防火墙设置(firewalld防火墙相关设置)
防火墙设置(firewalld防火墙相关设置)
firewalld默认拒绝其他IP访问
常用操作:systemctlstatusfirewalld查看防火墙状态systemctlrestartfirewalld开启重启防火墙firewallcmdreload重新载入一下防火墙设置,使设置生效systemctlstopfirewalld关闭防火墙systemctlenablefirewalld开机自启防火墙systemctldisablefirewalld开机不自启防火墙
开放关闭查询开放端口指定IP:firewallcmdzonepublicaddport80tcppermanent开放端口firewallcmdzonepublicaddport100500tcppermanent批量开放端口firewallcmdzonepublicremoveport80tcppermanent解除端口开放firewallcmdpermanentaddrichrulerulefamilyipv4sourceaddress192。168。0。102portprotocoltcpport23accept开放ip及端口firewallcmdpermanentaddrichrulerulefamilyipv4sourceaddress192。168。0。129portprotocoltcpport80reject限制ip访问某端口firewallcmdpermanentaddrichrulerulefamilyipv4sourceaddress192。168。0。129accept开放某ipfirewallcmdpermanentaddrichrulerulefamilyipv4sourceaddress192。168。0。129reject限制某ipfirewallcmdreload重新载入一下防火墙设置,使设置生效firewallcmdzonepubliclistports查看开放的端口firewallcmdlistports查看全部已经开放的端口firewallcmdzonepubliclistports查看public域开放端口firewallcmdzonepublicqueryport22tcp查看开启是否生效firewallcmdzonepubliclistrichrules查看已经设置的规则
vi
etcfirewalldzonespublic。xml删除规则
非常用操作:systemctlmaskfirewalld冻结火墙服务systemctlunmaskfirewalld解冻火墙服务firewallcmdgetdefaultzone查看火墙默认的域firewallcmdgetactivezone查看火墙活动的域firewallcmdgetzones查看火墙所有可用的域firewallcmdzonepubliclistall列出指定域的所有设置