当前位置:网站首页>firewall 命令简单操作
firewall 命令简单操作
2022-07-26 04:00:00 【qq_43479892】
优质资源分享
| 学习路线指引(点击解锁) | 知识定位 | 人群定位 |
|---|---|---|
| 🧡 Python实战微信订餐小程序 🧡 | 进阶级 | 本课程是python flask+微信小程序的完美结合,从项目搭建到腾讯云部署上线,打造一个全栈订餐系统。 |
| Python量化交易实战 | 入门级 | 手把手带你打造一个易扩展、更安全、效率更高的量化交易系统 |
Firewalld 是维护防火墙策略的守护程序的名称。使用 firewall-cmd 命令与防火墙配置进行交互, 使用区域概念对与系统交互的流量进行分段。网络接口分配给一个或多个区域,每个区域都包含允许的端口和服务的列表。默认区域还可用于管理与任何区域都不匹配的流量。
0 语法规则
| | Usage: firewall-cmd [OPTIONS...] |
| | |
| | General Options |
| | -h, --help Prints a short help text and exists |
| | -V, --version Print the version string of firewalld |
| | -q, --quiet Do not print status messages |
| | |
| | Status Options |
| | --state Return and print firewalld state |
| | --reload Reload firewall and keep state information |
| | --complete-reload Reload firewall and lose state information |
| | --runtime-to-permanent |
| | Create permanent from runtime configuration |
| | --check-config Check permanent configuration for errors |
1. 状态检查
firewall-cmd --state

2 如果没有开启,可以先开启
systemctl start firewalld && systemctl --enable firewalld
3查看现有防护策略
| | # 查看防火墙,添加的端口也可以看到 |
| | firewall-cmd --list-all |
| | # 显示支持的区域列表 |
| | firewall-cmd --get-zones |
| | # 显示所有公共区域(public) |
| | firewall-cmd --zone=public --list-all |
4 查看默认zone配置,默认是public
firewall-cmd --get-default-zone

5.添加端口访问 ,使用 --add-port 参数,例如设置80端口TCP访问:
| | firewall-cmd --add-port=80/tcp |
上面规则会在机器重启时,策略失效,需要添加参数 --permanent 保证长期有效
| | firewall-cmd --add-port=80/tcp --permanent |
6 重新加载firewall 配置
| | firewall-cmd --reload |
7 添加services 服务
查看当前支持的系统service:
| | firewall-cmd --get-services |

添加http service 服务
| | firewall-cmd --add-service=http --permanent && firewall-cmd --reload |
添加 Jenkins service:
| | firewall-cmd --add-service=jenkins --permanent && firewall-cmd --reload |
8 删除services 服务和端口
| | firewall-cmd --remove-service=http # 阻止http端口 |
| | firewall-cmd --remove-port=80tcp # 阻止通过tcp访问3306 |
边栏推荐
- PHP object conversion array
- Chapter 18: explore the wonders of the mean in the 2-bit a~b system, specify the 3x+1 conversion process of integers, specify an interval to verify the angular Valley conjecture, explore the number of
- General test case writing specification
- KBPC1510-ASEMI大芯片15A整流桥KBPC1510
- waf详解
- 基于JSP实现网上商城系统
- Opencv learning notes - remapping
- Overview of wavelet packet transform methods
- 加班一周开发了报表系统,这个低代码免费IT报表神器太好用了
- 【读书笔记->数据分析】01 数据分析导论
猜你喜欢

PHP method to find the location of session storage file

Analysis on the infectious problem of open source license

booking.com缤客上海面经

1311_ Hardware design_ Summary of ICT concept, application, advantages and disadvantages

构建关系抽取的动词源

KBPC1510-ASEMI大芯片15A整流桥KBPC1510

基于SSM选课信息管理系统

Zkevm: summary of zkevm and L1 by Mina's CEO

Communication protocol and message format between microservices

6年从零开始的自动化测试之路,开发转测试我不后悔...
随机推荐
Worked overtime for a week to develop a reporting system. This low code free it reporting artifact is very easy to use
[深入研究4G/5G/6G专题-42]: URLLC-13-《3GPP URLLC相关协议、规范、技术原理深度解读》-7-低延时技术-1-子载波间隔扩展
Acwing第 61 场周赛【完结】
[MCU simulation project] external interrupt 0 controls 8 LED flashes
How does redis implement persistence? Explain the AOF trigger mechanism and its advantages and disadvantages in detail, and take you to quickly master AOF
ZK snark: about private key, ring signature, zkksp
《opencv学习笔记》-- 边缘检测和canny算子、sobel算子、LapIacian 算子、scharr滤波器
zkEVM:MINA的CEO对zkEVM和L1相关内容的总结
oracle 11g “密码延迟验证”特性
括号嵌套问题(建议收藏)
Bond network mode configuration
电商运营小白,如何快速入门学习数据分析?
Operator new, operator delete supplementary handouts
[programmers must] Tanabata confession strategy: "the moon meets the cloud, the flowers meet the wind, and the night sky is beautiful at night". (with source code Collection)
day03_ 1_ Idea tutorial
Failed to install the hcmon driver
WAF details
What are the differences between vite and wenpack?
Implementation of distributed lock
The B2B2C multi merchant system has rich functions and is very easy to open