{{tag>[linux firewalld zones service]}} =====FirewallD===== ====Create new zone==== * Create new zone and add sources and services: firewall-cmd --permanent --new-zone=monitoring firewall-cmd --permanent --zone monitoring --add-source= firewall-cmd --permanent --zone monitoring --add-service= firewall-cmd --reload ====Create new service==== * Get zones:firewall-cmd --get-zones * Set default zone:firewall-cmd --set-default-zone=internal * Verify:firewall-cmd --get-zone-of-interface=eth0 * Stop firewalld:systemctl stop firewalld.service * Create service file:**vi /etc/firewalld/services/splunk.xml** splunk * Start firewalld:systemctl start firewalld.service * Add service to zone:firewall-cmd --permanent --zone=internal --add-service=splunk * Restart firewalld:systemctl restart firewalld