FIREWALL-CMD(1) (NAME) firewall-cmd - firewalld (SYNOPSIS) firewall-cmd [...] (DESCRIPTION) firewall-cmd firewalld . (runtime) (permanent) . firewalld . . (OPTIONS) (Sequence options) . ALREADY_ENABLED (11) NOT_ENABLED (12) ZONE_ALREADY_SET (16) . . . . UNKNOWN_ERROR (254) . : (General Options) -h, --help . -V, --version firewalld. . -q, --quiet ( ). (Status Options) --state firewalld ( ) . RUNNING_BUT_FAILED NOT_RUNNING . " (EXIT CODES)" . STDOUT . --reload (state). . : FlushAllOnReload=no (direct interface) firewalld (restart) . FlushAllOnReload firewalld.conf(5) . --complete-reload netfilter. (state) . . . : FlushAllOnReload=no (direct interface) firewalld (restart) . FlushAllOnReload firewalld.conf(5) . --runtime-to-permanent . firewalld . --check-config . XML . --reset-to-defaults firewalld. (Log Denied Options) --get-log-denied (log) . --set-log-denied=value reject drop INPUT FORWARD OUTPUT reject drop . : all unicast broadcast multicast off. off . (reload) . (Permanent Options) --permanent --permanent . . --permanent . --permanent . --permanent . (Zone Options) --get-default-zone . --set-default-zone=zone . . . --get-active-zones . . : zone1 interfaces: interface1 interface2 .. sources: source1 .. zone2 interfaces: interface3 .. zone3 sources: source2 .. . [--permanent] --get-zones . [--permanent] --get-services . [--permanent] --get-icmptypes icmptype . [--permanent] --get-zone-of-interface=interface interface no zone. [--permanent] --get-zone-of-source=source[/mask]|MAC|ipset:ipset no zone. [--permanent] --info-zone=zone zone. : zone interfaces: interface1 .. sources: source1 .. services: service1 .. ports: port1 .. protocols: protocol1 .. forward-ports: forward-port1 .. source-ports: source-port1 .. icmp-blocks: icmp-type1 .. rich rules: rich-rule1 .. [--permanent] --list-all-zones . : zone1 interfaces: interface1 .. sources: source1 .. services: service1 .. ports: port1 .. protocols: protocol1 .. forward-ports: forward-port1 .. icmp-blocks: icmp-type1 .. rich rules: rich-rule1 .. .. --permanent --new-zone=zone . - : '_' '-' . --permanent --new-zone-from-file=filename [--name=zone] . --permanent --delete-zone=zone . --permanent --load-zone-defaults=zone NO_DEFAULTS. --permanent --path-zone=zone . (Policy Options) [--permanent] --get-policies . [--permanent] --info-policy=policy policy. [--permanent] --list-all-policies . --permanent --new-policy=policy . - : '_' '-' . --permanent --new-policy-from-file=filename [--name=policy] . --permanent --path-policy=policy . --permanent --delete-policy=policy . --permanent --load-policy-defaults=policy . firewalld . (Options to Adapt and Query Zones and Policies) . --zone=zone --policy=policy . ( --get-default-zone ). [--permanent] [--zone=zone] [--policy=policy] --list-all . --permanent [--zone=zone] [--policy=policy] --get-target (target). --permanent [--zone=zone] [--policy=policy] --set-target=target (target). target : default ACCEPT DROP REJECT target : CONTINUE ACCEPT DROP REJECT default REJECT ICMP . ACCEPT . --permanent [--zone=zone] [--policy=policy] --set-description=description . --permanent [--zone=zone] [--policy=policy] --get-description . --permanent [--zone=zone] [--policy=policy] --set-short=description . --permanent [--zone=zone] [--policy=policy] --get-short . [--permanent] [--zone=zone] [--policy=policy] --list-services . [--permanent] [--zone=zone] [--policy=policy] --add-service=service [--timeout=timeval] . . (timeout) . timeval ( ) s () m () h () 20m 1h. firewalld . : firewall-cmd --get-services. --timeout --permanent . : (connection tracking helpers) . ( tftp) (outbound) . . (/ingress) . : # firewall-cmd --permanent --new-policy clientConntrack # firewall-cmd --permanent --policy clientConntrack --add-ingress-zone HOST # firewall-cmd --permanent --policy clientConntrack --add-egress-zone ANY # firewall-cmd --permanent --policy clientConntrack --add-service tftp [--permanent] [--zone=zone] [--policy=policy] --remove-service=service . . [--permanent] [--zone=zone] [--policy=policy] --query-service=service service . 0 1 . [--permanent] [--zone=zone] [--policy=policy] --list-ports . portid[-portid]/protocol . [--permanent] [--zone=zone] [--policy=policy] --add-port=portid[-portid]/protocol [--timeout=timeval] . . (timeout) . timeval ( ) s () m () h () 20m 1h. portid-portid . tcp udp sctp dccp . --timeout --permanent . [--permanent] [--zone=zone] [--policy=policy] --remove-port=portid[-portid]/protocol . . [--permanent] [--zone=zone] [--policy=policy] --query-port=portid[-portid]/protocol . 0 1 . [--permanent] [--zone=zone] [--policy=policy] --list-protocols . [--permanent] [--zone=zone] [--policy=policy] --add-protocol=protocol [--timeout=timeval] . . (timeout) . timeval ( ) s () m () h () 20m 1h. . /etc/protocols . --timeout --permanent . [--permanent] [--zone=zone] [--policy=policy] --remove-protocol=protocol . . [--permanent] [--zone=zone] [--policy=policy] --query-protocol=protocol . 0 1 . [--permanent] [--zone=zone] [--policy=policy] --list-source-ports . portid[-portid]/protocol . [--permanent] [--zone=zone] [--policy=policy] --add-source-port=portid[-portid]/protocol [--timeout=timeval] . . (timeout) . timeval ( ) s () m () h () 20m 1h. portid-portid . tcp udp sctp dccp . --timeout --permanent . [--permanent] [--zone=zone] [--policy=policy] --remove-source-port=portid[-portid]/protocol . . [--permanent] [--zone=zone] [--policy=policy] --query-source-port=portid[-portid]/protocol . 0 1 . [--permanent] [--zone=zone] [--policy=policy] --list-icmp-blocks (ICMP) . [--permanent] [--zone=zone] [--policy=policy] --add-icmp-block=icmptype [--timeout=timeval] ICMP icmptype. . (timeout) . timeval ( ) s () m () h () 20m 1h. icmptype ICMP firewalld . ICMP : firewall-cmd --get-icmptypes --timeout --permanent . [--permanent] [--zone=zone] [--policy=policy] --remove-icmp-block=icmptype ICMP icmptype. . [--permanent] [--zone=zone] [--policy=policy] --query-icmp-block=icmptype ICMP icmptype . 0 1 . [--permanent] [--zone=zone] [--policy=policy] --list-forward-ports IPv4 . IPv6 (rich language) . [--permanent] [--zone=zone] [--policy=policy] --add-forward-port=port=portid[-portid]:proto=protocol[:toport=portid[-portid]][:toaddr=address[/mask]] [--timeout=timeval] IPv4. . (timeout) . timeval ( ) s () m () h () 20m 1h. portid portid-portid . tcp udp sctp dccp . IP . --timeout --permanent . IPv6 (rich language) . : toaddr IP . [--permanent] [--zone=zone] [--policy=policy] --remove-forward-port=port=portid[-portid]:proto=protocol[:toport=portid[-portid]][:toaddr=address[/mask]] IPv4. . IPv6 (rich language) . [--permanent] [--zone=zone] [--policy=policy] --query-forward-port=port=portid[-portid]:proto=protocol[:toport=portid[-portid]][:toaddr=address[/mask]] IPv4 . 0 1 . IPv6 (rich language) . [--permanent] [--zone=zone] [--policy=policy] --add-masquerade [--timeout=timeval] ( ) IPv4. . timeval ( ) s () m () h () 20m 1h. . --timeout --permanent . IPv6 (rich language) . : IP . ( .): iptables . nftables 5.5+ . [--permanent] [--zone=zone] [--policy=policy] --remove-masquerade IPv4. . IPv6 (rich language) . [--permanent] [--zone=zone] [--policy=policy] --query-masquerade IPv4 . 0 1 . IPv6 (rich language) . [--permanent] [--zone=zone] [--policy=policy] --list-rich-rules . [--permanent] [--zone=zone] [--policy=policy] --add-rich-rule='rule' [--timeout=timeval] 'rule'. . (timeout) rule . timeval ( ) s () m () h () 20m 1h. firewalld.richlanguage(5) . --timeout --permanent . [--permanent] [--zone=zone] [--policy=policy] --remove-rich-rule='rule' 'rule'. . firewalld.richlanguage(5) . [--permanent] [--zone=zone] [--policy=policy] --query-rich-rule='rule' 'rule' . 0 1 . firewalld.richlanguage(5) . (Options to Adapt and Query Zones) . --zone=zone . ( --get-default-zone ). [--permanent] [--zone=zone] --add-icmp-block-inversion ICMP. [--permanent] [--zone=zone] --remove-icmp-block-inversion ICMP. [--permanent] [--zone=zone] --query-icmp-block-inversion ICMP . 0 1 . [--permanent] [--zone=zone] --add-forward (intra zone forwarding). [--permanent] [--zone=zone] --remove-forward . [--permanent] [--zone=zone] --query-forward . 0 1 . --permanent [--zone=zone] --get-priority . --permanent [--zone=zone] --set-priority . (ingress) (egress) . --permanent [--zone=zone] --get-ingress-priority (ingress) . --permanent [--zone=zone] --set-ingress-priority (ingress) . --permanent [--zone=zone] --get-egress-priority (egress) . --permanent [--zone=zone] --set-egress-priority (egress) . (Options to Adapt and Query Policies) . --policy=policy . --permanent --policy=policy --get-priority . --permanent --policy=policy --set-priority=priority . . -32768 32767 -1 0 . (< 0) . (> 0) . [--permanent] --policy=policy --list-ingress-zones . [--permanent] --policy=policy --add-ingress-zone=zone . . firewalld : HOST ANY. HOST ( firewalld ) . ANY . (wild card) . - HOST . [--permanent] --policy=policy --remove-ingress-zone=zone . . [--permanent] --policy=policy --query-ingress-zone=zone zone . 0 1 . [--permanent] --policy=policy --list-egress-zones . [--permanent] --policy=policy --add-egress-zone=zone . . firewalld : HOST ANY. HOST ANY --add-ingress-zone . [--permanent] --policy=policy --remove-egress-zone=zone . . [--permanent] --policy=policy --query-egress-zone=zone zone . 0 1 . [--permanent] --policy=policy|--policy-set=policy-set --add-disable . . [--permanent] --policy=policy|--policy-set=policy-set --remove-disable . [--permanent] --policy=policy --query-disable . (Options to Handle Bindings of Interfaces) . . --zone=zone zone . ( --get-default-zone ). : firewall-cmd --get-zones. ' ' '/' '!' '*' . [--permanent] [--zone=zone] --list-interfaces zone . . [--permanent] [--zone=zone] --add-interface=interface interface zone. . NetworkManager . firewalld . NetworkManager firewalld ZONE ifcfg . NetworkManager ( ) NM_CONTROLLED=no ( ZONE= ifcfg-interface) . /etc/sysconfig/network-scripts/ifcfg-interface . --add-interface . firewalld(1) Concepts . 'How to set or change a zone for a connection?' firewalld.zones(5) . [--permanent] [--zone=zone] --change-interface=interface NetworkManager . firewalld . NetworkManager firewalld ifcfg ZONE . interface zone. --remove-interface --add-interface . --add-interface . . [--permanent] [--zone=zone] --query-interface=interface interface zone . 0 1 . [--permanent] --remove-interface=interface NetworkManager . firewalld . NetworkManager : ifcfg firewalld ZONE . NetworkManager : firewalld ZONE ifcfg . (ifdown) . firewalld . interface . (Options to Handle Bindings of Sources) . IP IP IPv4 IPv6 MAC ipset ipset: . IPv4 . IPv6 . . . --zone=zone zone . ( --get-default-zone ). : firewall-cmd [--permanent] --get-zones. [--permanent] [--zone=zone] --list-sources zone . . [--permanent] [--zone=zone] --add-source=source[/mask]|MAC|ipset:ipset zone. . [--zone=zone] --change-source=source[/mask]|MAC|ipset:ipset zone. --remove-source --add-source . --add-source . . [--permanent] [--zone=zone] --query-source=source[/mask]|MAC|ipset:ipset zone . 0 1 . [--permanent] --remove-source=source[/mask]|MAC|ipset:ipset . IPSet (IPSet Options) --get-ipset-types ipset. --permanent --new-ipset=ipset --type=type [--family=inet|inet6] [--option=key[=value]] ipset (type) (family) timeout hashsize maxelem. ipset(8) . ipset - : '_' '-' . --permanent --new-ipset-from-file=filename [--name=ipset] ipset ipset . --permanent --delete-ipset=ipset ipset . --permanent --load-ipset-defaults=ipset ipset NO_DEFAULTS. [--permanent] --info-ipset=ipset ipset ipset. : ipset type: type options: option1[=value1] .. entries: entry1 .. [--permanent] --get-ipsets ipset . --permanent --ipset=ipset --set-description=description ipset. --permanent --ipset=ipset --get-description ipset. --permanent --ipset=ipset --set-short=description ipset. --permanent --ipset=ipset --get-short ipset. [--permanent] --ipset=ipset --add-entry=entry ipset. ipset timeout firewalld . [--permanent] --ipset=ipset --remove-entry=entry ipset. [--permanent] --ipset=ipset --query-entry=entry ipset . 0 1 . ipset (timeout) . ipset . [--permanent] --ipset=ipset --get-entries ipset. [--permanent] --ipset=ipset --add-entries-from-file=filename ipset . ipset . . (#) (;) . [--permanent] --ipset=ipset --remove-entries-from-file=filename ipset . ipset . . (#) (;) . --permanent --path-ipset=ipset ipset. (Service Options) . [--permanent] --info-service=service service. : service ports: port1 .. protocols: protocol1 .. source-ports: source-port1 .. helpers: helper1 .. destination: ipv1:address1 .. . --permanent --new-service=service . - : '_' '-' . --permanent --new-service-from-file=filename [--name=service] . --permanent --delete-service=service . --permanent --load-service-defaults=service NO_DEFAULTS. --permanent --path-service=service . --permanent --service=service --set-description=description . --permanent --service=service --get-description . --permanent --service=service --set-short=description . --permanent --service=service --get-short . --permanent --service=service --add-port=portid[-portid]/protocol . --permanent --service=service --remove-port=portid[-portid]/protocol . --permanent --service=service --query-port=portid[-portid]/protocol . --permanent --service=service --get-ports . --permanent --service=service --add-protocol=protocol . --permanent --service=service --remove-protocol=protocol . --permanent --service=service --query-protocol=protocol . --permanent --service=service --get-protocols . --permanent --service=service --add-source-port=portid[-portid]/protocol . --permanent --service=service --remove-source-port=portid[-portid]/protocol . --permanent --service=service --query-source-port=portid[-portid]/protocol . --permanent --service=service --get-source-ports . --permanent --service=service --add-helper=helper (helper) . --permanent --service=service --remove-helper=helper . --permanent --service=service --query-helper=helper . --permanent --service=service --get-service-helpers . --permanent --service=service --set-destination=ipv:address[/mask] ipv address[/mask] . --permanent --service=service --remove-destination=ipv ipv . --permanent --service=service --query-destination=ipv:address[/mask] ipv address[/mask] . --permanent --service=service --get-destinations . --permanent --service=service --add-include=service (include) . --permanent --service=service --remove-include=service . --permanent --service=service --query-include=service . --permanent --service=service --get-includes . (Helper Options) (helper) . [--permanent] --info-helper=helper helper. : helper family: family module: module ports: port1 .. . --permanent --new-helper=helper --module=nf_conntrack_module [--family=ipv4|ipv6] . - : '-' . --permanent --new-helper-from-file=filename [--name=helper] . --permanent --delete-helper=helper . --permanent --load-helper-defaults=helper NO_DEFAULTS. --permanent --path-helper=helper . [--permanent] --get-helpers . --permanent --helper=helper --set-description=description . --permanent --helper=helper --get-description . --permanent --helper=helper --set-short=description . --permanent --helper=helper --get-short . --permanent --helper=helper --add-port=portid[-portid]/protocol . --permanent --helper=helper --remove-port=portid[-portid]/protocol . --permanent --helper=helper --query-port=portid[-portid]/protocol . --permanent --helper=helper --get-ports . --permanent --helper=helper --set-module=description . --permanent --helper=helper --get-module . --permanent --helper=helper --set-family=description . --permanent --helper=helper --get-family . (ICMP) (Internet Control Message Protocol (ICMP) type Options) icmptype . [--permanent] --info-icmptype=icmptype icmptype. : icmptype destination: ipv1 .. . --permanent --new-icmptype=icmptype icmptype . ICMP - : '_' '-' . --permanent --new-icmptype-from-file=filename [--name=icmptype] icmptype . --permanent --delete-icmptype=icmptype icmptype . --permanent --load-icmptype-defaults=icmptype icmptype NO_DEFAULTS. --permanent --icmptype=icmptype --set-description=description icmptype. --permanent --icmptype=icmptype --get-description icmptype. --permanent --icmptype=icmptype --set-short=description icmptype. --permanent --icmptype=icmptype --get-short icmptype. --permanent --icmptype=icmptype --add-destination=ipv ipv icmptype . ipv ipv4 ipv6 . --permanent --icmptype=icmptype --remove-destination=ipv ipv icmptype . ipv ipv4 ipv6 . --permanent --icmptype=icmptype --query-destination=ipv ipv icmptype . ipv ipv4 ipv6 . --permanent --icmptype=icmptype --get-destinations icmptype . --permanent --path-icmptype=icmptype icmptype. (Direct Options) (DEPRECATED) . . firewalld.policies(5) . . iptables table ( filter/mangle/nat/...) chain ( INPUT/OUTPUT/FORWARD/...) commands ( -A/-D/-I/...) parameters ( -p/-s/-d/-j/...) targets ( ACCEPT/DROP/REJECT/...). --add-service=service --add-rich-rule='rule' . : FirewallBackend . CAVEATS firewalld.direct(5) . ipv4 ipv6 eb . ipv4 IPv4 (iptables(8)) ipv6 IPv6 (ip6tables(8)) eb (ebtables(8)) . [--permanent] --direct --get-all-chains . --direct --add-chain . [--permanent] --direct --get-chains { ipv4 | ipv6 | eb } table table . --direct --add-chain . [--permanent] --direct --add-chain { ipv4 | ipv6 | eb } table chain chain table. . INPUT_direct ( iptables-save | grep direct ). INPUT_direct . [--permanent] --direct --remove-chain { ipv4 | ipv6 | eb } table chain chain table. --direct --add-chain . [--permanent] --direct --query-chain { ipv4 | ipv6 | eb } table chain chain table . 0 1 . --direct --add-chain . [--permanent] --direct --get-all-rules . --direct --add-rule . [--permanent] --direct --get-rules { ipv4 | ipv6 | eb } table chain chain table . --direct --add-rule . [--permanent] --direct --add-rule { ipv4 | ipv6 | eb } table chain priority args args chain table priority. priority . . . . [--permanent] --direct --remove-rule { ipv4 | ipv6 | eb } table chain priority args priority args chain table. --direct --add-rule . [--permanent] --direct --remove-rules { ipv4 | ipv6 | eb } table chain chain table. --direct --add-rule . [--permanent] --direct --query-rule { ipv4 | ipv6 | eb } table chain priority args priority args chain table . 0 1 . --direct --add-rule . --direct --passthrough { ipv4 | ipv6 | eb } args . args iptables ip6tables ebtables . firewalld . [--permanent] --direct --get-all-passthroughs (passthrough) ipv . [--permanent] --direct --get-passthroughs { ipv4 | ipv6 | eb } ipv . [--permanent] --direct --add-passthrough { ipv4 | ipv6 | eb } args args ipv. [--permanent] --direct --remove-passthrough { ipv4 | ipv6 | eb } args args ipv. [--permanent] --direct --query-passthrough { ipv4 | ipv6 | eb } args args ipv . 0 1 . (Panic Options) --panic-on (panic mode). (drop) . ( ). . --panic-off . . . --query-panic 0 1 . (EXAMPLES) (Example 1) http . . firewall-cmd --add-service=http (Example 2) 443/tcp . . . . firewall-cmd --add-port=443/tcp firewall-cmd --permanent --add-port=443/tcp (EXIT CODES) 0 . 2 : +--------------------+--------+ | | | +--------------------+--------+ |ALREADY_ENABLED | 11 | +--------------------+--------+ |NOT_ENABLED | 12 | +--------------------+--------+ |COMMAND_FAILED | 13 | +--------------------+--------+ |NO_IPV6_NAT | 14 | +--------------------+--------+ |PANIC_MODE | 15 | +--------------------+--------+ |ZONE_ALREADY_SET | 16 | +--------------------+--------+ |UNKNOWN_INTERFACE | 17 | +--------------------+--------+ |ZONE_CONFLICT | 18 | +--------------------+--------+ |BUILTIN_CHAIN | 19 | +--------------------+--------+ |EBTABLES_NO_REJECT | 20 | +--------------------+--------+ |NOT_OVERLOADABLE | 21 | +--------------------+--------+ |NO_DEFAULTS | 22 | +--------------------+--------+ |BUILTIN_ZONE | 23 | +--------------------+--------+ |BUILTIN_SERVICE | 24 | +--------------------+--------+ |BUILTIN_ICMPTYPE | 25 | +--------------------+--------+ |NAME_CONFLICT | 26 | +--------------------+--------+ |NAME_MISMATCH | 27 | +--------------------+--------+ |PARSE_ERROR | 28 | +--------------------+--------+ |ACCESS_DENIED | 29 | +--------------------+--------+ |UNKNOWN_SOURCE | 30 | +--------------------+--------+ |RT_TO_PERM_FAILED | 31 | +--------------------+--------+ |IPSET_WITH_TIMEOUT | 32 | +--------------------+--------+ |BUILTIN_IPSET | 33 | +--------------------+--------+ |ALREADY_SET | 34 | +--------------------+--------+ |MISSING_IMPORT | 35 | +--------------------+--------+ |DBUS_ERROR | 36 | +--------------------+--------+ |BUILTIN_HELPER | 37 | +--------------------+--------+ |NOT_APPLIED | 38 | +--------------------+--------+ |INVALID_ACTION | 100 | +--------------------+--------+ |INVALID_SERVICE | 101 | +--------------------+--------+ |INVALID_PORT | 102 | +--------------------+--------+ |INVALID_PROTOCOL | 103 | +--------------------+--------+ |INVALID_INTERFACE | 104 | +--------------------+--------+ |INVALID_ADDR | 105 | +--------------------+--------+ |INVALID_FORWARD | 106 | +--------------------+--------+ |INVALID_ICMPTYPE | 107 | +--------------------+--------+ |INVALID_TABLE | 108 | +--------------------+--------+ |INVALID_CHAIN | 109 | +--------------------+--------+ |INVALID_TARGET | 110 | +--------------------+--------+ |INVALID_IPV | 111 | +--------------------+--------+ |INVALID_ZONE | 112 | +--------------------+--------+ |INVALID_PROPERTY | 113 | +--------------------+--------+ |INVALID_VALUE | 114 | +--------------------+--------+ |INVALID_OBJECT | 115 | +--------------------+--------+ |INVALID_NAME | 116 | +--------------------+--------+ |INVALID_FILENAME | 117 | +--------------------+--------+ |INVALID_DIRECTORY | 118 | +--------------------+--------+ |INVALID_TYPE | 119 | +--------------------+--------+ |INVALID_SETTING | 120 | +--------------------+--------+ |INVALID_DESTINATION | 121 | +--------------------+--------+ |INVALID_RULE | 122 | +--------------------+--------+ |INVALID_LIMIT | 123 | +--------------------+--------+ |INVALID_FAMILY | 124 | +--------------------+--------+ |INVALID_LOG_LEVEL | 125 | +--------------------+--------+ |INVALID_AUDIT_TYPE | 126 | +--------------------+--------+ |INVALID_MARK | 127 | +--------------------+--------+ |INVALID_CONTEXT | 128 | +--------------------+--------+ |INVALID_COMMAND | 129 | +--------------------+--------+ |INVALID_USER | 130 | +--------------------+--------+ |INVALID_UID | 131 | +--------------------+--------+ |INVALID_MODULE | 132 | +--------------------+--------+ |INVALID_PASSTHROUGH | 133 | +--------------------+--------+ |INVALID_MAC | 134 | +--------------------+--------+ |INVALID_IPSET | 135 | +--------------------+--------+ |INVALID_ENTRY | 136 | +--------------------+--------+ |INVALID_OPTION | 137 | +--------------------+--------+ |INVALID_HELPER | 138 | +--------------------+--------+ |INVALID_PRIORITY | 139 | +--------------------+--------+ |INVALID_POLICY | 140 | +--------------------+--------+ |INVALID_LOG_PREFIX | 141 | +--------------------+--------+ |INVALID_NFLOG_GROUP | 142 | +--------------------+--------+ |INVALID_NFLOG_QUEUE | 143 | +--------------------+--------+ |INVALID_SOURCE | 144 | +--------------------+--------+ |MISSING_TABLE | 200 | +--------------------+--------+ |MISSING_CHAIN | 201 | +--------------------+--------+ |MISSING_PORT | 202 | +--------------------+--------+ |MISSING_PROTOCOL | 203 | +--------------------+--------+ |MISSING_ADDR | 204 | +--------------------+--------+ |MISSING_NAME | 205 | +--------------------+--------+ |MISSING_SETTING | 206 | +--------------------+--------+ |MISSING_FAMILY | 207 | +--------------------+--------+ |RUNNING_BUT_FAILED | 251 | +--------------------+--------+ |NOT_RUNNING | 252 | +--------------------+--------+ |NOT_AUTHORIZED | 253 | +--------------------+--------+ |UNKNOWN_ERROR | 254 | +--------------------+--------+ --query-* : 0 1 . (SEE ALSO) firewall-applet(1), firewalld(1), firewall-cmd(1), firewall-config(1), firewalld.conf(5), firewalld.direct(5), firewalld.dbus(5), firewalld.icmptype(5), firewall-offline-cmd(1), firewalld.richlanguage(5), firewalld.service(5), firewalld.zone(5), firewalld.zones(5), firewalld.policy(5), firewalld.policies(5), firewalld.ipset(5), firewalld.helper(5) (NOTES) firewalld: http://firewalld.org (AUTHORS) Thomas Woerner Jiri Popelka Eric Garver firewalld 2.5.1 FIREWALL-CMD(1)