神殇 發表於 2023-2-23 16:09:00

银河麒麟服务器操作系统 V10 SP1 防火墙(firewalld)指令

<h2>一、Kylin系统查看firewalld状态</h2>
<p>systemctl status firewalld(或者:systemctl status firewalld.service,或者:systemctl is-active firewalld)active(running):表示防火墙已经开启。</p>
<p><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315105633813-1427126009.png"></p>
<h2>二、开启、重启、关闭firewalld服务</h2>
<p>1、开启:systemctl start firewalld&nbsp;&nbsp;查看状态:systemctl status firewalld</p>
<p><em><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315105828808-888485587.png"></em></p>
<p>2、关闭:systemctl stop firewalld&nbsp;&nbsp;查看状态:systemctl status firewalld<em><em><br><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315105952182-949893965.png"></em></em></p>
<p>3、重启:systemctl restart firewalld&nbsp;&nbsp;查看状态:systemctl status firewalld<em><em><br><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315110030600-1744361942.png"></em></em></p>
<h2>三、设置、取消开机启动(firewalld)</h2>
<p>1、设置开机启动firewalld:systemctl enable firewalld<br><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315110252910-1176825916.png"></p>
<p>2、开机关闭防火墙firewalld:systemctl disable firewalld</p>
<p><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315110219938-1078269604.png"></p>
<p>3、查询是否开机启动firewalld:systemctl is-enabled firewalld(enabled表示开机启动防火墙,disabled表示开机关闭防火墙)<br><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315110134634-291851341.png"></p>
<h2>四、查询、开放、关闭firewalld端口</h2>
<p>1、查询全部已开放的端口:firewall-cmd --list-all<br><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315111147050-642147356.png"></p>
<p>2、查询某个端口是否开放:firewall-cmd --query-port=[端口]/tcp,yes表示已经开放,no表示没有开放。</p>
<p># firewall-cmd --query-port=3306/tcp<br><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315111450450-724055023.png"></p>
<p>&nbsp;3、开放端口:firewall-cmd --permanent --add-port=[端口]/tcp,succes表示开方端口成功,如果开放已经开放的端口会报错如下图:</p>
<p>#&nbsp;firewall-cmd --permanent --add-port=3303/tcp</p>
<p><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315111721418-1833338654.png"></p>
<p>4、关闭端口:firewall-cmd --permanent --remove-port=[端口]/tcp,success表示关闭成功。<br>#&nbsp;firewall-cmd --permanent --remove-port=3303/tcp</p>
<p><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315111950887-144138519.png"></p>
<p>5、刷新服务(开放、关闭端口操作后需要刷新才能生效):firewall-cmd --reload,success表示刷新成功。<em id="__mceDel"><em id="__mceDel"><em id="__mceDel"><em id="__mceDel"><br></em></em></em></em></p>
<p><img src="https://img2023.cnblogs.com/blog/1204515/202303/1204515-20230315112052049-1966265892.png"></p>
<p>&nbsp;</p><br><br>
来源:https://www.cnblogs.com/liunaixu/p/17148444.html
頁: [1]
查看完整版本: 银河麒麟服务器操作系统 V10 SP1 防火墙(firewalld)指令