Where Does firewalld Store Zones and Rules on Linux?
firewalld keeps system zones in /usr/lib and custom zones in /etc/firewalld on Linux.
Last updated
firewalld splits shipped zones from yours. Package zones live in /usr/lib/firewalld and get overwritten on updates. Custom zones, services, and direct rules belong in /etc/firewalld, which survives upgrades.
Edit through firewall-cmd so runtime and permanent states agree. Back up /etc/firewalld before distro jumps. Reload rather than restart to keep connections alive during changes.
Where firewalld stores this, by platform
/etc/firewalld
Custom zones, services, and firewalld.conf. Root owned. Never edit /usr/lib copies; copy them here first to override.
Frequently asked questions
How do I back up firewalld rules?
Copy /etc/firewalld whole, which holds custom zones and services. Restore to the same path and reload. Runtime only changes vanish on reload.
Where are firewalld logs?
Denied packets log through the kernel log when logging is enabled per zone. Check journalctl for the firewalld unit too.
Notice an outdated path? Let us know.