安装Firewall命令:

yum install firewalld firewalld-config

Firewall开启常见端口命令:

firewall-cmd --zone=public --add-port=80/tcp --permanent
firewall-cmd --zone=public --add-port=443/tcp --permanent
firewall-cmd --zone=public --add-port=22/tcp --permanent
firewall-cmd --zone=public --add-port=21/tcp --permanent
firewall-cmd --zone=public --add-port=53/udp --permanent

Firewall关闭常见端口命令:

firewall-cmd --zone=public --remove-port=80/tcp --permanent
firewall-cmd --zone=public --remove-port=443/tcp --permanent
firewall-cmd --zone=public --remove-port=22/tcp --permanent
firewall-cmd --zone=public --remove-port=21/tcp --permanent
firewall-cmd --zone=public --remove-port=53/udp --permanent

批量添加区间端口:

firewall-cmd --zone=public --add-port=4400-4600/udp --permanent
firewall-cmd --zone=public --add-port=4400-4600/tcp --permanent

封禁IP:

firewall-cmd --permanent --zone=public --new-ipset=blacklist --type=hash:ip                #开启功能
firewall-cmd --permanent --zone=public --ipset=blacklist --add-entry=222.222.222.222       #封禁
firewall-cmd --permanent --zone=public --ipset=blacklist --remove-entry=222.222.222.222    #解封

封禁网段:

firewall-cmd --permanent --zone=public --new-ipset=blacklist --type=hash:net               #开启功能
firewall-cmd --permanent --zone=public --ipset=blacklist --add-entry=222.222.222.0/24      #封禁
firewall-cmd --permanent --zone=public --ipset=blacklist --remove-entry=222.222.222.0/24   #解封

开启防火墙命令:

systemctl start firewalld.service

重启防火墙命令:

firewall-cmd --reload  或者   service firewalld restart

查看端口列表:

firewall-cmd --permanent --list-port

禁用防火墙

systemctl stop firewalld

设置开机启动

systemctl enable firewalld

停止并禁用开机启动

systemctl disable firewalld

查看状态

systemctl status firewalld或者 firewall-cmd --state