osboxes@osboxes:~ $ sudo firewall-cmd --zone=public --permanent --add-port=3306/tcp
success
osboxes@osboxes:~ $ sudo firewall-cmd --reload
success
osboxes@osboxes:~ $ sudo firewall-cmd --list-all
public (active)
  target: default
  icmp-block-inversion: no
  interfaces: enp0s3
  sources: 
  services: ssh dhcpv6-client
  ports: 80/tcp 8080/tcp 3306/tcp
  protocols: 
  masquerade: no
  forward-ports: 
  source-ports: 
  icmp-blocks: 
  rich rules: