Updated: 28 September 2026 · Applies to: firewalld 1.3 (AlmaLinux, Rocky Linux, RHEL 9) and 2.4 (version 10)
firewall-cmd manages firewalld, the firewall of AlmaLinux, Rocky Linux and RHEL. The examples below cover the tasks you need most often. We checked every rule's syntax with firewalld 1.3.4 on AlmaLinux 9 (and 2.4.3 on AlmaLinux 10 has the same commands).
Runtime and permanent
Every change is either runtime (active now, lost at reload or reboot) or permanent (saved, active after --reload). The safe pattern is to add --permanent and then reload. Alternatively, test a rule at runtime and, if it works, save everything with firewall-cmd --runtime-to-permanent.
1. See what is allowed
firewall-cmd --state firewall-cmd --get-active-zones firewall-cmd --list-all
New servers use the public zone, which allows ssh, cockpit and dhcpv6-client by default.
2. Allow a service or a port
firewall-cmd --permanent --add-service=http --add-service=https firewall-cmd --permanent --add-port=8080/tcp firewall-cmd --permanent --remove-service=cockpit # close what you do not use firewall-cmd --reload
List the service names firewalld knows with firewall-cmd --get-services.
3. Allow a port for one address only (rich rule)
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.7/32" port port="3306" protocol="tcp" accept' firewall-cmd --reload
This is how to open a database or admin port to your office IP only. List rich rules with firewall-cmd --list-rich-rules.
4. Block an address or a network
firewall-cmd --permanent --zone=drop --add-source=203.0.113.66 firewall-cmd --reload
Traffic from sources in the drop zone is silently discarded. For long block lists, use an ipset:
firewall-cmd --permanent --new-ipset=blocklist --type=hash:net firewall-cmd --permanent --ipset=blocklist --add-entry=198.51.100.0/24 firewall-cmd --permanent --zone=drop --add-source=ipset:blocklist firewall-cmd --reload
5. Forward a port
firewall-cmd --permanent --add-forward-port=port=80:proto=tcp:toport=8080 firewall-cmd --reload
Requests to port 80 go to port 8080 on the same server. To forward to another machine, add :toaddr=10.0.0.5 and enable masquerading with --add-masquerade.
6. Temporary rules and emergencies
firewall-cmd --add-port=9000/tcp --timeout=30m # removed automatically after 30 minutes firewall-cmd --panic-on # drop ALL traffic, including your SSH session firewall-cmd --panic-off
Use panic mode only from a console (IPMI or KVM), never over SSH.
Common problems
- A rule works until reboot: it was added without
--permanent. Runfirewall-cmd --runtime-to-permanent. - A permanent rule has no effect: run
firewall-cmd --reload. - The rule is in another zone than the interface: check
--get-active-zonesand add--zone=to your command.
See also how to open a port on RHEL, AlmaLinux and Rocky Linux.
Official documentation: firewalld documentation.
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
