17.5 Summary
A carefully planned and implemented firewall is a vital component of any secure system. In the case of Ubuntu, the firewalld service provides a firewall system that is both flexible and easy to administer.
The firewalld service uses the concept of zones to group together sets of firewall rules and includes a suite of pre-defined zones designed to meet a range of firewall protection requirements. These zones may be modified to add or remove rules, or entirely new zones created and configured. The network devices on the system that connect to networks or the internet are referred to as interfaces. Each interface, in turn, is assigned to a zone. The primary tools for working with firewalld are the firewall-cmd command-line tool and the firewall-config graphical utility.