Firewalld Service Management
CentOS 7 utilizes systemctl as the primary service management tool, combining functionality from previous service and chkconfig commands.
# Check firewall status using legacy service command
service firewalld status
# Check firewall status using systemctl
systemctl status firewalld
Firewalld Service Control Commands
# Start the firewall service
systemctl start firewalld
# Stop the firewall service
systemctl stop firewalld
# Restart the firewall service
systemctl restart firewalld
# Check service status
systemctl status firewalld
# Enable automatic startup
systemctl enable firewalld
# Disable automatic startup
systemctl disable firewalld
# Verify startup configuration
systemctl is-enabled firewalld
# List enabled services
systemctl list-unit-files | grep enabled
# Check for failed services
systemctl --failed
Firewall Confiugration Commands
# Display firewall version
firewall-cmd --version
# Show command help
firewall-cmd --help
# Check firewall state
firewall-cmd --state
# Reload firewall rules
firewall-cmd --reload
# Open a TCP port permanently
firewall-cmd --zone=public --permanent --add-port=PORT/tcp
# Remove a TCP port
firewall-cmd --zone=public --permanent --remove-port=PORT/tcp
# Check port status
firewall-cmd --zone=public --query-port=PORT/tcp
# List all open ports
firewall-cmd --zone=public --list-ports
# Display current rules
firewall-cmd --list-all
# Get default zone
firewall-cmd --get-default-zone
# Set default zone
firewall-cmd --set-default-zone=ZONE_NAME
# Show active zones
firewall-cmd --get-active-zones
# List available zones
firewall-cmd --get-zones
# Check interface zone assignment
firewall-cmd --get-zone-of-interface=INTERFACE_NAME
# Enable panic mode (block all traffic)
firewall-cmd --panic-on
# Disable panic mode
firewall-cmd --panic-off
# Check panic mode status
firewall-cmd --query-panic
Firewall Zones Overview
- block: Blocks all incoming connections
- dmz: Demilitarized zone for limited access
- drop: Drops all packets without response
- external: For external networks with masquerading
- home: Home network enviroment
- internal: Internal network trust zone
- public: Public untrusted networks
- trusted: All traffic accepted
- work: Workplace network environment
Practical Configuration Examples
# Open MySQL port
firewall-cmd --zone=public --permanent --add-port=3306/tcp
# Apply configuration changes
firewall-cmd --reload
# Remove MySQL port access
firewall-cmd --zone=public --permanent --remove-port=3306/tcp
Common Service Ports
# HTTP: 80
# HTTPS: 443
# MySQL: 3306
# MongoDB: 27017
# PostgreSQL: 5432
# Elasticsearch: 9200
# Redis: 6379
# RabbitMQ: 15672, 5672
# Consul: 8500
# Nacos: 8848
# FTP: 21
# SSH: 22
# Telnet: 23
# SMTP: 25