[CentOS] firewalld

Sun Jan 29 21:54:02 UTC 2017
TE Dukes <tdukes at palmettoshopper.com>

Still un-resolved.  Could be wrong but I think its firewalld preventing me
from accessing mail with roundcube.

I'm getting Connection to storage server failed.
>From roundcubemail log: 

[29-Jan-2017 16:45:05 -0500]: <4r5ccifn> IMAP Error: Login failed for tdukes
from 192.168.1.102. AUTHENTICATE PLAIN: * BYE Internal error occurred. Refer
to server log for more information. in
/usr/share/roundcubemail/program/lib/Roundcube/rcube_imap.php on line 197
(POST /?_task=login?_task=login&_action=login)

There is absolutely nothing in the httpd logs.

I telnet to localhost 143 or 993  and I can connect, telneting to 25 or 465,
connection refused.

Clearly, below, those services and ports are open as well as mysql.

Ouput from:  firewall-cmd --list-all-zones

work
  target: default
  icmp-block-inversion: no
  interfaces: 
  sources: 
  services: dhcpv6-client ssh urbackup-server
  ports: 
  protocols: 
  masquerade: no
  forward-ports: 
  sourceports: 
  icmp-blocks: 
  rich rules: 
	

drop
  target: DROP
  icmp-block-inversion: no
  interfaces: 
  sources: 
  services: 
  ports: 
  protocols: 
  masquerade: no
  forward-ports: 
  sourceports: 
  icmp-blocks: 
  rich rules: 
	

internal (active)
  target: default
  icmp-block-inversion: no
  interfaces: enp1s0 lo
  sources: 
  services: dhcp dhcpv6 dhcpv6-client dns ftp http https imap imaps mdns
mysql openvpn pop3 pop3s rsyncd samba samba-client smtp smtps ssh
transmission-client urbackup-server
  ports: 465/tcp 20000/tcp 25/tcp 10000/tcp
  protocols: 
  masquerade: no
  forward-ports: 
  sourceports: 
  icmp-blocks: 
  rich rules: 
	

external
  target: default
  icmp-block-inversion: no
  interfaces: 
  sources: 
  services: ssh urbackup-server
  ports: 
  protocols: 
  masquerade: yes
  forward-ports: 
  sourceports: 
  icmp-blocks: 
  rich rules: 
	

trusted (active)
  target: ACCEPT
  icmp-block-inversion: no
  interfaces: virbr0
  sources: 
  services: dhcp dhcpv6 dhcpv6-client dns ftp http https imap imaps mysql
ntp openvpn pop3 pop3s rsyncd samba samba-client smtp smtps ssh
transmission-client urbackup-server
  ports: 465/tcp 20000/tcp 25/tcp 10000/tcp
  protocols: 
  masquerade: no
  forward-ports: 
  sourceports: 
  icmp-blocks: 
  rich rules: 
	

home
  target: default
  icmp-block-inversion: no
  interfaces: 
  sources: 
  services: dhcpv6-client mdns samba-client ssh
  ports: 10000/tcp
  protocols: 
  masquerade: no
  forward-ports: 
  sourceports: 
  icmp-blocks: 
  rich rules: 
	

dmz
  target: default
  icmp-block-inversion: no
  interfaces: 
  sources: 
  services: ssh
  ports: 
  protocols: 
  masquerade: no
  forward-ports: 
  sourceports: 
  icmp-blocks: 
  rich rules: 
	

public (active)
  target: default
  icmp-block-inversion: no
  interfaces: eno1
  sources: 
  services: dhcp dhcpv6-client dns ftp http https imap imaps mysql pop3
pop3s rsyncd samba samba-client smtp smtps ssh transmission-client
urbackup-server
  ports: 465/tcp 20000/tcp 25/tcp 10000/tcp
  protocols: 
  masquerade: no
  forward-ports: 
  sourceports: 
  icmp-blocks: 
  rich rules: 
	

block
  target: %%REJECT%%
  icmp-block-inversion: no
  interfaces: 
  sources: 
  services: 
  ports: 
  protocols: 
  masquerade: no
  forward-ports: 
  sourceports: 
  icmp-blocks: 
  rich rules: 
	

eno1 is on the public zone, lo is on the internal zone

I can read mail with mutt and usermin.

What am I missing?

TIA