Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. Firewalld basics

Firewalld basics

Applies to Dedicated servers, Flexible VPS (RHEL family)Audience Server administratorsLast reviewed September 2026

Quick answer

Firewalld is the default firewall on current RHEL-family distributions (RHEL, CentOS Stream, Rocky Linux, AlmaLinux), and can also be installed on other distributions. It manages rules through zones rather than a flat rule list. Use firewall-cmd with --permanent to make changes survive a reboot.

Basic commands

1

Start and enable the service

sudo systemctl start firewalld
sudo systemctl enable firewalld
2

Check status

sudo firewall-cmd --state
sudo systemctl status firewalld
3

List all zones

Firewalld uses pre-defined zones, each with its own set of rules. The public zone is the default, and SSH is allowed on it out of the box.

sudo firewall-cmd --list-all-zones
4

View the active zone's configuration

sudo firewall-cmd --zone=public --list-all

Allowing services

Service definitions live at /usr/lib/firewalld/services (pre-configured) and /etc/firewalld/services (custom). Always add --permanent so the rule survives a reboot, then reload.

1

List available services

sudo firewall-cmd --get-services
2

Add a service

sudo firewall-cmd --zone=public --add-service=http --permanent
sudo firewall-cmd --zone=public --add-service=mysql --permanent
sudo firewall-cmd --reload
3

Remove a service

sudo firewall-cmd --zone=public --remove-service=mysql --permanent
sudo firewall-cmd --reload

Securing your connection

1

Confirm SSH is allowed

SSH is allowed by default on the public zone. If it's been removed, add it back:

sudo firewall-cmd --zone=public --add-service=ssh --permanent
sudo firewall-cmd --reload
2

Restrict SSH to a known IP address

Adding your address as a source to the public zone does not restrict anything, because the public zone already accepts traffic from every other address through the interface. To limit SSH to one address, remove the ssh service from the public zone and allow it with a rich rule instead.

sudo firewall-cmd --permanent --zone=public --remove-service=ssh
sudo firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address=YOUR.IP.ADDRESS/32 service name=ssh accept'
sudo firewall-cmd --reload

Keep your current SSH session open while you test this. Open a second session from the allowed address and confirm it connects before you close the first one. If you lock yourself out, you need console access to the server to undo the change.

Related articles

  • UFW firewall basics
  • Iptables basics
  • How to improve your SSH security
  • How to change the SSH port
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure