1、指定IP与端口
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="192.168.1.100" port protocol="tcp" port="3306" accept"
指定多个端口(连续)
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="192.168.1.100" port protocol="tcp" port="3306-3309" accept"
指定ip段可以访问
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="192.168.1.0/24" port protocol="tcp" port="3306" accept"
开启所有ip访问端口
firewall-cmd --zone=public --add-port=80/tcp --permanent
2、重新载入,使配置生效
firewall-cmd --reload
3、查看配置结果
firewall-cmd --list-all
4、删除规则
firewall-cmd --permanent --remove-rich-rule="rule family="ipv4" source address="192.168.1.100" port protocol="tcp" port="3306" accept"
指定端口删除
firewall-cmd --zone=public --remove-port=80/tcp --permanent
5、其他常用命令
#linux关闭防火墙
临时关闭
systemctl stop firewalld
禁止开机启动
systemctl disable firewalld
设置开机启动
systemctl enable firewalld
查看防火墙状态
systemctl status firewalld
打开防火墙
systemctl start firewalld