firewall-cmd --help
systemctl unmask firewalld
systemctl mask firewalld
systemctl enable firewalld
systemctl disable firewalld
systemctl start firewalld
systemctl stop firewalld
systemctl restart firewalld
firewall-cmd --state
systemctl status firewalld
firewall-cmd --reload
firewall-cmd --remove-service=ftp --permanent
firewall-cmd --query-service=http
firewall-cmd --query-port=22/tcp
firewall-cmd --list-interfaces
firewall-cmd --list-all
firewall-cmd --add-port=3128/tcp
firewall-cmd --zone=public --add-port=1688/tcp --permanent
firewall-cmd --zone=dmz --add-port=8080/tcp
firewall-cmd --zone=public --add-port=5060-5061/udp
firewall-cmd --zone=public --add-port=20000-30000/tcp --permanent
firewall-cmd --zone=public --remove-port=20000-30000/tcp --permanent
firewall-cmd --permanent --get-services
firewall-cmd --permanent --zone=public --add-service=ssh
firewall-cmd --permanent --zone=public --add-service=http
firewall-cmd --permanent --zone=public --add-service=https
firewall-cmd --permanent --zone=trusted --remove-service=http
firewall-cmd --permanent --zone=public --remove-port=1688/tcp
firewall-cmd --get-zones
firewall-cmd --set-default-zone=public
firewall-cmd --zone=public --add-interface=em1
firewall-cmd --list-all-zones
ls /usr/lib/firewalld/services
支持的服务名称
- amanda-client
- bacula
- bacula-client
- dhcp
- dhcpv6
- dhcpv6-client
- dns
- ftp
- high-availability
- http
- https
- imaps
- ipp
- ipp-client
- ipsec
- kerberos
- kpasswd
- ldap
- ldaps
- libvirt
- libvirt-tls
- mdns
- mountd
- ms-wbt
- mysql
- nfs
- ntp
- openvpn
- pmcd
- pmproxy
- pmwebapi
- pmwebapis
- pop3s
- postgresql
- proxy-dhcp
- radius
- rpc-bind
- samba
- samba-client
- smtp
- ssh
- telnet
- tftp
- tftp-client
- transmission-client
- vnc-server
- wbem-https
文章评论