What is a firewall and a port?
A firewall is like a security guard at the door of your server. It checks who may come in and who may not.
A port is like a numbered door. Web traffic uses two doors. Port 80 is for HTTP, the normal web. Port 443 is for HTTPS, the secure web with the padlock.
On AlmaLinux and Rocky Linux 8, the firewall tool is called firewalld. If these two doors are shut, nobody can open your site.
Steps
- Log in to your server over SSH as the root user. SSH is a safe way to type commands on a remote computer.
- Check that the firewall is running:
This shows if firewalld is active. If it is stopped, start it withsystemctl status firewalldsystemctl start firewalld. - See which services are already allowed:
This prints the current rules for the default zone. A zone is a group of rules.firewall-cmd --list-all - Open the HTTP service:
This allows port 80. The wordfirewall-cmd --permanent --add-service=http--permanentkeeps the rule after a reboot. - Open the HTTPS service:
This allows port 443.firewall-cmd --permanent --add-service=https - Reload the firewall so the new rules start working:
firewall-cmd --reload - Check the result:
You should seefirewall-cmd --list-serviceshttpandhttpsin the list.
Opening ports by number
You can also open the ports by number instead of by service name.
firewall-cmd --permanent --add-port=80/tcp
firewall-cmd --permanent --add-port=443/tcp
firewall-cmd --reload
These commands do the same job. TCP is the kind of connection web pages use.
Tip: Be careful not to close the SSH port by mistake. If you lose it, you may be locked out of your own server. Never remove the
ssh service unless you know another way in.Tip: If the site still does not load, make sure your web server, such as Apache or Nginx, is running. A single open port does not help if nothing is listening behind it.
Quick recap
- Port 80 is HTTP and port 443 is HTTPS.
- Use
firewall-cmd --permanent --add-service=httpand the same forhttps. - Run
firewall-cmd --reloadto apply the change. - Check with
firewall-cmd --list-services. - Keep SSH open so you can still log in.