ÔõÑùʹÓ÷À»ðǽÉèÖÃCentOSЧÀÍÆ÷µÄÍøÂç´«ÊäÇå¾²
ÔõÑùʹÓ÷À»ðǽÉèÖÃcentosЧÀÍÆ÷µÄÍøÂç´«ÊäÇå¾²
·À»ðǽÊÇЧÀÍÆ÷Çå¾²ÖеÄÖ÷Òª×é³É²¿·ÖÖ®Ò»£¬Ëü¿ÉÒÔ×ÊÖúÎÒÃǹýÂ˵ô¶ñÒâµÄÍøÂçÁ÷Á¿£¬±£»¤Ð§ÀÍÆ÷ÃâÊÜÈëÇֺ͹¥»÷¡£±¾ÎĽ«ÏÈÈÝÔõÑùʹÓ÷À»ðǽÉèÖÃcentosЧÀÍÆ÷µÄÍøÂç´«ÊäÇå¾²£¬²¢¸½ÉÏ´úÂëʾÀý¡£
¼ì²é·À»ðǽ״̬
ÔÚ×îÏÈÉèÖÃ֮ǰ£¬ÎÒÃÇÏÈҪȷÈÏ·À»ðǽÊÇ·ñÒѾÆôÓá£ÔÚÖÕ¶ËÖÐÊäÈëÒÔÏÂÏÂÁîÀ´¼ì²é·À»ðǽ״̬£º
sudo systemctl status firewalld
µÇ¼ºó¸´ÖÆ
ÈôÊÇÊä³öÏÔʾ”active (running)”£¬ÔòÌåÏÖ·À»ðǽÒѾÆôÓã»ÈôÊÇÊä³öÏÔʾ”inactive (dead)”£¬ÔòÌåÏÖ·À»ðǽδÆôÓá£
ÆôÓ÷À»ðǽ
ÈôÊÇ·À»ðǽδÆôÓã¬ÎÒÃÇÐèÒªÏÈÆôÓÃËü¡£ÔÚÖÕ¶ËÖÐÊäÈëÒÔÏÂÏÂÁîÀ´ÆôÓ÷À»ðǽ£º
sudo systemctl start firewalld
µÇ¼ºó¸´ÖÆ
ÉèÖÃĬÈÏ·À»ðǽ¹æÔò
ÔÚÉèÖÃÏêϸµÄÍøÂç´«ÊäÇå¾²¹æÔò֮ǰ£¬ÎÒÃÇÏÈÉèÖÃһЩĬÈϵķÀ»ðǽ¹æÔò£¬ÒÔ×èֹδÊÚȨµÄ»á¼û¡£ÔÚÖÕ¶ËÖÐÊäÈëÒÔÏÂÏÂÁîÀ´ÉèÖÃĬÈϹæÔò£º
sudo firewall-cmd --set-default-zone=public sudo firewall-cmd --permanent --zone=public --remove-service=dhcpv6-client sudo firewall-cmd --permanent --zone=public --remove-service=dhcpv6-server sudo firewall-cmd --reload
µÇ¼ºó¸´ÖÆ
ÒÔÉÏÏÂÁÉèÖÃĬÈϵķÀ»ðǽÇøÓòΪ”public”£¬²¢ÇÒÒƳýÁËÓëDHCPv6¿Í»§¶ËºÍЧÀÍÆ÷Ïà¹ØµÄЧÀÍ¡£
¿ª·ÅÐèÒªµÄ¶Ë¿Ú
½ÓÏÂÀ´£¬ÎÒÃÇÐèÒª¿ª·ÅЧÀÍÆ÷ÉÏÐèҪʹÓõĶ˿ڡ£ÔÚÖÕ¶ËÖÐÊäÈëÒÔÏÂÏÂÁîÀ´¿ª·Å¶Ë¿Ú£¬ÒÔʾÀý¶Ë¿Ú80ΪÀý£º
sudo firewall-cmd --permanent --zone=public --add-port=80/tcp sudo firewall-cmd --permanent --zone=public --add-port=80/udp sudo firewall-cmd --reload
µÇ¼ºó¸´ÖÆ
ÒÔÉÏÏÂÁÓÀÊÀ¿ª·Å80¶Ë¿Ú£¬Ö§³ÖTCPºÍUDPÐÒé¡£
ÆÁÕϲ»ÐèÒªµÄ¶Ë¿Ú
ΪÁËÔöÌíЧÀÍÆ÷µÄÇå¾²ÐÔ£¬ÎÒÃÇ¿ÉÒÔÆÁÕϲ»ÐèÒªµÄ¶Ë¿Ú£¬ÒÔ±ÜÃâ¹¥»÷ÕßʹÓÃËüÃǾÙÐй¥»÷¡£ÔÚÖÕ¶ËÖÐÊäÈëÒÔÏÂÏÂÁîÀ´ÆÁÕÏÖ¸¶¨µÄ¶Ë¿Ú£¬ÒÔʾÀý¶Ë¿Ú22ΪÀý£º
sudo firewall-cmd --permanent --zone=public --remove-port=22/tcp sudo firewall-cmd --permanent --zone=public --remove-port=22/udp sudo firewall-cmd --reload
µÇ¼ºó¸´ÖÆ
ÒÔÉÏÏÂÁÓÀÊÀÆÁÕÏ22¶Ë¿ÚµÄTCPºÍUDPÐÒé¡£
ÉèÖ÷À»ðǽ¹æÔò
³ýÁË¿ª·ÅºÍÆÁÕ϶˿ÚÖ®Í⣬ÎÒÃÇ»¹¿ÉÒÔƾ֤×Ô¼ºµÄÐèÇóÉèÖøüÖØ´óµÄ·À»ðǽ¹æÔò¡£ÔÚÖÕ¶ËÖÐÊäÈëÒÔÏÂÏÂÁîÀ´ÉèÖùæÔò£¬ÒÔÔÊÐíÖ¸¶¨µÄIPµØµã»á¼ûЧÀÍÆ÷¶Ë¿Ú£º
sudo firewall-cmd --permanent --zone=public --add-rich-rule="rule family='ipv4' source address='192.168.0.10' port protocol='tcp' port='3306' accept" sudo firewall-cmd --reload
µÇ¼ºó¸´ÖÆ
ÒÔÉÏÏÂÁÓÀÊÀÔÊÐíIPµØµãΪ192.168.0.10µÄÖ÷ʱ»ú¼ûЧÀÍÆ÷µÄ3306¶Ë¿Ú¡£
¼ì²é·À»ðǽ¹æÔò
ÔÚÉèÖÃÍê³Éºó£¬ÎÒÃÇ¿ÉÒÔʹÓÃÒÔÏÂÏÂÁîÀ´Éó²éÄ¿½ñµÄ·À»ðǽ¹æÔò£º
sudo firewall-cmd --zone=public --list-all
µÇ¼ºó¸´ÖÆ
ÒÔÉÏÏÂÁÏÔʾĿ½ñ”public”ÇøÓòµÄËùÓзÀ»ðǽ¹æÔò¡£
×ܽ᣺
±¾ÎÄÏÈÈÝÁËÔõÑùʹÓ÷À»ðǽÉèÖÃcentosЧÀÍÆ÷µÄÍøÂç´«ÊäÇå¾²¡£Í¨¹ýÉèÖ÷À»ðǽ¹æÔò£¬¿ª·ÅÐèÒªµÄ¶Ë¿Ú£¬ÆÁÕϲ»ÐèÒªµÄ¶Ë¿Ú£¬ÒÔ¼°ÉèÖÃÖØ´óµÄ¹æÔò£¬ÎÒÃÇ¿ÉÒÔÔöǿЧÀÍÆ÷µÄÍøÂçÇå¾²ÐÔ¡£Çëƾ֤ÏÖʵÐèÇóÀ´Ñ¡ÔñºÏÊʵķÀ»ðǽ¹æÔò£¬²¢ÔÚÉèÖÃÍê³Éºó¼ì²é¹æÔòÊÇ·ñÉúЧ¡£
ÒÔÉϾÍÊÇÔõÑùʹÓ÷À»ðǽÉèÖÃCentOSЧÀÍÆ÷µÄÍøÂç´«ÊäÇå¾²µÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡