systemctl命令
- systemctl status firewalld.service查看防火墙的状态;
- systemctl start firewalld.service启动防火墙;
- systemctl stop firewalld.service关闭防火墙;
- systemctl restart firewalld.service重启防火墙;
- systemctl enable firewalld.service开机启动防火墙;
- systemctl disable firewalld.service开机禁用防火墙;
- systemctl is-enabled firewalld.service查看防火墙是否开机启动;
手动开放防火墙端口
- 检查防火墙开放的端口
firewall-cmd --list-ports
- 检查端口是否开放
firewall-cmd --query-port 80/tcp
- 开启防火墙
firewall-cmd --zone=public --add-port=80/tcp --permanent
- 移除端口
firewall-cmd --zone=public --remove-port=9090/tcp --permanent
- 关于防火墙操作的解释
–zone #作用域
–add-port=80/tcp #添加端口,格式为:端口/通讯协议
–remove-port=80/tcp #移除端口,格式为:端口/通讯协议
–permanent #永久生效,没有此参数重启后失效
- 重启防火墙
firewall-cmd --reload