centos7防火牆端口設置常用命令
#查看防火牆狀態
systemctl status firewalld
#開啟防火牆
systemctl start firewalld
#關閉防火牆
systemctl stop firewalld
#查看當前firewall狀態
firewall-cmd –state
#重啟firewall
firewall-cmd –reload
#查看已經開放的端口:
firewall-cmd –list-ports
#開啟端口
firewall-cmd –zone=public –add-port=80/tcp –permanent
#開啟端口後需要重啟防火牆
命令含義:
–zone #作用域
–add-port=80/tcp #添加端口,格式為:端口/通訊協議
–permanent #永久生效,沒有此參數重啟後失效
#多個端口:
firewall-cmd –zone=public –add-port=80-90/tcp –permanent
#刪除端口
firewall-cmd –zone=public –remove-port=80/tcp –permanent
#設置開機啟用防火牆
systemctl enable firewalld.service
#設置開機不啟動防火牆
systemctl disable firewalld.service
#查看本機已經啟用的監聽端口:
#centos7以下使用netstat -ant,7使用ss
ss -ant
#centos7查看防火牆所有信息
firewall-cmd –list-all
#centos7查看防火牆開放的端口信息
firewall-cmd –list-ports