启动命令
代码语言:javascript复制启动:
systemctl start firewalld
查看状态:
systemctl status firewalld
停止:
systemctl stop firewalld
禁用:
systemctl disable firewalld
启用:
systemctl enable firewalld
添加端口开放:
firewall-cmd --zone=public --add-port=2380/tcp --permanent
移除端口开放
firewall-cmd --zone= public --remove-port=80/tcp --permanent
查看已经开发的端口:
firewall-cmd --zone=public --list-ports
支持vvrp的虚拟协议(keepalived中使用)
firewall-cmd --direct --permanent --add-rule ipv4 filter INPUT 0 --in-interface em1 --destination 224.0.0.18 --protocol vrrp -j ACCEPT
支持网卡的转发
firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -i eth1 -p gre -j ACCEPT
重新加载规则:
firewall-cmd --reload