Active/Disabled Services

Check to see if running services are also enabled (note, not all services will require to be enabled. Its just a rough guide to go by).

for i in $(systemctl list-units | awk '$4 ~ /running/ {print $1}'); do systemctl list-unit-files | grep $i | awk '/disabled/'; done

Firewalld Runtime-to-perm

firewall-cmd --runtime-to-permanent