SSH connections from a specific IP address:
sudo firewall-cmd \ --permanent \ --zone=public \ --add-rich-rule='rule family="ipv4" source address="192.168.1.100" service name="ssh" reject'
Reload:
sudo firewall-cmd --reload
List rich rules:
sudo firewall-cmd --zone=public --list-rich-rules
Remove the rule when required:
sudo firewall-cmd \ --permanent \ --zone=public \ --remove-rich-rule='rule family="ipv4" source address="192.168.1.100" service name="ssh" reject'
Firewalld’s rich language provides a more detailed rule syntax than simply opening or closing a service or port.
14. Example: Allow SSH Only From a Trusted Network
A common security requirement is to restrict SSH access to a known network.
For example:
sudo firewall-cmd \ --permanent \ --zone=public \ --add-rich-rule='rule family="ipv4" source address="192.168.10.0/24" service name="ssh" accept'
However, when implementing restrictive SSH rules, carefully consider the existing zone policy and ensure you have an alternative administrative path before testing the configuration.
For cloud servers, also check the provider’s firewall or security-group rules.
15. Check the Complete Firewall Configuration
To display the configuration of the default zone:
sudo firewall-cmd --list-all
For a specific zone:
sudo firewall-cmd --zone=public --list-all
To list all active zones:
sudo firewall-cmd --list-all-zones
For the permanent configuration:
sudo firewall-cmd --permanent --zone=public --list-all
This distinction is useful when troubleshooting situations where a rule appears to exist but disappears after a reload.
16. Reload firewalld
After making permanent changes:
sudo firewall-cmd --reload
A reload applies the permanent configuration to the runtime environment. Firewalld is designed to preserve existing connections during a normal reload.
Avoid using:
sudo firewall-cmd --complete-reload
unless there is a specific reason to completely reload the firewall.
A complete reload can affect active connections and is intended for more serious firewall problems.
17. Panic Mode
Firewalld provides a panic mode for emergency situations.
Enable panic mode:
sudo firewall-cmd --panic-on
Check the status:
sudo firewall-cmd --query-panic
Disable it:
sudo firewall-cmd --panic-off
Panic mode drops incoming and outgoing packets and should only be used for serious network-security situations. It is a runtime-only setting and cannot be configured with --permanent.
Warning: Enabling panic mode on a remote server can immediately interrupt network connectivity, including SSH access.
18. Check Whether a Port Is Actually Listening
Opening a firewall port does not automatically mean that an application is listening on that port.
For example:
sudo ss -lntp
To check a specific port:
sudo ss -lntp | grep :8080
You should verify both:
- The application is listening on the port.
- The firewall allows the required traffic.
For example:
sudo firewall-cmd --zone=public --list-ports
19. Test the Firewall From Another System
From another Linux system, you can test connectivity using:
nc -vz SERVER_IP 8080
For HTTP:
curl -I http://SERVER_IP:8080
For HTTPS:
curl -Ik https://SERVER_IP
If the service is not reachable, check:
sudo firewall-cmd --state sudo firewall-cmd --get-active-zones sudo firewall-cmd --zone=public --list-all sudo ss -lntp
Also check any external firewall provided by your hosting or cloud platform.
20. Troubleshooting firewall-cmd
Port is open but connection still fails
Check whether the application is listening:
sudo ss -lntp | grep :8080
Then check firewalld:
sudo firewall-cmd --zone=public --list-ports
Also verify:
- Cloud security groups
- Cloud firewalls
- Network ACLs
- Load balancers
- Router/firewall rules
- Application binding address
Rule disappears after reload
Check runtime configuration:
sudo firewall-cmd --zone=public --list-all
Check permanent configuration:
sudo firewall-cmd --permanent --zone=public --list-all
If the rule exists only in runtime, add it permanently or use:
sudo firewall-cmd --runtime-to-permanent
SSH access was lost after firewall changes
If possible, use:
- Cloud console
- Out-of-band management
- Existing administrative session
- Recovery console
Then verify:
sudo firewall-cmd --get-active-zones sudo firewall-cmd --list-services sudo firewall-cmd --list-ports
Make sure SSH is allowed in the correct zone:
sudo firewall-cmd --zone=public --list-services
21. Security Recommendations
When managing a production Linux firewall:
Allow only required services
Do not open ports simply because an application might use them.
Check the application requirements first.
Prefer services where appropriate
For standard services:
--add-service=http
is often clearer than:
--add-port=80/tcp
Restrict administrative ports
SSH should ideally be restricted by:
- Trusted source networks
- VPN access
- Bastion hosts
- Other appropriate access controls
Avoid unnecessary public exposure
Databases such as MySQL, PostgreSQL, Redis, and MongoDB generally should not be publicly exposed unless there is a specific architecture requiring it.
Test before making changes permanent
Use runtime configuration first when appropriate, verify connectivity, then persist the working configuration.
Keep cloud-level controls aligned
For cloud-hosted servers, firewalld is only one layer of network security. Also review:
- Cloud firewall
- Security groups
- Network ACLs
- Load balancer rules
- Private networking
Keep the operating system supported
Do not use an EOL operating system for new production deployments simply because an old firewall tutorial was written for it.
CentOS Linux 7 reached EOL on June 30, 2024.
22. Useful firewall-cmd Commands
| Purpose | Command |
|---|---|
| Check firewalld state | firewall-cmd --state |
| Check version | firewall-cmd --version |
| List zones | firewall-cmd --get-zones |
| Check default zone | firewall-cmd --get-default-zone |
| List active zones | firewall-cmd --get-active-zones |
| List services | firewall-cmd --get-services |
| List zone configuration | firewall-cmd --zone=public --list-all |
| List open services | firewall-cmd --zone=public --list-services |
| List open ports | firewall-cmd --zone=public --list-ports |
| Add HTTP | firewall-cmd --zone=public --add-service=http |
| Add HTTPS permanently | firewall-cmd --permanent --zone=public --add-service=https |
| Open TCP port | firewall-cmd --zone=public --add-port=8080/tcp |
| Reload configuration | firewall-cmd --reload |
| Save runtime configuration | firewall-cmd --runtime-to-permanent |
| Check panic mode | firewall-cmd --query-panic |
Conclusion
firewall-cmd provides a structured way to manage Linux firewall rules through firewalld.
The most important concepts to understand are:
- Zones determine which firewall policy applies.
- Services provide predefined groups of ports and protocols.
- Ports can be opened directly when required.
- Runtime configuration applies immediately but is not automatically persistent.
- Permanent configuration survives reloads and reboots.
- Rich rules provide more granular traffic controls.
- Panic mode provides an emergency mechanism that drops network traffic.
- Firewall configuration should always be considered together with application listening ports and external cloud/network firewalls.
For production systems, avoid blindly opening ports. Identify the required traffic, restrict access to trusted sources where possible, test the configuration, and keep the underlying operating system supported.
Frequently Asked Questions
What is firewall-cmd?
firewall-cmd is the command-line client used to manage firewalld.
What is the difference between firewall-cmd and firewalld?
firewalld is the firewall management service/daemon. firewall-cmd is the command-line interface used to interact with it.
What is the difference between runtime and permanent configuration?
Runtime configuration is currently active. Permanent configuration is stored and loaded when firewalld starts or reloads.
Does --permanent immediately open the port?
No. A permanent change is stored but does not immediately become active. Run:
sudo firewall-cmd --reload
to load the permanent configuration into the runtime environment.
How do I check whether port 8080 is allowed?
sudo firewall-cmd --zone=public --list-ports
You should also check whether an application is listening:
sudo ss -lntp | grep :8080
How do I allow HTTP and HTTPS?
sudo firewall-cmd --permanent --zone=public --add-service=http sudo firewall-cmd --permanent --zone=public --add-service=https sudo firewall-cmd --reload
Can firewall-cmd block a specific IP?
Yes. Rich rules can be used to accept, reject, or drop traffic based on source addresses and other conditions.
Is CentOS 7 still recommended for new servers?
No. CentOS Linux 7 reached EOL on June 30, 2024. New deployments should use a currently supported operating system.
Related Articles
Talk to our experts
Have a technology challenge or looking for the right solution for your business? Our team can help you with cloud, DevOps, development, infrastructure, design, and more. Feel free to reach out to our experts here.