Switch on firewalld lockdown with a half-checked whitelist and your own admin commands get refused, at the worst possible moment. This guide gets you a checked lockdown-whitelist.xml that permits only the clients you choose. It is written for firewalld 2.1.1, and a small whitelist takes about 10 minutes, plus time to test from the account that will use it.
firewalld.conf ships with Lockdown=no, so a whitelist does nothing until you enable lockdown.You need root privileges and a working firewalld installation. Check the version and state first:
firewall-cmd --version
sudo firewall-cmd --state
On this installation the first command reports 2.1.1. If the second does not report running, stop: do not use reload or lockdown commands yet. A stopped service cannot apply the file.
The installed 2.1.1 manpage names the permanent file /etc/firewalld/lockdown-whitelist.xml. Singular. Do not create the plural lockdown-whitelists.xml that some newer online documentation shows, unless the manpage on your machine says otherwise.
sudo install -D -m 0644 /dev/null /tmp/lockdown-whitelist.xml
sudo cp -a /etc/firewalld/lockdown-whitelist.xml /tmp/lockdown-whitelist.xml.backup 2>/dev/null || true
sudo test -f /etc/firewalld/lockdown-whitelist.xml && \
sudo sed -n '1,160p' /etc/firewalld/lockdown-whitelist.xml || \
echo 'No existing whitelist file'
The backup is only a convenience for this session. If the file exists and you want a durable rollback, make a separate dated copy before editing.
Checkpoint: you either see the current whitelist or the line No existing whitelist file, and a backup exists if there was a file to copy.
There are three useful entry types:
Then pick with these rules:
unconfined context can open access more broadly than the intended application.Find the real executable path and, if you use SELinux, the context of the running process. Run these as the target user where PATH differences matter:
command -v firewall-cmd
ps -e --context | grep '[f]irewall-cmd'
The command path can differ for root and other users, because firewalld evaluates the path supplied through the environment. Do not copy a path from another host without checking it here.
The root element appears once. Each child is an empty element with exactly the attribute described by the manpage. This example allows one exact command line and one named automation account.
<?xml version="1.0" encoding="utf-8"?>
<whitelist>
<command name="/usr/bin/firewall-cmd --reload"/>
<user name="firewall-automation"/>
</whitelist>
Warning: replace both placeholder values with ones you have verified. Do not leave the example values in production.
Write the file with an elevated editor, or stage it outside /etc and install it after reviewing it:
cat > /tmp/lockdown-whitelist.xml <<'XML'
<?xml version="1.0" encoding="utf-8"?>
<whitelist>
<command name="/usr/bin/firewall-cmd --reload"/>
<user name="firewall-automation"/>
</whitelist>
XML
sudo install -o root -g root -m 0644 /tmp/lockdown-whitelist.xml \
/etc/firewalld/lockdown-whitelist.xml
Tip: for a prefix rule, put the asterisk inside the XML attribute, such as name="/usr/bin/firewall-cmd --zone=public --add-service=*". That is deliberately broad: it matches every command line beginning with that text. An exact rule does not match a different argument order or an omitted argument.
Ask firewalld to check its permanent configuration before reloading. This does not enable lockdown:
sudo firewall-cmd --check-config
sudo firewall-cmd --reload
sudo firewall-cmd --list-lockdown-whitelist-commands
sudo firewall-cmd --list-lockdown-whitelist-users
sudo firewall-cmd --query-lockdown
Checkpoint: the check succeeds, the listings include the entries you chose, and the final query still says no. The context and UID listings are available with --list-lockdown-whitelist-contexts and --list-lockdown-whitelist-uids.
Warning: enabling lockdown is security-sensitive and can disrupt administration immediately. Keep a root shell open and confirm that your actual management command is covered before you run this.
sudo firewall-cmd --lockdown-on
sudo firewall-cmd --query-lockdown
Do not test this first over your only remote session. If your intended client is rejected, disable lockdown from the open root shell:
sudo firewall-cmd --lockdown-off
If the file fails validation or reload, restore the copy you made before editing and check again:
sudo install -o root -g root -m 0644 /tmp/lockdown-whitelist.xml.backup \
/etc/firewalld/lockdown-whitelist.xml
sudo firewall-cmd --check-config
sudo firewall-cmd --reload
Recovery: the restore command overwrites the current whitelist file. If the backup does not exist, edit the file back to its last known good contents instead. --lockdown-off is the immediate recovery for an administrative lockout, but it does not undo edits to the XML.
/etc/firewalld/lockdown-whitelist.xml and has one <whitelist> root.sudo firewall-cmd --check-config succeeds after the change.