linux firewall
一、查看防火墙状态 systemctl status firewalld
systemctl start firewalld 二、开放或限制端口 firewall-cmd --zone=public --add-port=22/tcp --permanent
(2)重新载入一下防火墙设置,使设置生效 firewall-cmd --reload (3)可通过如下命令查看是否生效 firewall-cmd --zone=public --query-port=22/tcp
firewall-cmd --zone=public --list-ports
firewall-cmd --zone=public --remove-port=22/tcp --permanent
firewall-cmd --reload
firewall-cmd --zone=public --list-ports
firewall-cmd --zone=public --add-port=100-500/tcp --permanent
firewall-cmd --reload
firewall-cmd --zone=public --list-ports (4)同理,批量限制端口为 firewall-cmd --zone=public --remove-port=100-500/tcp --permanent firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="192.168.0.200" port protocol="tcp" port="80" reject"
firewall-cmd --reload firewall-cmd --zone=public --list-rich-rules
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="192.168.0.200" port protocol="tcp" port="80" accept"
firewall-cmd --reload firewall-cmd --zone=public --list-rich-rules
vi /etc/firewalld/zones/public.xml 3、限制IP地址段 firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="10.0.0.0/24" port protocol="tcp" port="80" reject" ? (2)重新载入一下防火墙设置,使设置生效 firewall-cmd --reload firewall-cmd --zone=public --list-rich-rules firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="10.0.0.0/24" port protocol="tcp" port="80" accept"firewall-cmd --reload--------------------- 作者:咖啡那么浓 来源:CSDN 原文:https://blog.csdn.net/ywd1992/article/details/80401630 版权声明:本文为博主原创文章,转载请附上博文链接! (编辑:李大同) 【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容! |