[root@centos7pc system]# firewall-cmd --zone=public --add-port=21/tcp --permanent
success
[root@centos7pc system]# systemctl restart firewalld.service
[root@centos7pc system]# firewall-cmd --list-ports
21/tcp
1、防火墙
1)查看
[root@centos7pc vsftpd]# firewall-cmd --state
not running
2)启动
systemctl start firewalld.service
3)停止
systemctl stop firewalld.service
4)重启
systemctl restart firewalld.service
5)禁止开机启动
systemctl disable firewalld.service
6)设置开机启动
systemctl enable firewalld.service
7)查看设置开机启动是否成功
[root@centos7pc system]# systemctl is-enabled firewalld.service;echo $?
disabled
1
[root@centos7pc system]# systemctl enable firewalld.service
Created symlink from /etc/systemd/system/dbus-org.fedoraproject.FirewallD1.service to /usr/lib/systemd/system/firewalld.service.
Created symlink from /etc/systemd/system/multi-user.target.wants/firewalld.service to /usr/lib/systemd/system/firewalld.service.
[root@centos7pc system]# systemctl is-enabled firewalld.service;echo $?
enabled
0
2、防火墙开启/关闭特定端口
1)、命令
firewall-cmd --zone=public --add-port=80/tcp --permanent #开启端口命令
firewall-cmd --zone=public --remove-port=20/tcp --permanent #关闭端口命令
systemctl restart firewalld.service #重启防火墙
也可以不重启,重新载入配置。
firewall-cmd --reload
--zone :作用域
--add-port=80/tcp :添加端口,格式为:端口/通讯协议
--permanent :永久生效,没有此参数重启后失效
2)查看
[root@centos7pc system]# firewall-cmd --zone=public --add-port=21/tcp --permanent
success
[root@centos7pc system]# systemctl restart firewalld.service
[root@centos7pc system]# firewall-cmd --list-ports
21/tcp