CompTIA Linux+ (XK0-006)TroubleshootingMedium

A web application listens on TCP port 8443 and `ss -tlnp` confirms it is in the LISTEN state on the server. However, external clients cannot connect and receive connection timeouts. Which command permanently allows inbound traffic on this port through firewalld?

  1. Aiptables -A INPUT -p tcp --dport 8443 -j ACCEPT
  2. Bsetenforce 0
  3. Cfirewall-cmd --add-port=8443/tcp --permanent && firewall-cmd --reload
  4. Dsystemctl restart firewalld
Show answer & explanation

Correct answer: C. firewall-cmd --add-port=8443/tcp --permanent && firewall-cmd --reload

Adding the port with --permanent writes the rule to firewalld's persistent configuration, and --reload applies it immediately without dropping existing connections. Since the service is already listening correctly, the block must be at the firewall layer, and firewalld is the standard tool on distributions where it manages the underlying nftables/iptables rules.

Why the other options are wrong

  • A. Directly manipulating iptables can conflict with firewalld and won't survive a reload or reboot.
  • B. Disabling SELinux enforcement addresses a different class of problem and is not a firewall fix.
  • D. Restarting firewalld reloads existing rules but does not add the missing port rule.

firewalld Port Management

firewalld manages firewall rules using zones and services; --add-port opens a specific port, and --permanent plus --reload makes the change persistent and active.

  • firewall-cmd --add-port=<port>/<proto> --permanent
  • firewall-cmd --reload applies persistent changes
  • firewall-cmd --list-all shows current zone configuration

Memory trick: Listening isn't enough — the firewall gatekeeper must also say yes.

More Troubleshooting questions