[root@host ~]# firewall-cmd --permanent --direct --add-rule ipv4 filter OUTPUT 0 -d 10.12.13.34 -j ACCEPT success [root@host ~]# firewall-cmd --permanent --direct --add-rule ipv4 filter OUTPUT 1 -j DROP success [root@host ~]# firewall-cmd --reload success