永久关闭SELinux
[root@centos ~]# vi /etc/selinux/config #将enforcing改为disabled
# This file controls the state of SELinux on the system.
# SELINUX= can take one of these three values:
# enforcing - SELinux security policy is enforced.
# permissive - SELinux prints warnings instead of enforcing.
# disabled - No SELinux policy is loaded.
SELINUX=disabled
# SELINUXTYPE= can take one of these two values:
# targeted - Targeted processes are protected,
# mls - Multi Level Security protection.
SELINUXTYPE=targeted
"/etc/selinux/config" 13L, 457C written
[root@centos ~]# setenforce
usage: setenforce [ Enforcing | Permissive | 1 | 0 ]
[root@centos ~]# setenforce 0
[root@centos ~]# getenforce
Permissive
永久关闭iptables
对于iptables关闭或开启建议
1)服务器可以被外界访问(公网/外网ip),iptables开启
2)内部环境(局域网/