放通某個端口
firewall-cmd --permanent --zone=public --add-port=5672/tcp
移除以上規則
firewall-cmd --permanent --zone=public --remove-port=5672/tcp
放通某個端口段
firewall-cmd --permanent --zone=public --add-port=10000-20000/tcp
查看所有放通的端口
firewall-cmd --zone=public --list-ports
查看防火牆的配置
firewall-cmd --list-all
放通某個IP訪問
firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address=192.168.1.169 accept'
移除以上規則
firewall-cmd --permanent --remove-rich-rule='rule family=ipv4 source address=192.168.1.169 accept'
放通某個IP段訪問
firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address=192.168.2.0/24 accept'
禁止某個IP訪問
firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address=192.168.1.169 drop'
放通某個IP訪問某個端口
firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address=192.168.1.169 port protocol=tcp port=6379 accept'
重新加載防火牆配置
firewall-cmd --reload
關閉防火牆
systemctl stop firewalld.service
啟動防火牆
systemctl start firewalld.service
重啟防火牆
systemctl restart firewalld.service
查看防火牆狀態
firewall-cmd --state