
How to reload firewalld without loosing Libvirt iptables forwarding rules

cn flag

It's been well know that firewalld will flush Libvirt rules upon reload and thus making port forwarding to VMs broken until you restart libvirtd. Here is what I did:

  1. Create /etc/systemd/system/firewalld-reload-hook.service
Description=firewalld reload hook - run a hook script on firewalld reload

ExecStart=/bin/bash -c '/bin/busctl monitor --system --json=short --match "interface=org.fedoraproject.FirewallD1,member=Reloaded" | while read -r line ; do [ -x /sbin/firewalld-reload-hook ] && /sbin/firewalld-reload-hook ; done'

  1. Create /sbin/firewalld-reload-hook

# Invoked by /etc/systemd/system/firewalld-reload-hook.service
set -e

logger "$BASH_SOURCE: Firewalld reload hook triggered."

/usr/bin/systemctl restart libvirtd

logger "$BASH_SOURCE: Libvirt restarted."

exit 0

and make it executable chmod +x /sbin/firewalld-reload-hook

  1. Install libvirt-hook-qemu
git clone
make install
  1. Edit /etc/libvirt/hooks/hooks.json to match your needs. This just an example
    "www": {
        "private_ip": "",
        "port_map": {
            "tcp": [80, 443]
    "mail": {
        "private_ip": "",
        "port_map": {
            "tcp": [25, 465]
  1. Enable and start firewalld-reload-hook.service
systemctl enable firewalld-reload-hook.service
systemctl start firewalld-reload-hook.service
  1. firewall-cmd --reload

At this point systemctl restart libvirtd and firewall-cmd --reload produce the same results and survive reboots (tested on Debian bullseye with nftables and libvirt 7.0/NAT network)

So, is this the best way of doing it?

Refer libvirt-hook-qemu, firewalld-reload-hook.service, firewalld.dbus


Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.