开启端口
1
2
3firewall-cmd --zone=public --add-port=<port>/<protocol> --permanent
<port> 要开启的端口
<protocol> 协议:tcp、udp关闭端口
firewall-cmd --zone=public --remove-port=<port>/<protocol> --permanent
批量开启区间端口
1
2firewall-cmd --zone=public --add-port=<start>-<end>/<protocol> --permanent
<start>、<end>:要开启的区间[start, end]开启、关闭、重启防火墙命令:
1
2
3systemctl start/stop/restart firewalld.service
或者
service firewalld start/stop/restart重新载入防火墙配置(更新配置后需要执行此命令):
firewall-cmd --reload
查看开放的端口:
firewall-cmd --permanent --list-port
禁用防火墙
systemctl stop firewalld
设置开机启动
systemctl enable firewalld
停止防火墙并禁用开机启动
systemctl disable firewalld
查看状态
1
2
3systemctl status firewalld
或者
firewall-cmd --state