You can display the exact rults using this command

sudo iptables -L -v

for ipv4 rules and

sudo ip6tables -L -v

for ipv6

82889  123M ACCEPT     all  --  any    any     anywhere             anywhere             ctstate RELATED,ESTABLISHE
    1    60 ACCEPT     all  --  lo     any     anywhere             anywhere

The firs line accepts any traffic for established connections, and for related traffic such as udp used by DNF.

The second line accepts anything arriving on the loopback device.