CentOS 7.5 设置防火墙 firewall

1、查看防火墙状态

方法一:service firewalld status

[root@host-192-168-37-24 ~]# service firewalld status
Redirecting to /bin/systemctl status firewalld.service
● firewalld.service - firewalld - dynamic firewall daemon
   Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled; vendor preset: enabled)
   Active: active (running) since Sun 2019-10-27 17:15:13 CST; 1min 51s ago
     Docs: man:firewalld(1)
 Main PID: 92586 (firewalld)
   CGroup: /system.slice/firewalld.service
           └─92586 /usr/bin/python -Es /usr/sbin/firewalld --nofork --nopid

Oct 27 17:15:13 host-192-168-37-24 systemd[1]: Starting firewalld - dynamic firewall daemon...
Oct 27 17:15:13 host-192-168-37-24 systemd[1]: Started firewalld - dynamic firewall daemon.
[root@host-192-168-37-24 ~]# 

方法二:systemctl status firewalld.service

[root@host-192-168-37-24 ~]# systemctl status firewalld.service 
● firewalld.service - firewalld - dynamic firewall daemon
   Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled; vendor preset: enabled)
   Active: active (running) since Sun 2019-10-27 17:15:13 CST; 12s ago
     Docs: man:firewalld(1)
 Main PID: 92586 (firewalld)
   CGroup: /system.slice/firewalld.service
           └─92586 /usr/bin/python -Es /usr/sbin/firewalld --nofork --nopid

Oct 27 17:15:13 host-192-168-37-24 systemd[1]: Starting firewalld - dynamic firewall daemon...
Oct 27 17:15:13 host-192-168-37-24 systemd[1]: Started firewalld - dynamic firewall daemon.
[root@host-192-168-37-24 ~]# 

方法三:firewall-cmd --state

[root@host-192-168-37-24 ~]# firewall-cmd --state
not running
[root@host-192-168-37-24 ~]# firewall-cmd --state
running

2、启动、停止、重启 firewalld.service

方法一:systemctl

[root@host-192-168-37-24 ~]# systemctl stop firewalld.service
[root@host-192-168-37-24 ~]# systemctl start firewalld.service
[root@host-192-168-37-24 ~]# systemctl restart firewalld.service

方法二:service

[root@host-192-168-37-24 ~]# service firewalld stop
[root@host-192-168-37-24 ~]# service firewalld start
[root@host-192-168-37-24 ~]# service firewalld restart

3、查看防火墙规则

[root@host-192-168-37-24 ~]# firewall-cmd --list-all 
public (active)
  target: default
  icmp-block-inversion: no
  interfaces: eth0
  sources: 
  services: ssh dhcpv6-client
  ports: 
  protocols: 
  masquerade: no
  forward-ports: 
  source-ports: 
  icmp-blocks: 
  rich rules: 
	
[root@host-192-168-37-24 ~]# 

4、查询规则、开放端口、关闭端口

[root@host-192-168-37-24 ~]# firewall-cmd --query-port=80/tcp
no
[root@host-192-168-37-24 ~]# firewall-cmd --add-port=80/tcp
success
[root@host-192-168-37-24 ~]# firewall-cmd --remove-port=8080/tcp
success

# 修改防火墙规则后,需要重启防火墙
[root@host-192-168-37-24 ~]# firewall-cmd --reload 
success
[root@host-192-168-37-24 ~]# 
参数含义:
firwall-cmd:	# 是Linux提供的操作firewall的命令工具;
--permanent:	# 表示设置为持久;
--add-port:	# 表示添加的端口;
--remove-port:	# 表示删除端口

5、END

愉快的玩耍吧

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值