...Also if you do experiment with firewalld, think really carefully about your Zones. It's really easy to have to start over because you can't duplicate subnet entries; this can be trickier than it sounds. Sure you can write rich rules but then you might as well stick with iptables.