开启/关闭防火墙
firewall-cmd --state
systemctl status firewalld
systemctl start firewalld
systemctl enable firewalld
systemctl stop firewalld
systemctl disable firewalld
查看端口开放状态
firewall-cmd --list-all
开放/关闭端口
firewall-cmd --permanent --add-port=3306/tcp
firewall-cmd --permanent --remove-port=3306/tcp
firewall-cmd --permanent --add-port=1-9999/tcp
firewall-cmd --permanent --remove-port=1-9999/tcp
firewall-cmd --reload
限制/解除IP访问
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="123.44.55.66" port protocol="tcp" port="3306" reject"
firewall-cmd --permanent --remove-rich-rule="rule family="ipv4" source address="123.44.55.66" port protocol="tcp" port="3306" reject"
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="123.44.55.0/24" port protocol="tcp" port="3306" reject"
firewall-cmd --permanent --remove-rich-rule="rule family="ipv4" source address="123.44.55.0/24" port protocol="tcp" port="3306" reject"
firewall-cmd --reload
修改配置文件
vim /etc/firewalld/zones/public.xml