Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Open Web Ports 80 and 443 with Firewalld on AlmaLinux or Rocky Linux 8

This guide shows you how to let visitors reach your website by opening the HTTP and HTTPS ports in the firewall. It needs root access, so it is for VPS and dedicated server owners.

VPS and Cloud Servers2 min read7 steps

What is a firewall and a port?

A firewall is like a security guard at the door of your server. It checks who may come in and who may not.

A port is like a numbered door. Web traffic uses two doors. Port 80 is for HTTP, the normal web. Port 443 is for HTTPS, the secure web with the padlock.

On AlmaLinux and Rocky Linux 8, the firewall tool is called firewalld. If these two doors are shut, nobody can open your site.

Steps

  1. Log in to your server over SSH as the root user. SSH is a safe way to type commands on a remote computer.
  2. Check that the firewall is running:
    systemctl status firewalld
    This shows if firewalld is active. If it is stopped, start it with systemctl start firewalld.
  3. See which services are already allowed:
    firewall-cmd --list-all
    This prints the current rules for the default zone. A zone is a group of rules.
  4. Open the HTTP service:
    firewall-cmd --permanent --add-service=http
    This allows port 80. The word --permanent keeps the rule after a reboot.
  5. Open the HTTPS service:
    firewall-cmd --permanent --add-service=https
    This allows port 443.
  6. Reload the firewall so the new rules start working:
    firewall-cmd --reload
  7. Check the result:
    firewall-cmd --list-services
    You should see http and https in the list.

Opening ports by number

You can also open the ports by number instead of by service name.

firewall-cmd --permanent --add-port=80/tcp
firewall-cmd --permanent --add-port=443/tcp
firewall-cmd --reload

These commands do the same job. TCP is the kind of connection web pages use.

Tip: Be careful not to close the SSH port by mistake. If you lose it, you may be locked out of your own server. Never remove the ssh service unless you know another way in.
Tip: If the site still does not load, make sure your web server, such as Apache or Nginx, is running. A single open port does not help if nothing is listening behind it.

Quick recap

  • Port 80 is HTTP and port 443 is HTTPS.
  • Use firewall-cmd --permanent --add-service=http and the same for https.
  • Run firewall-cmd --reload to apply the change.
  • Check with firewall-cmd --list-services.
  • Keep SSH open so you can still log in.