Updated: 28 September 2026 · Applies to: firewalld on AlmaLinux and Rocky Linux 9 and 10 and RHEL 9 and 10; UFW on Ubuntu 24.04 and 26.04 and Debian 13; CSF
To make a service reachable from outside, two things must be true: the service listens on the port, and the firewall allows it. This guide opens a port with firewalld, the firewall of AlmaLinux, Rocky Linux and RHEL, and gives the matching commands for UFW and CSF. The older CentOS 7 method of editing iptables rules directly is replaced by these tools; CentOS 7 reached end of life in June 2024.
1. Check that the service listens
ss -ltnp 'sport = :8080'
If nothing is listed, start the service first. If it shows 127.0.0.1:8080, it only accepts local connections; change its listen address in its configuration.
2. Open the port with firewalld
- See the active zone and what it allows:
firewall-cmd --get-active-zones firewall-cmd --list-all
- Open the port permanently and load the change:
firewall-cmd --permanent --add-port=8080/tcp firewall-cmd --reload
For a known service, use its name instead of a number, for example--add-service=https. List the names withfirewall-cmd --get-services. - Check:
firewall-cmd --list-ports
To allow the port only from one address, use a rich rule instead of step 2:
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.7/32" port port="8080" protocol="tcp" accept' firewall-cmd --reload
Close a port again with --remove-port=8080/tcp and a reload.
3. SELinux (AlmaLinux, Rocky Linux, RHEL)
If the service itself refuses to start on a non-standard port, SELinux may not allow that port for it. For a web server on port 8081:
semanage port -a -t http_port_t -p tcp 8081
See which ports a type already has with semanage port -l | grep http_port_t.
UFW (Ubuntu, Debian)
ufw allow 8080/tcp ufw allow from 198.51.100.7 to any port 8080 proto tcp # one address only ufw status numbered
CSF (common on cPanel servers)
Add the port to the comma-separated TCP_IN list in /etc/csf/csf.conf (and TCP6_IN for IPv6), then run csf -r. For one address only, add a line such as tcp|in|d=8080|s=198.51.100.7 to /etc/csf/csf.allow instead.
4. Test from outside
nc -zv 203.0.113.10 8080
Run this from another machine. If it still fails, see troubleshooting connection refused.
Official documentation: firewalld: open a port or service.
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
