標籤:dead wal end loaded font col tcp inactive port
注意:firewalld服務有兩份規則策略配置記錄,配置永久生效的策略記錄時,需要執行"reload"參數後才能立即生效:
- Permanent:永久生效的
- RunTime:現在正在生效的
1.查看目前範圍
[[email protected] bin]# chkconfig iptables offpublic
2.查看防火牆狀態,需要注意的是,設定連接埠規則時防火牆必須是啟動狀態
[[email protected] ~]# systemctl status firewalld //返回資訊提示防火牆未啟動● firewalld.service - firewalld - dynamic firewall daemon Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled) Active: inactive (dead) //dead代表關閉狀態 Docs: man:firewalld(1)[[email protected]-7bec-0002 ~]# systemctl start firewalld //啟動防火牆[[email protected] ~]# systemctl status firewalld ● firewalld.service - firewalld - dynamic firewall daemon Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled) Active: active (running) since Tue 2018-10-09 19:38:36 CST; 2s ago Docs: man:firewalld(1) Main PID: 9269 (firewalld) CGroup: /system.slice/firewalld.service └─9269 /usr/bin/python -Es /usr/sbin/firewalld --nofork --nopidOct 09 19:38:36 ecs-7bec-0002 systemd[1]: Starting firewalld - dynamic firewall daemon...Oct 09 19:38:36 ecs-7bec-0002 systemd[1]: Started firewalld - dynamic firewall daemon.
3.配置需要開發的連接埠
[[email protected] ~]# firewall-cmd --zone=public --add-port=連接埠號碼/tcp --permanentsuccess
4.執行命令使連接埠生效
[[email protected] ~]# firewall-cmd --reloadsuccess
5.查看連接埠是否生效
[[email protected] ~]# firewall-cmd --zone=public --query-port=連接埠號碼/tcpyes
6.防火牆其他動作
[[email protected] ~]# firewall-cmd --list-port //查看所有開發連接埠3306/tcp 80/tcp[[email protected]-7bec-0002 ~]# firewall-cmd --zone=public --remove-port=8080/tcp --permanent 刪除一個連接埠success[[email protected]-7bec-0002 ~]# firewall-cmd --reload //使新配置的連接埠規則生效success[[email protected]-7bec-0002 ~]# firewall-cmd --version //查看版本0.4.3.2[[email protected]-7bec-0002 ~]# firewall-cmd --staterunning[[email protected]-7bec-0002 ~]# firewall-cmd --get-active-zones //查看所在地區public interfaces: eth0
Centos 7中,防火牆配置連接埠規則