启动: systemctl start firewalld
查看状态: systemctl status firewalld
停止: systemctl disable firewalld
禁用: systemctl stop firewalld
永久开放一个端口
firewall-cmd --zone=public --add-port=80/tcp --permanent
(--permanent永久生效,没有此参数重启后失效)
删除端口
firewall-cmd --zone=public --remove-port=80/tcp --permanent
重新载入
firewall-cmd --reload
查询端口状态
firewall-cmd --zone=public --query-port=9200/tcp
查看全部状态
firewall-cmd --list-all
对指定ip开放端口
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" \
source address="192.168.1.101" port protocol="tcp" port="9200" accept"
查看富配置列表
firewall-cmd --list-rich-rule
删除规则
firewall-cmd --permanent --remove-rich-rule="rule family="ipv4" \
source address="192.168.1.101" port protocol="tcp" port="80" accept"