1烙肺、開(kāi)放端口
firewall-cmd --zone=public --add-port=5672/tcp --permanent # 開(kāi)放5672端口
firewall-cmd --zone=public --remove-port=5672/tcp --permanent #關(guān)閉5672端口
firewall-cmd --reload # 配置立即生效
2护侮、查看防火墻所有開(kāi)放的端口
firewall-cmd --zone=public --list-ports
3.钻趋、關(guān)閉防火墻
如果要開(kāi)放的端口太多琐鲁,嫌麻煩,可以關(guān)閉防火墻绽快,安全性自行評(píng)估
systemctl stop firewalld.service
4碱屁、查看防火墻狀態(tài)
firewall-cmd --state
5、查看監(jiān)聽(tīng)的端口
netstat -lnpt
6客年、檢查端口被哪個(gè)進(jìn)程占用
netstat -lnpt |grep 5672
7霞幅、查看進(jìn)程的詳細(xì)信息
ps 6832
8、中止進(jìn)程
kill -9 6832
9量瓜、限制某個(gè)IP地址訪問(wèn)某端口
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="192.168.0.200" port protocol="tcp" port="80" reject"
執(zhí)行完后要執(zhí)行 reload
查看限制
firewall-cmd --zone=public --list-rich-rules
解除限制:
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="192.168.0.200" port protocol="tcp" port="80" accept"
10司恳、 限制某個(gè)IP地址段訪問(wèn)
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="10.0.0.0/24" port protocol="tcp" port="80" reject"
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="10.0.0.0/24" port protocol="tcp" port="80" accept"
firewall-cmd --reload