You are not logged in.
Hello, I'm trying to open a port, but I can't get it to work.
I've tried to run these commands:
$ sudo firewall-cmd --zone=public --add-port 50000/tcp
Warning: ALREADY_ENABLED: '50000:tcp' already in 'public'
success
$ sudo firewall-cmd --add-port 50000/tcp
Warning: ALREADY_ENABLED: '50000:tcp' already in 'public'
success
$ sudo firewall-cmd --reload
success
$ sudo firewall-cmd --list-ports
$ sudo firewall-cmd --zone=public --remove-port 50000/tcp
Warning: NOT_ENABLED: '50000:tcp' not in 'public'
successI have no idea on where to start to get it to run, any help please? thank you
edit: I don't know what information might be of use for you to see, I will add them to the post as needed
Last edited by Koda (2026-09-18 15:09:43)
Offline
Hi! Can't help too much with firewalld zones, but firewalld usually keeps your runtime-changes only until you reload firewalld. That way bogus changes would not automatically be applied on your next reboot/reload.
So
sudo firewall-cmd --reloadis resetting your changes to the last saved state from your config.
You can open the ports with your "--add-port" command and directly check if that did work. If they do, you can use
firewall-cmd --runtime-to-permanentto make them survive your next call of:
firewall-cmd --reloadThe documentation of firewalld lives here if you want to dig deeper into the concepts: https://firewalld.org/documentation/how … rvice.html
Offline
That seems to fix my problem with firewalld. However, when trying to see if they are open (via port checker website) it tells me that the port is closed (I opened it for both TCP and UDP). Do you know why?
Offline
How is the machine connected to the internet?
Are we talking about a VPS that is directly reachable or is this a machine on a local network that sits behind a router and is not directly reachable from the internet?
If it is a VPS: you could try disabling your firewall temporarily and check if the port is reachable then.
If it is in a local network: you might need to open and forward the port at additional hops in your network.
Offline
aside from the port scanner failing (are you behind a (cg-)nat router? is there actually some service listening to that port to accept incomming connections?) another way to configure your firewall is the other way around
first, add the new rule to the config only
firewall-cmd --permanent --zone=public --add-port 50000/tcpnote: this does not yet enable that new rule
and then second, reload to apply the config
firewall-cmd --reloadnote: this only applies rules already in the config and reverts everything only added to runtime without --permanent and not yet saved to the config via --runtime-to-permanent
it's a "take your poison" approach: either edit the config and then load it - or edit the runtime and then save that to the config
Offline
How is the machine connected to the internet?
Are we talking about a VPS that is directly reachable or is this a machine on a local network that sits behind a router and is not directly reachable from the internet?If it is a VPS: you could try disabling your firewall temporarily and check if the port is reachable then.
If it is in a local network: you might need to open and forward the port at additional hops in your network.
It's in a local network, but I'm not the network's admin
Offline
then the external port scanner fails at the routers nat firewall - which would need to be opened as well
Offline