1. Using the Setup command
[1] Open a terminal window and enter the Setup command
[[Email protected] ~]# Setup
[2] Select the firewall configuration, select the run Tool and go to the firewall config interface
[3] Tick enabled to turn on the firewall, do not check the open, open here, and select Customize to customize the configuration
[4] Select the service port to open, this example chooses Ftp,www (HTTP). The default SSH service port is open for SSH remote login, if you are configuring a Linux server remotely, be sure to keep the SSH service port open, do not disconnect from the posterior.
[5] The configuration is good after the forward to the last save, if there are other ports to open, there are corresponding custom pages in the middle. Last to this page, select Yes to overwrite the original settings to save.
2. Command-line mode
[1] Edit firewall configuration, 21 ports and 80 ports are added FTP service with 80 service port
[Email protected] ~]# vi/etc/sysconfig/iptables# Firewall configuration written by system-config-firewall# Manual Custo Mization of this file was not recommended.*filter:input accept [0:0]:forward Accept [0:0]:output Accept [0:0]-a Input-m St Ate--state established,related-j accept-a input-p icmp-j accept-a input-i lo-j accept-a input-m State--state NEW- M tcp-p TCP--dport 22-j ACCEPT-A input-m State--state new-m tcp-p TCP--dport-J Accept-a input-m State--state new-m tcp-p TCP--dport-J ACCEPT-A input-j REJECT--reject-with icmp-host-prohibited-a Forward-j REJECT--reject-with Icmp-host-prohibitedcommit
[2] Shutting down the Firewall service (temporarily shutting down the Firewall service, the service will automatically turn on after restarting)
[[Email protected] ~]# service iptables stopiptables:flushing Firewall rules: [ OK ]iptables:setting Chains to Policy Accept:filter [ OK ]iptables:unloading modules: [ OK ]
[3] Configuring the Firewall service default boot does not start (if the server does not require a firewall)
[Email protected] ~]# chkconfig iptables off
CentOS Firewall configuration