sudo apt update
sudo apt install firewalld
#enable & start firewall
sudo systemctl enable firewalld
sudo systemctl start firewalld

#open service by port
sudo firewall-cmd --permanent --zone=public --add-port=3306/tcp 
#open service by service name
sudo firewall-cmd --permanent --zone=public --add-service=http 
sudo firewall-cmd --permanent --zone=public --add-service=https
#reload firewall
sudo firewall-cmd --reload