Affected versions: CentOS Stream 9

📖 ~1 min read

Table of contents
  1. Symptom & Impact
  2. Environment & Reproduction
  3. Root Cause Analysis
  4. Quick Triage
  5. Step-by-Step Diagnosis
  6. Solution – Primary Fix
  7. Solution – Alternative Approaches
  8. Verification & Acceptance Criteria
  9. Rollback Plan
  10. Prevention & Hardening
  11. Related Errors & Cross-Refs
  12. References & Further Reading

Symptom & Impact

New interface lands in wrong zone

Environment & Reproduction

DefaultZone=public but interface profile assigned to internal.

Root Cause Analysis

NetworkManager and firewalld disagree on zone assignment.

Quick Triage

firewall-cmd –get-zone-of-interface= versus NM connection.zone.

Step-by-Step Diagnosis

Run: nmcli con show | grep zone; firewall-cmd –get-zone-of-interface=.

Illustrative mockup for centos-stream-9 — cp243_diag
Mismatched zone assignment between NM and firewalld — Illustrative mockup — Progressive Robot

Solution – Primary Fix

nmcli con modify connection.zone ; nmcli con up .

Still having issues? Our IT Consulting team can diagnose and resolve this for you. Get in touch for a free consultation.

Illustrative mockup for centos-stream-9 — cp243_fix
Interface anchored to correct firewalld zone — Illustrative mockup — Progressive Robot

Solution – Alternative Approaches

Lock DefaultZone in /etc/firewalld/firewalld.conf and bind interfaces via NM.

Verification & Acceptance Criteria

firewall-cmd reports the expected zone after reactivation.

Rollback Plan

Set NM connection.zone back to original and reload firewalld.

Prevention & Hardening

Codify zone mapping in NM profile templates.

Pairs with services unexpectedly blocked or exposed.

Related tutorial: View the step-by-step tutorial for centos-stream-9.

View all centos-stream-9 tutorials on the Tutorials Hub →

Browse all common problems & solutions on the Tutorials Hub.

References & Further Reading

firewalld zones documentation.

Need Expert Help?

If you cannot resolve this yourself, our team offers hands-on Server Management, Managed IT Services, and flexible Support Plans. Contact us today — we respond within one business day.