启动:
systemctl start firewalld
查看状态:
systemctl status firewalld
停止:
systemctl disable firewalld
禁用:
systemctl stop firewalld
查看列表
firewall-cmd --list-all
[root@localhost conf]# firewall-cmd --list-all
public (active)
target: default
icmp-block-inversion: no
interfaces: eth0
sources:
services: dhcpv6-client ssh
ports: 20/tcp 21/tcp 22/tcp 80/tcp 8888/tcp 39000-40000/tcp 443/tcp
protocols:
masquerade: no
forward-ports:
source-ports:
icmp-blocks:
rich rules:
永久允许172.25.5.0网段访问:
firewall-cmd --permanent --add-source=172.25.5.0/24
永久开启3260端口:
(--add-port=80/tcp #添加端口,格式为:端口/通讯协议--permanent #永久生效,没有此参数重启后失效)
firewall-cmd --permanent --add-port=3260/tcp --zone=work
永久开启ssh服务(--zone=work添加的区域为work):
firewall-cmd --permanent --add-service=ssh --zone=work
移除ssh服务:
firewall-cmd --permanent --remove-service=ssh --zone=work
更新防火墙规则:
firewall-cmd --reload