Updated: 28 September 2026 · Applies to: firewalld 1.3 (AlmaLinux, Rocky Linux, RHEL 9) and 2.4 (version 10)

firewall-cmd manages firewalld, the firewall of AlmaLinux, Rocky Linux and RHEL. The examples below cover the tasks you need most often. We checked every rule's syntax with firewalld 1.3.4 on AlmaLinux 9 (and 2.4.3 on AlmaLinux 10 has the same commands).

Runtime and permanent

Every change is either runtime (active now, lost at reload or reboot) or permanent (saved, active after --reload). The safe pattern is to add --permanent and then reload. Alternatively, test a rule at runtime and, if it works, save everything with firewall-cmd --runtime-to-permanent.

1. See what is allowed

firewall-cmd --state
firewall-cmd --get-active-zones
firewall-cmd --list-all

New servers use the public zone, which allows ssh, cockpit and dhcpv6-client by default.

2. Allow a service or a port

firewall-cmd --permanent --add-service=http --add-service=https
firewall-cmd --permanent --add-port=8080/tcp
firewall-cmd --permanent --remove-service=cockpit     # close what you do not use
firewall-cmd --reload

List the service names firewalld knows with firewall-cmd --get-services.

3. Allow a port for one address only (rich rule)

firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.7/32" port port="3306" protocol="tcp" accept'
firewall-cmd --reload

This is how to open a database or admin port to your office IP only. List rich rules with firewall-cmd --list-rich-rules.

4. Block an address or a network

firewall-cmd --permanent --zone=drop --add-source=203.0.113.66
firewall-cmd --reload

Traffic from sources in the drop zone is silently discarded. For long block lists, use an ipset:

firewall-cmd --permanent --new-ipset=blocklist --type=hash:net
firewall-cmd --permanent --ipset=blocklist --add-entry=198.51.100.0/24
firewall-cmd --permanent --zone=drop --add-source=ipset:blocklist
firewall-cmd --reload

5. Forward a port

firewall-cmd --permanent --add-forward-port=port=80:proto=tcp:toport=8080
firewall-cmd --reload

Requests to port 80 go to port 8080 on the same server. To forward to another machine, add :toaddr=10.0.0.5 and enable masquerading with --add-masquerade.

6. Temporary rules and emergencies

firewall-cmd --add-port=9000/tcp --timeout=30m    # removed automatically after 30 minutes
firewall-cmd --panic-on                            # drop ALL traffic, including your SSH session
firewall-cmd --panic-off

Use panic mode only from a console (IPMI or KVM), never over SSH.

Common problems

  • A rule works until reboot: it was added without --permanent. Run firewall-cmd --runtime-to-permanent.
  • A permanent rule has no effect: run firewall-cmd --reload.
  • The rule is in another zone than the interface: check --get-active-zones and add --zone= to your command.

See also how to open a port on RHEL, AlmaLinux and Rocky Linux.

Official documentation: firewalld documentation.

Ucartz services for this topic

Was this answer helpful? 0 Users Found This Useful (0 Votes)