2025-11-15 00:08:53
next #firewalld oddity; you can't use 'firewall-cmd' when firewalld is stopped (like configuring a rootfs not yet booted), but it has got 'firewall-offline-cmd' that lets you do it - except the options are sometimes different; e.g.
firewall-cmd --zone=external --remove-service ssh --permanent
becomes
firewall-offline-cmd --zone=external --remove-service-fro…