Updated: 28 September 2026 · Applies to: firewalld on AlmaLinux and Rocky Linux 9 and 10 and RHEL 9 and 10; UFW on Ubuntu 24.04 and 26.04 and Debian 13; CSF

To make a service reachable from outside, two things must be true: the service listens on the port, and the firewall allows it. This guide opens a port with firewalld, the firewall of AlmaLinux, Rocky Linux and RHEL, and gives the matching commands for UFW and CSF. The older CentOS 7 method of editing iptables rules directly is replaced by these tools; CentOS 7 reached end of life in June 2024.

1. Check that the service listens

ss -ltnp 'sport = :8080'

If nothing is listed, start the service first. If it shows 127.0.0.1:8080, it only accepts local connections; change its listen address in its configuration.

2. Open the port with firewalld

  1. See the active zone and what it allows:
    firewall-cmd --get-active-zones
    firewall-cmd --list-all
  2. Open the port permanently and load the change:
    firewall-cmd --permanent --add-port=8080/tcp
    firewall-cmd --reload
    For a known service, use its name instead of a number, for example --add-service=https. List the names with firewall-cmd --get-services.
  3. Check: firewall-cmd --list-ports

To allow the port only from one address, use a rich rule instead of step 2:

firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.7/32" port port="8080" protocol="tcp" accept'
firewall-cmd --reload

Close a port again with --remove-port=8080/tcp and a reload.

3. SELinux (AlmaLinux, Rocky Linux, RHEL)

If the service itself refuses to start on a non-standard port, SELinux may not allow that port for it. For a web server on port 8081:

semanage port -a -t http_port_t -p tcp 8081

See which ports a type already has with semanage port -l | grep http_port_t.

UFW (Ubuntu, Debian)

ufw allow 8080/tcp
ufw allow from 198.51.100.7 to any port 8080 proto tcp   # one address only
ufw status numbered

CSF (common on cPanel servers)

Add the port to the comma-separated TCP_IN list in /etc/csf/csf.conf (and TCP6_IN for IPv6), then run csf -r. For one address only, add a line such as tcp|in|d=8080|s=198.51.100.7 to /etc/csf/csf.allow instead.

4. Test from outside

nc -zv 203.0.113.10 8080

Run this from another machine. If it still fails, see troubleshooting connection refused.

Official documentation: firewalld: open a port or service.

Ucartz services for this topic

Was this answer helpful? 1 Users Found This Useful (2 Votes)