# firewall-cmd --zone=public --add-port=61009/tcp --permanent success # firewall-cmd --reload success # iptables-save | grep 61009 -A IN_public_allow -p tcp -m tcp --dport 61009 -m conntrack --ctstate NEW -j ACCEPT