Q: You need to open port 8080 on a CentOS/RHEL server running `firewalld` instead of `iptables`. How do you add the rule permanently?
firewalld is the default firewall manager on modern RHEL/CentOS/Fedora systems, replacing direct iptables manipulation. It uses the conce...
#Linux #Linux / SRE — Scenario-Based Interview Questions #L1 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""Never reboot a server blindly; always capture top process telemetry, lsof descriptors, and thread dumps first. The interviewer is testing: Modern firewall management with firewalld, zones.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
firewalld is the default firewall manager on modern RHEL/CentOS/Fedora systems, replacing direct iptables manipulation. It uses the concept of zones (groups of rules applied to network interfaces).
- Add the port to the default zone:
- Reload the firewall to apply:
- Verify:
2️⃣
Remediation & Permanent Safeguards
To open port 8080 permanently: If you need to restrict the port to a specific source IP range: The --permanent flag is critical—without it, the rule is temporary and lost on reboot or reload.
firewall-cmd --permanent --add-port=8080/tcp
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Add the port to the default zone:."
⚡ 60-Second Elevator Pitch Talking Points
- Add the port to the default zone:
- Reload the firewall to apply:
- Verify:
Advertisement