firewall安装
- 安装并设置开机启动
yum install firewalld firewall-config
systemctl start firewalld.service
systemctl enable firewalld.service
systemctl status firewalld
firewall-cmd命令
- 防火墙状态
firewall-cmd --state
- 重新加载规则
firewall-cmd --reload
- 查看所有规则
firewall-cmd --list-all
- 添加端口(多个端口用逗号隔开)
firewall-cmd --permanent --add-port=5000/tcp
firewall-cmd --permanent --add-port={9200/tcp,9300/tcp}
- 端口转发
(例子:将80端口转发到5601)
firewall-cmd --permanent --add-forward-port=port=80:proto=tcp:toport=5601
如果不想用firewall,用iptables
systemctl stop firewalld.service
systemctl disable firewalld.service
yum -y install iptables-services
systemctl start iptables
systemctl enable iptables