Snagged again by my own lack of RTFM ----
The behavior is explained in the man page:
Code:
Permanent Options
--permanent
. . . These changes are not effective immediately, only after service restart/reload or system reboot. Without the --permanent
option, a change will only be part of the runtime configuration.
firewall-cmd --complete-reload
and now iptables -nvL reports all xxx.0.0.0/8 drops and blocks.