查询端口号80是否开启
firewall-cmd --query-port=80/tcp
开启80端口
firewall-cmd --zone=public --add-port=80/tcp --permanent
移除80端口
firewall-cmd --zone=public --remove-port=80/tcp --permanent
重启防火墙
firewall-cmd --reload
查询有哪些端口是开启的
firewall-cmd --list-port
开启防火墙
systemctl start firewalld
关闭防火墙
systemctl stop firewalld
查看firewall服务状态
systemctl status firewalld
查看firewall的状态
firewall-cmd --state
查看防火墙规则
firewall-cmd --list-all
禁止一个IP段,比如禁止192.168.100.*
firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address="192.168.100.0/24" drop'
屏蔽IP
firewall-cmd --permanent --add-rich-rule="rule family=ipv4 source address=192.168.100.1 reject"
移除屏蔽
firewall-cmd --permanent --remove-rich-rule="rule family=ipv4 source address=192.168.100.1 reject"
查看屏蔽结果
firewall-cmd --list-rich-rules