{{tag>[linux firewalld zones service]}}
=====FirewallD=====
====Create new zone====
* Create new zone and add sources and services:
firewall-cmd --permanent --new-zone=monitoring
firewall-cmd --permanent --zone monitoring --add-source=
firewall-cmd --permanent --zone monitoring --add-service=
firewall-cmd --reload
====Create new service====
* Get zones:firewall-cmd --get-zones
* Set default zone:firewall-cmd --set-default-zone=internal
* Verify:firewall-cmd --get-zone-of-interface=eth0
* Stop firewalld:systemctl stop firewalld.service
* Create service file:**vi /etc/firewalld/services/splunk.xml**
splunk
* Start firewalld:systemctl start firewalld.service
* Add service to zone:firewall-cmd --permanent --zone=internal --add-service=splunk
* Restart firewalld:systemctl restart firewalld