查看防火墙状态:
firewall-cmd --state
打开防火墙
systemctl start firewalld
关闭防火墙
systemctl stop firewalld
重启防火墙
firewall-cmd --relaod
或者
systemctl reload firewalld
开机自启动防火墙
systemctl enable firewalld
禁止开机启动防火墙
systemctl disable firewalld
查看已打开的端口
firewall-cmd --list-ports
永久打开某个(些)端口
firewall-cmd --permanent --zone=public --add-port=8080/tcp
firewall-cmd --zone=public --permanent --add-port=4990-4999/tcp
永久关闭某个端口
firewall-cmd --permanent --zone=public --remove-port=5000/tcp