Firewalld turns host firewall policy into manageable zones, services, ports, and rich rules. This hands-on course teaches you to inspect and change those layers while planning for the operational risk of locking yourself out of a remote system.
You will distinguish runtime from permanent configuration, classify a test interface by zone, express source-specific policy, configure and remove a port-forward rule, and test panic mode with an automatic recovery script. The final challenge stages a restrictive web-server policy in the drop zone without activating that zone on your live connection.
What You Will Learn
- Install, start, enable, and inspect Firewalld and its active zones
- Move a virtual network interface between zones without risking the primary connection
- Add named services and raw ports in runtime and permanent configurations
- Reload Firewalld and explain what happens to runtime-only changes
- Create rich rules that accept, reject, and log traffic by source address or subnet
- Enable masquerading and configure, inspect, and remove a TCP port-forward rule
- Test panic mode with a background recovery script and verify network restoration
- Audit a staged
drop-zone policy for HTTP, HTTPS, restricted SSH, and a logged reject rule
Who This Course Is For
This intermediate course is for Linux administrators, DevOps practitioners, and security learners who can already operate a server from the command line and want practical Firewalld configuration experience.
Prerequisites: Comfort with Linux shell commands, sudo, basic service management, IP addresses, subnets, TCP ports, and common services such as HTTP and SSH.
Learning environment: A remote Linux terminal with administrator access, Firewalld, a virtual test interface, and a local web service. The primary interface remains in the permissive trusted zone to protect lab access, so some allow rules are configuration exercises rather than end-to-end filtering tests.
Frequently Asked Questions
Will these labs change the firewall on my own computer or network?
No. You work inside the isolated lab machine. Changes target its Firewalld configuration and test interfaces, not your local workstation or router.
Do I test every rule with real traffic?
No. You verify most rules through Firewalld state and configuration output. The active trusted zone makes some allow rules behaviorally redundant, and local port-forward testing may be limited by NAT loopback; panic mode is tested through connectivity logs and automatic recovery.
Does the final challenge put the server into the drop zone?
No. It stages and audits permanent rules for the drop zone but deliberately does not assign the live interface or make that zone the default, avoiding loss of the remote session.





