CentOS7 防火墙相关操作与端口配置 (收集+持续更新)
一、防火墙 开启、关闭、查看状态
1、开启防火墙
[root@localhost ~]# systemctl start firewalld
2、关闭防火墙
[root@localhost ~]# systemctl stop firewalld
3、重启防火墙
[root@localhost ~]# systemctl start firewalld
4、查看防火墙当下的状态
[root@localhost ~]# systemctl status firewalld
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/53c89bc6c20b2d49acc689cd3ce1ad31.jpg)
5、开机自动启用防火墙
[root@localhost ~]# systemctl enable firewalld
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/5b8d79c868a5e783d062c4327823ecfe.jpg)
6、开机默认禁用防火墙
[root@localhost ~]# systemctl disable firewalld
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/7cbf48f50b0fae590e40c57a07100dd9.jpg)
7、查看防火墙开机 启用/禁用 状态
[root@localhost ~]# systemctl is-enabled firewalld
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/7fc523459fea01b97ac5b7712805fa85.jpg)
8、查看系统当前启动服务的列表
[root@localhost ~]# systemctl list-unit-files|grep enabled
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/65858bc9b90b56dff246006eef958068.jpg)
9、查看启动失败的服务列表
[root@localhost ~]# systemctl --failed
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/a5f51d376422ef19500973d62df60978.jpg)
二、防火墙相关命令
1、查看防火墙版本
[root@localhost ~]# firewall-cmd --version
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/7cb6093c5be91d04aae580ae49953a40.jpg)
2、查看帮助
[root@localhost ~]# firewall-cmd --help
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/b66675d3f90f98566a9ac92e2471905b.jpg)
其余还有很多
3、查看示当前防火墙状态
[root@localhost ~]# firewall-cmd --state
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/49391bb879c556f4de052dfa98343bbb.jpg)
4、查看当前防火墙打开的所有端口
[root@localhost ~]# firewall-cmd --zone=public --list-ports
5、更新防火墙规则
[root@localhost ~]# firewall-cmd --reload
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/dca1b1f7e49185165594ef0be4adea44.jpg)
6、查看防火墙区域信息
[root@localhost ~]# firewall-cmd --get-active-zones
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/eba2a776aa0909231b3d4ee8e7e47461.jpg)
7、查看指定接口所属区域
[root@localhost ~]# firewall-cmd --get-zone-of-interface=eth0
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/1998370c3bb21526524ef218843bd7ee.jpg)
8、拒绝所有包 (慎用)
[root@localhost ~]# firewall-cmd --panic-on
9、取消 包拒绝状态
[root@localhost ~]# firewall-cmd --panic-off
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/e7686f1c2ccbdf37faad589a9b27d41d.jpg)
10、查看包的拒绝状态
[root@localhost ~]# firewall-cmd --query-panic
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/c549b124104e53f583b88b8c8cde2efb.jpg)
三、firewall防火墙及端口设置
1、防火墙添加端口
[root@localhost ~]# firewall-cmd --zone=public(作用域) --add-port=80/tcp(端口和访问类型) --permanent(永久生效)
2、添加80端口
[root@localhost ~]# firewall-cmd --zone=public --add-port=80/tcp --permanent
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/b3aadedc6a0f7a0bf4b5beeb74d0b6c1.jpg)
(--permanent永久生效,没有此参数重启后失效)
3、重新载入防火墙配置
[root@localhost ~]# firewall-cmd --reload
4、查看指定端口状态
[root@localhost ~]# firewall-cmd --zone= public --query-port=80/tcp
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/e75769bd2e0a9f3f63968cb4b7fb8c2f.jpg)
5、防火墙移除指定端口
[root@localhost ~]# firewall-cmd --zone=public --remove-port=80/tcp --permanent
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/c88e956460f30ca92f64b182a1d50e82.jpg)
6、检查是否允许伪装IP
[root@localhost ~]# firewall-cmd --query-masquerade
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/4365f4150a8378c3425a6ff663035f8e.jpg)
7、允许防火墙伪装IP
[root@localhost ~]# firewall-cmd --add-masquerade
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/3c3823d728bab37c5d37a85c03932c07.jpg)
8、禁止防火墙伪装IP
[root@localhost ~]# firewall-cmd --remove-masquerade
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/3e9ff29eaf7ff210e99f47d65832d67f.jpg)
9、开放MySQL端口
[root@localhost ~]# firewall-cmd --add-service=mysql
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/b1c9f3fc233f158f9c5bfdfd409f368f.jpg)
10、阻止mysql端口
[root@localhost ~]# firewall-cmd --remove-service=mysql
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/43e8fdcf3603c24f595ab90b1c5d12cb.jpg)
11、查看开放的服务
[root@localhost ~]# firewall-cmd --list-services
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/660a4306c7ba098af983a89c21087fd8.jpg)
12、开放通过tcp访问3306
[root@localhost ~]# firewall-cmd --add-port=3306/tcp
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/c27830fc6b8f522eefb827b6ab10b7be.jpg)
13、阻止通过tcp访问3306
[root@localhost ~]# firewall-cmd --remove-port=3306/tcp
14、开放通过udp访问233
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/aab0c9a46f0ce71dbaac5350cb2af9f6.jpg)
15、开放通过udp访问233
[root@localhost ~]# firewall-cmd --add-port=233/udp
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/250adf3cb96ad90775e33db97ae248b7.jpg)
16、查看开放的端口
[root@localhost ~]# firewall-cmd --list-ports
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/aef68ae95c2af00e94e905327f555b8b.jpg)
17、端口转发
(1)80端口转发到8080(Tomcat的默认端口为8080),443转发到8443(https配置的端口为8443)
[root@localhost ~]# firewall-cmd --add-forward-port=port=80:proto=tcp:toport=8080
[root@localhost ~]# firewall-cmd --add-forward-port=port=443:proto=tcp:toport=8443
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/d4668e580ad356b1fc49900e647c9658.jpg)
(2)将80端口的流量转发至192.168.11.11
[root@localhost ~]# firewall-cmd --add-forward-port=port=80:proto=tcp:toaddr=192.168.11.11
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/51132f51952491679a0708281dec87c0.jpg)
(3)将80端口的流量转发至192.168.11.11的8080端口
[root@localhost ~]# firewall-cmd --add-forward-port=port=80:proto=tcp:toaddr=192.168.11.11:toport=8080
![CentOS7 防火墙相关操作与端口配置 (收集+持续更新)](http://www.isolves.com/d/file/p/2019/11-06/8dbf7f7bc3faf2a08f9d8954dd731735.jpg)
未完 —— 待续 !
本文摘自博客