service iptables status
service iptables stop
service iptables start
service iptables restart
chkconfig iptables off
chkconfig iptables on
vim /etc/sysconfig/iptables
# 加入如下代码
-A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
保存退出后重启防火墙
service iptables restart
systemctl status firewalld
出现Active: active (running)切高亮显示则表示是启动状态。
出现 Active: inactive (dead)灰色表示停止,看单词也行。
firewall-cmd --state
service firewalld start 或 systemctl start firewalld
service firewalld restart 或 systemctl restart firewalld
service firewalld stop 或 systemctl stop firewalld
firewall-cmd --list-all
查询端口是否开放
firewall-cmd --query-port=8080/tcp
开放80端口
firewall-cmd --permanent --add-port=80/tcp
重载防火墙(修改配置后要重启防火墙)
firewall-cmd --reload
移除端口
firewall-cmd --permanent --remove-port=8080/tcp
重载防火墙(修改配置后要重启防火墙)
firewall-cmd --reload
firewall-cmd --permanent --zone=public --add-rich-rule="rule family="ipv4" source address="10.1.1.14/32" port protocol="tcp" port="80" accept"
firewall-cmd --permanent --zone=public --remove-rich-rule="rule family="ipv4" source address="10.1.1.14/32" port protocol="tcp" port="80" accept"
/etc/firewalld/zones/public.xml
参数解释