Configuring Firewall with Firewalld on CentOS 7

Firewalld Service Management

CentOS 7 utilizes systemctl as the primary service management tool, combining functionality from previous service and chkconfig commands.

# Check firewall status using legacy service command
service firewalld status

# Check firewall status using systemctl
systemctl status firewalld

Firewalld Service Control Commands

# Start the firewall service
systemctl start firewalld

# Stop the firewall service
systemctl stop firewalld

# Restart the firewall service
systemctl restart firewalld

# Check service status
systemctl status firewalld

# Enable automatic startup
systemctl enable firewalld

# Disable automatic startup
systemctl disable firewalld

# Verify startup configuration
systemctl is-enabled firewalld

# List enabled services
systemctl list-unit-files | grep enabled

# Check for failed services
systemctl --failed

Firewall Confiugration Commands

# Display firewall version
firewall-cmd --version

# Show command help
firewall-cmd --help

# Check firewall state
firewall-cmd --state

# Reload firewall rules
firewall-cmd --reload

# Open a TCP port permanently
firewall-cmd --zone=public --permanent --add-port=PORT/tcp

# Remove a TCP port
firewall-cmd --zone=public --permanent --remove-port=PORT/tcp

# Check port status
firewall-cmd --zone=public --query-port=PORT/tcp

# List all open ports
firewall-cmd --zone=public --list-ports

# Display current rules
firewall-cmd --list-all

# Get default zone
firewall-cmd --get-default-zone

# Set default zone
firewall-cmd --set-default-zone=ZONE_NAME

# Show active zones
firewall-cmd --get-active-zones

# List available zones
firewall-cmd --get-zones

# Check interface zone assignment
firewall-cmd --get-zone-of-interface=INTERFACE_NAME

# Enable panic mode (block all traffic)
firewall-cmd --panic-on

# Disable panic mode
firewall-cmd --panic-off

# Check panic mode status
firewall-cmd --query-panic

Firewall Zones Overview

  • block: Blocks all incoming connections
  • dmz: Demilitarized zone for limited access
  • drop: Drops all packets without response
  • external: For external networks with masquerading
  • home: Home network enviroment
  • internal: Internal network trust zone
  • public: Public untrusted networks
  • trusted: All traffic accepted
  • work: Workplace network environment

Practical Configuration Examples

# Open MySQL port
firewall-cmd --zone=public --permanent --add-port=3306/tcp

# Apply configuration changes
firewall-cmd --reload

# Remove MySQL port access
firewall-cmd --zone=public --permanent --remove-port=3306/tcp

Common Service Ports

# HTTP: 80
# HTTPS: 443
# MySQL: 3306
# MongoDB: 27017
# PostgreSQL: 5432
# Elasticsearch: 9200
# Redis: 6379
# RabbitMQ: 15672, 5672
# Consul: 8500
# Nacos: 8848
# FTP: 21
# SSH: 22
# Telnet: 23
# SMTP: 25

Tags: CentOS7 firewalld firewall-configuration linux-security network-ports

Posted on Sat, 03 Oct 2026 16:57:42 +0000 by richei