Mon Dec 22 09:10:04 UTC 2014

FWIW we already have a mechanism to restricts which ports specific
applications are allowed to open without using firewalld at all. Its
called "SELinux" (only works for confined domains but server
applications should run in one anyway).

