centos7 firewall 防火牆 命令

2021-08-21 04:23:57 字數 2209 閱讀 6039

出自:

#yum install firewalld  //安裝firewalld 防火牆
# systemctl start firewalld.service

● firewalld.service - firewalld - dynamic firewall daemon

loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled; vendor preset: enabled)

active: active (running) since 四 2017-06-08 19:25:45 cst; 4 days ago

docs: man:firewalld(1)

main pid: 744 (firewalld)

cgroup: /system.slice/firewalld.service

└─744 /usr/bin/python -es /usr/sbin/firewalld --nofork --nopid

#firewall-cmd --panic-on  //在 0.3.0 之前的 firewalld版本中, panic 選項是 –enable-panic 與 –disable-panic

#firewall-cmd --get-service

#firewall-cmd --query-panic
#firewall-cmd --reload

# firewall-cmd --zone=public --add-service=https //臨時

# firewall-cmd --permanent --zone=public --add-service=https //永久

#firewall-cmd --permanent --zone=public --add-port=8080-8081/tcp //永久

#firewall-cmd --zone=public --add-port=8080-8081/tcp //臨時

#firewall-cmd --reload

#firewall-cmd --permanent --zone=public --list-services //服務空格隔開 例如 dhcpv6-client https ss

#firewall-cmd --permanent --zone=public --list-ports //埠空格隔開 例如 8080-8081/tcp 8388/tcp 80/tcp

#systemctl start firewalld.service //開啟服務

#systemctl enable firewalld.service //開機制動啟動

#systemctl stop firewalld.service //關閉服務

#systemctl disable firewalld.service //禁止開機啟動

firewall-cmd --query-masquerade # 檢查是否允許偽裝ip

firewall-cmd --add-masquerade # 允許防火牆偽裝ip

firewall-cmd --remove-masquerade# 禁止防火牆偽裝ip

# firewall-cmd --zone=public --add-forward-port=port=22:proto=tcp:toport=3753

centos 7 firewall無法啟動

報錯資訊 root localhost bin systemctl status firewalld firewalld.service firewalld dynamic firewall daemon loaded loaded usr lib systemd system firewalld....

CentOS 7 firewall使用方法

1.在firewall規則中新增80埠 firewall cmd zone public add port 80 tcp permanent 2.獲取firewall狀態資訊 firewall cmd state firewall cmd reload 不改變狀態 firewall cmd comp...

centos7 firewall指定IP與埠訪問

1 啟動防火牆 systemctl start firewalld.service 2 指定ip與埠 firewall cmd permanent add rich rule rule family ipv4 source address 192.168.142.166 port protocol ...