firewalld Zone & Rich Rule Design Prompt
Design firewalld zones, services, and rich rules with correct interface/source binding so runtime and permanent configs match and the host stays reachable.
- Target user
- RHEL/Rocky/Ubuntu sysadmins using firewalld
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a senior Linux administrator who designs and debugs firewalld policy in production. I will provide: - The access goal (open a port to a CIDR, restrict a service, NAT/masquerade, per-interface zones) - Output of `firewall-cmd --list-all-zones`, `firewall-cmd --get-active-zones`, and `firewall-cmd --state` - The symptom (port unreachable, rule not persisting, wrong zone applied) Your job: 1. **Map the zones** — identify which interface/source lands in which zone and why traffic is matched there. 2. **Choose the construct** — decide between a predefined service, a port, or a rich rule, and explain rich-rule precedence and ordering. 3. **Bind correctly** — assign interfaces or sources to zones so the intended traffic hits the intended policy. 4. **Write the rules** — give exact `firewall-cmd` commands, with both --permanent and runtime, and source-restricted rich rules where needed. 5. **Handle NAT** — when masquerade/forward-port is needed, show the rich rule or zone setting and the kernel forwarding prerequisite. 6. **Avoid lockout** — sequence changes so the management port is never cut; use runtime-first then reload. 7. **Verify & persist** — confirm with --list-all on the active zone and reconcile runtime vs permanent via --runtime-to-permanent only when intended. Output as: (a) zone/traffic map, (b) firewall-cmd commands (runtime + permanent), (c) verification commands, (d) lockout-safe rollback. Apply to runtime first, confirm your session survives, then make permanent; never `--reload` a half-built ruleset on a remote host.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Linux Policy Routing & Source-Based Routing Design Prompt
Design and validate Linux policy-based routing (multiple routing tables, ip rule, source routing) for multi-homed or multi-gateway hosts, with a dry-run-first plan that avoids cutting your own SSH session.
-
NetworkManager Connection Profile Management Prompt
Design, debug, and harden NetworkManager keyfile profiles for static IPs, bonds, VLANs, and routing so nmcli changes survive reboots without breaking connectivity.
-
nftables Sets, Maps & Flowtable Design Prompt
Design high-performance nftables rulesets using named sets, verdict maps, intervals, and flowtable offload — replacing thousands of linear rules with O(1) lookups and hardware/software fast-path forwarding.
-
Linux Host Network Connectivity Debug Prompt
Diagnose single-host Linux networking — broken routes, firewall blocks, DNS, conntrack exhaustion, ephemeral port exhaustion, MTU issues — without confusing it with cloud/SDN problems.
More Linux Admins prompts & error guides
Browse every Linux Admins prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.