启动:systemctl start firewalld.service
关闭:systemctl stop firewalld.service
状态:systemctl status firewalld.service
默认对外开放22端口
开放端口:firewall-cmd --zone=public --add-port=80
/tcp
--permanent
添加ip访问端口
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="192.168.142.166" port protocol="tcp" port="5432" accept"
也可以是端口段port="5432-5555"
删除ip访问端口
firewall-cmd --permanent --remove-rich-rule="rule family="ipv4" source address="192.168.142.166" port protocol="tcp" port="5432" accept"
使配置生效:firewall-cmd --reload
查看当前规则:firewall-cmd --list-all