firewalld
A dynamically managed Linux firewall daemon with network zones and a D-Bus interface.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About firewalld
firewalld is a firewall service for Linux that groups network connections and interfaces into zones, each with its own trust level. It handles IPv4 and IPv6 settings, Ethernet bridges and IP sets, and applies changes immediately without restarting the daemon.
Runtime and permanent configuration are kept separate, so you can test rules in runtime and save them once they work. Applications and users can change settings through the D-Bus interface, which also drives the firewall-cmd command-line tool, the firewall-config GUI and the firewall-applet.
Strengths
- Zones set trust levels per connection or interface
- Changes apply without restarting the service
- Separate runtime and permanent configuration for safe testing
- Command-line, GUI and applet front ends
Limitations
- Linux only
- Zone concepts take some learning compared with plain rule lists
Details
- Pricing
- FreeFree and open source.
- License
- Open source, license not stated
- Developer
- The firewalld contributors
- Platforms
- Linux, Command line
- How it runs
- Downloadable app
- Account
- Not required
- Works offline
- Yes
- Best suited for
- Linux users and administrators managing firewall rules by zone
- Categories
- Network tools, Security tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to firewalld
Compare allSoftware that can replace firewalld for an important use case, and what changes if you switch.
ufw
Uncomplicated Firewall, a command-line tool for managing a netfilter firewall on Linux.
ufw is a GPL-3.0 command-line Linux firewall tool with short allow and deny commands and application profiles, but it lacks zones and is less expressive than firewalld.
OpenSnitch
An interactive application firewall for Linux that asks before letting any program make an outbound connection.
OpenSnitch is a GPL-3.0 Linux application firewall that prompts per program on outbound connections and can configure nftables inbound policy, adding a steady stream of prompts at first.
Similar software
Related functionality, not necessarily a direct replacement.
Fail2ban
Log-watching daemon that bans addresses after repeated authentication failures.
CrowdSec
Detect suspicious behavior in server logs and web traffic.
AppArmor
A Linux kernel security module that confines programs to the actions allowed in per-application profiles.
SELinux
The userland libraries and tools for Security Enhanced Linux, the kernel's mandatory access control system.
OPNsense
An open-source firewall and routing platform based on FreeBSD that you install on your own hardware.
IPFire
A hardened Linux-based firewall distribution with VPN support, network segmentation and a web management console.