netfilter防火墙

  • 查看SELinux防火墙状态
[root@dl-001 ~]# getenforce 
Enforcing

说明: Enforcing为打开状态;Disabled为关闭状态


  • 临时关闭SELinux防火墙:
[root@dl-001 ~]# setenforce 0

  • 永久关闭SELinux防火墙:
[root@dl-001 ~]# vi /etc/selinux/config    //编辑防火墙的配置文件
# This file controls the state of SELinux on the system.
# SELINUX= can take one of these three values:
#     enforcing - SELinux security policy is enforced.
#     permissive - SELinux prints warnings instead of enforcing.
#     disabled - No SELinux policy is loaded.
SELINUX=enforcing
# SELINUXTYPE= can take one of three two values:
#     targeted - Targeted processes are protected,
#     minimum - Modification of targeted policy. Only selected processes are protected.
#     mls - Multi Level Security protection.
SELINUXTYPE=targeted

说明:将SELINUX=enforcing改为disabled保存,重启系统即可生效。


netfilter(Firewalld)防火墙

netfilter防火墙在CentOS7之前用的防火墙,在CentOS7上更改了名字为firewalld。这里主要介绍netfilter

  • 关闭firewalld防火墙
[root@dl-001 ~]# systemctl disable firewalld    //永久关闭firewalld
Removed symlink /etc/systemd/system/dbus-org.fedoraproject.FirewallD1.service.
Removed symlink /etc/systemd/system/basic.target.wants/firewalld.service.
[root@dl-001 ~]# systemctl stop firewalld    //停止firewalld服务

  • 启用netfilter
[root@dl-001 ~]# yum install -y iptables-services    //下载工具包iptables,这里的iptables是netfilter的一个工具
[root@dl-001 ~]# systemctl enable iptables    //开启iptables服务
Created symlink from /etc/systemd/system/basic.target.wants/iptables.service to /usr/lib/systemd/system/iptables.service.
[root@dl-001 ~]# systemctl start iptables

说明: 安装完成后默认开启iptables服务。


  • 查看iptables默认规则
[root@dl-001 ~]# iptables -nvL
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
   41  2732 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     all  --  lo     *       0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            state NEW tcp dpt:22
    0     0 REJECT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            reject-with icmp-host-prohibited

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 REJECT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            reject-with icmp-host-prohibited

Chain OUTPUT (policy ACCEPT 24 packets, 2184 bytes)
 pkts bytes target     prot opt in     out     source               destination    
  • 2
    点赞
  • 4
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值