Firewalld basics
Kort antwoord
Firewalld is the default firewall on current RHEL-family distributions (RHEL, CentOS Stream, Rocky Linux, AlmaLinux), and can also be installed on other distributions. It manages rules through zones rather than a flat rule list. Use firewall-cmd with --permanent to make changes survive a reboot.
Basic commands
Start and enable the service
sudo systemctl start firewalld
sudo systemctl enable firewalldCheck status
sudo firewall-cmd --state
sudo systemctl status firewalldList all zones
Firewalld uses pre-defined zones, each with its own set of rules. The public zone is the default, and SSH is allowed on it out of the box.
sudo firewall-cmd --list-all-zonesView the active zone's configuration
sudo firewall-cmd --zone=public --list-allAllowing services
Service definitions live at /usr/lib/firewalld/services (pre-configured) and /etc/firewalld/services (custom). Always add --permanent so the rule survives a reboot, then reload.
List available services
sudo firewall-cmd --get-servicesAdd a service
sudo firewall-cmd --zone=public --add-service=http --permanent
sudo firewall-cmd --zone=public --add-service=mysql --permanent
sudo firewall-cmd --reloadRemove a service
sudo firewall-cmd --zone=public --remove-service=mysql --permanent
sudo firewall-cmd --reloadSecuring your connection
Confirm SSH is allowed
SSH is allowed by default on the public zone. If it's been removed, add it back:
sudo firewall-cmd --zone=public --add-service=ssh --permanent
sudo firewall-cmd --reloadRestrict SSH to a known IP address
Adding your address as a source to the public zone does not restrict anything, because the public zone already accepts traffic from every other address through the interface. To limit SSH to one address, remove the ssh service from the public zone and allow it with a rich rule instead.
sudo firewall-cmd --permanent --zone=public --remove-service=ssh
sudo firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address=YOUR.IP.ADDRESS/32 service name=ssh accept'
sudo firewall-cmd --reloadKeep your current SSH session open while you test this. Open a second session from the allowed address and confirm it connects before you close the first one. If you lock yourself out, you need console access to the server to undo the change.