一.常用设置流程:
分为如下步骤:
1--为添加规则或者批量添加规则
2--使添加规则生效
3--查看是否结果生效
1-设置规则
1.允许“10.51.54.1”访问本机
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="10.51.54.1" port protocol="tcp" port="9201" accept"
1.1批量添加网段
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="10.51.54.1/24" port protocol="tcp" port="9201" accept"
1.2暴露端口
#开启某个端口(所有IP可访问)
firewall-cmd --permanent --zone=public --add-port=80/tcp
#删除策略:
firewall-cmd --permanent --zone=public --remove-port=80/tcp
1.3批量添加屏蔽ip网段
firewall-cmd --permanent --zone="public" --add-rich-rule="rule family="ipv4" source address="10.30.125.0/24" drop"
1.4屏蔽固定ip
firewall-cmd --permanent --zone="public" --add-rich-rule="rule family="ipv4" source