drop firewalld log + config · detect direct rule abuse · runs locally
direct.xml passthrough · zone xml · rich rules · reload events · permanent vs /run/firewalld runtime
heuristic screener · incomplete firewalld dumps list missing zones as informational · not definitive proof