Things to Know About firewall-cmd: Linux Firewall Configuration Guide

Post Date: October 22, 2018
Last Updated: September 29, 2026

Introduction

firewall-cmd is the command-line client used to manage firewalld, a dynamic firewall management service commonly available on Linux systems.

It provides a convenient way to configure:

  • Firewall zones
  • Services
  • TCP/UDP ports
  • Network interfaces
  • Source IP addresses
  • Rich rules
  • Masquerading
  • Port forwarding
  • Runtime and permanent firewall configurations

One of the most important concepts when working with firewalld is the difference between runtime and permanent configuration.

The runtime configuration is currently active. Changes made without --permanent can be lost when firewalld is reloaded or restarted. Permanent configuration is stored and becomes active after a reload, restart, or system boot.


Prerequisites

You should have:

  • A Linux server with firewalld installed
  • root or sudo access
  • Basic Linux command-line knowledge
  • Knowledge of the ports and services that your application actually requires

The commands below are applicable to modern firewalld-based Linux systems. Package installation commands may differ depending on the distribution.


Implemenation

1. Install firewalld

On systems using DNF:

sudo dnf install firewalld

Start and enable the service:

sudo systemctl enable --now firewalld

Check the service:

sudo systemctl status firewalld

Check whether firewalld is running:

sudo firewall-cmd --state

Expected output:

running

You can also check the installed version:

sudo firewall-cmd --version

firewall-cmd is the primary command-line utility for querying and modifying firewalld configuration.


2. Understand Runtime and Permanent Configuration

This is one of the most important concepts in firewalld.

Runtime Configuration

Runtime configuration represents the rules currently active on the system.

For example:

sudo firewall-cmd --zone=public --add-service=http

This immediately allows HTTP traffic in the public zone.

However, the change is not automatically saved to the permanent configuration.

A firewalld reload can therefore remove a runtime-only change.

Permanent Configuration

To save a rule permanently:

sudo firewall-cmd --permanent --zone=public --add-service=http

The permanent configuration must then be loaded into the runtime configuration:

sudo firewall-cmd --reload

Alternatively, you can apply a change both immediately and permanently with two commands:

sudo firewall-cmd --zone=public --add-service=http
sudo firewall-cmd --permanent --zone=public --add-service=http

The official firewalld documentation recommends understanding this distinction before making production changes.

For production systems, a useful approach is:

  1. Make the change in runtime.
  2. Test connectivity.
  3. If everything works correctly, save it permanently.

You can save the complete working runtime configuration with:

sudo firewall-cmd --runtime-to-permanent

This overwrites the existing permanent configuration with the current runtime configuration.


3. List Available Firewall Zones

Firewalld uses zones to apply different firewall policies based on the trust level of a network connection.

List the available zones:

sudo firewall-cmd --get-zones

Typical zones include:

block
dmz
drop
external
home
internal
public
trusted
work

The exact list can vary by firewalld installation.

Check the default zone:

sudo firewall-cmd --get-default-zone

Check currently active zones:

sudo firewall-cmd --get-active-zones

You can also inspect the complete configuration of a zone:

sudo firewall-cmd --zone=public --list-all

Example:

public
  interfaces: eth0
  services: ssh http https
  ports:
  protocols:
  forward:
  masquerade: no
  rich rules:

Firewalld zones provide a logical way to associate interfaces or source addresses with different firewall policies.


4. Change the Default Zone

To change the default zone:

sudo firewall-cmd --set-default-zone=work

Verify:

sudo firewall-cmd --get-default-zone

Be careful when changing the default zone on a remote production server. A zone change can alter which firewall rules apply to an interface and may affect remote access.


5. Add a Service to a Zone

Firewalld provides predefined services such as:

  • SSH
  • HTTP
  • HTTPS
  • DNS
  • SMTP
  • FTP

List available services:

sudo firewall-cmd --get-services

For example, to allow HTTP in the public zone:

sudo firewall-cmd --zone=public --add-service=http

To make it permanent:

sudo firewall-cmd --permanent --zone=public --add-service=http
sudo firewall-cmd --reload

Allow HTTPS:

sudo firewall-cmd --permanent --zone=public --add-service=https
sudo firewall-cmd --reload

Verify:

sudo firewall-cmd --zone=public --list-services

Using a predefined service is generally preferable when the required service already exists because you do not need to manually specify its standard ports.


6. Remove a Service

To remove a service from the runtime configuration:

sudo firewall-cmd --zone=public --remove-service=http

To remove it permanently:

sudo firewall-cmd --permanent --zone=public --remove-service=http
sudo firewall-cmd --reload

Verify:

sudo firewall-cmd --zone=public --list-services

7. Open a Specific Port

If a predefined service is not appropriate, you can open a specific port.

For example, to allow TCP port 8080:

sudo firewall-cmd --zone=public --add-port=8080/tcp

To make it permanent:

sudo firewall-cmd --permanent --zone=public --add-port=8080/tcp
sudo firewall-cmd --reload

Verify:

sudo firewall-cmd --zone=public --list-ports

For UDP:

sudo firewall-cmd --permanent --zone=public --add-port=51820/udp
sudo firewall-cmd --reload

You can also specify a port range:

sudo firewall-cmd --permanent --zone=public --add-port=5000-5010/tcp

The official firewalld documentation supports both individual ports and port ranges.


8. Remove an Open Port

To remove port 8080/tcp:

sudo firewall-cmd --permanent --zone=public --remove-port=8080/tcp
sudo firewall-cmd --reload

Verify:

sudo firewall-cmd --zone=public --list-ports

9. Create a Custom Zone

You can create a custom zone when the predefined zones do not match your network requirements.

Create a zone named application:

sudo firewall-cmd --permanent --new-zone=application

Reload firewalld:

sudo firewall-cmd --reload

Verify:

sudo firewall-cmd --get-zones

You can then add services or ports to the new zone:

sudo firewall-cmd --permanent --zone=application --add-port=8080/tcp

Reload:

sudo firewall-cmd --reload

Custom zones can be useful when different interfaces, applications, or source networks require different firewall policies.


10. Associate a Network Interface with a Zone

First identify the available network interfaces:

ip addr

Check the zone associated with an interface:

sudo firewall-cmd --get-zone-of-interface=eth0

To associate an interface with a zone:

sudo firewall-cmd --permanent --zone=internal --add-interface=eth0

Reload:

sudo firewall-cmd --reload

Verify:

sudo firewall-cmd --get-active-zones

Firewalld uses interface and source bindings to determine which zone’s rules apply to traffic.

Warning: On a remote server, changing the zone associated with the active network interface can disconnect your SSH session. Confirm that SSH access is permitted in the target zone before applying the change.


11. Associate a Source IP or Network with a Zone

Instead of assigning an entire interface to a zone, you can associate traffic from a specific source network.

For example:

sudo firewall-cmd --permanent --zone=internal --add-source=192.168.10.0/24

Reload:

sudo firewall-cmd --reload

Verify:

sudo firewall-cmd --zone=internal --list-sources

This can be useful when internal applications should receive different access from trusted network ranges.


12. Delete a Custom Zone

Before deleting a custom zone, verify its configuration:

sudo firewall-cmd --permanent --zone=application --list-all

Delete it:

sudo firewall-cmd --permanent --delete-zone=application

Reload:

sudo firewall-cmd --reload

Only delete custom zones after confirming that no required interfaces or source networks depend on them.


13. Rich Rules

For more advanced firewall conditions, firewalld supports rich rules.

Rich rules allow conditions such as:

  • Source IP restrictions
  • Specific services
  • Specific ports
  • Accept, reject, or drop actions
  • Logging
  • Rate limiting
  • More detailed traffic conditions

For example, to reject SSH connections from a specific IP address:

sudo firewall-cmd \
  --permanent \
  --zone=public \
  --add-rich-rule='rule family="ipv4" source address="192.168.1.100" service name="ssh" reject'

Reload:

sudo firewall-cmd --reload

List rich rules:

sudo firewall-cmd --zone=public --list-rich-rules

Remove the rule when required:

sudo firewall-cmd \
  --permanent \
  --zone=public \
  --remove-rich-rule='rule family="ipv4" source address="192.168.1.100" service name="ssh" reject'

Firewalld’s rich language provides a more detailed rule syntax than simply opening or closing a service or port.


14. Example: Allow SSH Only From a Trusted Network

A common security requirement is to restrict SSH access to a known network.

For example:

sudo firewall-cmd \
  --permanent \
  --zone=public \
  --add-rich-rule='rule family="ipv4" source address="192.168.10.0/24" service name="ssh" accept'

However, when implementing restrictive SSH rules, carefully consider the existing zone policy and ensure you have an alternative administrative path before testing the configuration.

For cloud servers, also check the provider’s firewall or security-group rules.


15. Check the Complete Firewall Configuration

To display the configuration of the default zone:

sudo firewall-cmd --list-all

For a specific zone:

sudo firewall-cmd --zone=public --list-all

To list all active zones:

sudo firewall-cmd --list-all-zones

For the permanent configuration:

sudo firewall-cmd --permanent --zone=public --list-all

This distinction is useful when troubleshooting situations where a rule appears to exist but disappears after a reload.


16. Reload firewalld

After making permanent changes:

sudo firewall-cmd --reload

A reload applies the permanent configuration to the runtime environment. Firewalld is designed to preserve existing connections during a normal reload.

Avoid using:

sudo firewall-cmd --complete-reload

unless there is a specific reason to completely reload the firewall.

A complete reload can affect active connections and is intended for more serious firewall problems.


17. Panic Mode

Firewalld provides a panic mode for emergency situations.

Enable panic mode:

sudo firewall-cmd --panic-on

Check the status:

sudo firewall-cmd --query-panic

Disable it:

sudo firewall-cmd --panic-off

Panic mode drops incoming and outgoing packets and should only be used for serious network-security situations. It is a runtime-only setting and cannot be configured with --permanent.

Warning: Enabling panic mode on a remote server can immediately interrupt network connectivity, including SSH access.


18. Check Whether a Port Is Actually Listening

Opening a firewall port does not automatically mean that an application is listening on that port.

For example:

sudo ss -lntp

To check a specific port:

sudo ss -lntp | grep :8080

You should verify both:

  1. The application is listening on the port.
  2. The firewall allows the required traffic.

For example:

sudo firewall-cmd --zone=public --list-ports

19. Test the Firewall From Another System

From another Linux system, you can test connectivity using:

nc -vz SERVER_IP 8080

For HTTP:

curl -I http://SERVER_IP:8080

For HTTPS:

curl -Ik https://SERVER_IP

If the service is not reachable, check:

sudo firewall-cmd --state
sudo firewall-cmd --get-active-zones
sudo firewall-cmd --zone=public --list-all
sudo ss -lntp

Also check any external firewall provided by your hosting or cloud platform.


20. Troubleshooting firewall-cmd

Port is open but connection still fails

Check whether the application is listening:

sudo ss -lntp | grep :8080

Then check firewalld:

sudo firewall-cmd --zone=public --list-ports

Also verify:

  • Cloud security groups
  • Cloud firewalls
  • Network ACLs
  • Load balancers
  • Router/firewall rules
  • Application binding address

Rule disappears after reload

Check runtime configuration:

sudo firewall-cmd --zone=public --list-all

Check permanent configuration:

sudo firewall-cmd --permanent --zone=public --list-all

If the rule exists only in runtime, add it permanently or use:

sudo firewall-cmd --runtime-to-permanent

SSH access was lost after firewall changes

If possible, use:

  • Cloud console
  • Out-of-band management
  • Existing administrative session
  • Recovery console

Then verify:

sudo firewall-cmd --get-active-zones
sudo firewall-cmd --list-services
sudo firewall-cmd --list-ports

Make sure SSH is allowed in the correct zone:

sudo firewall-cmd --zone=public --list-services

21. Security Recommendations

When managing a production Linux firewall:

Allow only required services

Do not open ports simply because an application might use them.

Check the application requirements first.

Prefer services where appropriate

For standard services:

--add-service=http

is often clearer than:

--add-port=80/tcp

Restrict administrative ports

SSH should ideally be restricted by:

  • Trusted source networks
  • VPN access
  • Bastion hosts
  • Other appropriate access controls

Avoid unnecessary public exposure

Databases such as MySQL, PostgreSQL, Redis, and MongoDB generally should not be publicly exposed unless there is a specific architecture requiring it.

Test before making changes permanent

Use runtime configuration first when appropriate, verify connectivity, then persist the working configuration.

Keep cloud-level controls aligned

For cloud-hosted servers, firewalld is only one layer of network security. Also review:

  • Cloud firewall
  • Security groups
  • Network ACLs
  • Load balancer rules
  • Private networking

Keep the operating system supported

Do not use an EOL operating system for new production deployments simply because an old firewall tutorial was written for it.

CentOS Linux 7 reached EOL on June 30, 2024.


22. Useful firewall-cmd Commands

PurposeCommand
Check firewalld statefirewall-cmd --state
Check versionfirewall-cmd --version
List zonesfirewall-cmd --get-zones
Check default zonefirewall-cmd --get-default-zone
List active zonesfirewall-cmd --get-active-zones
List servicesfirewall-cmd --get-services
List zone configurationfirewall-cmd --zone=public --list-all
List open servicesfirewall-cmd --zone=public --list-services
List open portsfirewall-cmd --zone=public --list-ports
Add HTTPfirewall-cmd --zone=public --add-service=http
Add HTTPS permanentlyfirewall-cmd --permanent --zone=public --add-service=https
Open TCP portfirewall-cmd --zone=public --add-port=8080/tcp
Reload configurationfirewall-cmd --reload
Save runtime configurationfirewall-cmd --runtime-to-permanent
Check panic modefirewall-cmd --query-panic

Conclusion

firewall-cmd provides a structured way to manage Linux firewall rules through firewalld.

The most important concepts to understand are:

  • Zones determine which firewall policy applies.
  • Services provide predefined groups of ports and protocols.
  • Ports can be opened directly when required.
  • Runtime configuration applies immediately but is not automatically persistent.
  • Permanent configuration survives reloads and reboots.
  • Rich rules provide more granular traffic controls.
  • Panic mode provides an emergency mechanism that drops network traffic.
  • Firewall configuration should always be considered together with application listening ports and external cloud/network firewalls.

For production systems, avoid blindly opening ports. Identify the required traffic, restrict access to trusted sources where possible, test the configuration, and keep the underlying operating system supported.


Frequently Asked Questions

What is firewall-cmd?

firewall-cmd is the command-line client used to manage firewalld.

What is the difference between firewall-cmd and firewalld?

firewalld is the firewall management service/daemon. firewall-cmd is the command-line interface used to interact with it.

What is the difference between runtime and permanent configuration?

Runtime configuration is currently active. Permanent configuration is stored and loaded when firewalld starts or reloads.

Does --permanent immediately open the port?

No. A permanent change is stored but does not immediately become active. Run:

sudo firewall-cmd --reload

to load the permanent configuration into the runtime environment.

How do I check whether port 8080 is allowed?

sudo firewall-cmd --zone=public --list-ports

You should also check whether an application is listening:

sudo ss -lntp | grep :8080

How do I allow HTTP and HTTPS?

sudo firewall-cmd --permanent --zone=public --add-service=http
sudo firewall-cmd --permanent --zone=public --add-service=https
sudo firewall-cmd --reload

Can firewall-cmd block a specific IP?

Yes. Rich rules can be used to accept, reject, or drop traffic based on source addresses and other conditions.

No. CentOS Linux 7 reached EOL on June 30, 2024. New deployments should use a currently supported operating system.


Related Articles


Talk to our experts

Have a technology challenge or looking for the right solution for your business? Our team can help you with cloud, DevOps, development, infrastructure, design, and more. Feel free to reach out to our experts here.

admin

Our team has expertise across software and web development, WordPress, e-commerce, mobile applications, UI/UX, cloud and infrastructure, DevOps, CI/CD, API integration, security, testing, automation, and technical support. The team also works with AI-based software solutions, LLMs, AI workflows, AI agents, and intelligent application development to help businesses automate processes and build smarter digital solutions. We focus on developing, deploying, maintaining, and optimising secure, scalable, and reliable technology solutions while helping businesses adopt modern technologies and drive digital transformation.

Leave a Reply

Scroll to Top