[root@server1 ~]# firewall-cmd --direct --permanent --add-chain ipv4 raw blacklist [root@server1 ~]# firewall-cmd --direct --permanent --add-rule ipv4 raw PREROUTING 0 -s 192.168.0.0/24 -j blacklist [root@server1 ~]# firewall-cmd --direct --permanent --add-rule ipv4 raw blacklist 0 -m limit --limit 1/min -j LOG --log-prefix "blacklisted " [root@server1 ~]# firewall-cmd --direct --permanent --add-rule ipv4 raw blacklist 1 -j DROP