StudyToCert

All certifications / Linux+ / Lessons

CompTIA Linux+ XK0-006 · Domain 3: Security

Firewalls: firewalld zones and --permanent, ufw, nftables/iptables basics

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

A host firewall filters network traffic entering and leaving a Linux system, so only the services you intend are reachable. In the kernel, packet filtering is done by netfilter; the tools you use are front ends that write netfilter rules. Linux+ covers firewalld (RHEL-family), ufw (Ubuntu) and the lower-level nftables and iptables. A host firewall complements, rather than replaces, network firewalls, and it is part of the defense-in-depth approach the exam expects. firewalld organizes rules into zones, each representing a trust level: drop, block, public, external, internal, dmz, work, home and trusted. Each network interface or source address is assigned to one zone, and the zone's allowed services and ports apply to its traffic. public is a common default. Key commands use firewall-cmd: --get-default-zone, --get-active-zones, --list-all (shows the current zone's services, ports and interfaces), --add-service=https, --add-port=8080/tcp, --remove-service, --zone=internal --change-interface=eth1, and rich rules for finer control such as allowing a service only from one subnet. Services are predefined names that map to ports, like ssh for 22/tcp; firewall-cmd --get-services lists them.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Linux+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Linux+ study plan