{"id":458,"date":"2024-08-07T15:34:55","date_gmt":"2024-08-07T07:34:55","guid":{"rendered":"https:\/\/thereisno.top:4430\/?p=458"},"modified":"2024-08-13T18:14:43","modified_gmt":"2024-08-13T10:14:43","slug":"centos7%e6%b7%bb%e5%8a%a0%e5%88%a0%e9%99%a4%e7%ad%96-%e9%bb%91%e5%90%8d%e5%8d%95","status":"publish","type":"post","link":"https:\/\/thereisno.top\/?p=458","title":{"rendered":"Centos7\u6dfb\u52a0\u5220\u9664\u7b56\u7565\u9ed1\u540d\u5355"},"content":{"rendered":"\n<p>\u5f00\u542f\u9632\u706b\u5899\uff1asystemctl start firewalld<br>\u67e5\u770b\u5f00\u653e\u7684\u7aef\u53e3\u548c\u670d\u52a1\u4ee5\u53ca\u5c4f\u853d\u7684IP\uff1afirewall-cmd &#8211;zone=public &#8211;list-all<br>\u67e5\u770b\u7cfb\u7edf\u4e2d\u67e5\u770b\u7cfb\u7edf\u4e2d\u53ef\u7528\u7684\u670d\u52a1\uff1a&nbsp; firewall-cmd &#8211;get-services<\/p>\n\n\n\n<p>\u5141\u8bb8\u5168\u90e8\u7f51\u6bb5\u8bbf\u95ee\u672c\u673a80\u7aef\u53e3\uff1afirewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-port=80\/tcp&nbsp; (&#8211;permanent\u6c38\u4e45\u751f\u6548\uff0c\u6ca1\u6709\u6b64\u53c2\u6570\u91cd\u542f\u540e\u5931\u6548)<br>\u67e5\u770b\uff1a&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; firewall-cmd &#8211;zone= public &#8211;query-port=80\/tcp<\/p>\n\n\n\n<p>### \u6dfb\u52a0\u89c4\u5219\u5141\u8bb8\u89c4\u5219\uff1a<br>\u5141\u8bb8\u5168\u90e8\u7f51\u6bb5\u8bbf\u95ee\u672c\u673a\u7aef\u53e3\u6bb5\uff1a&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-port=5060-5061\/udp<br>\u5141\u8bb8[\u6307\u5b9aIP]\u8bbf\u95ee\u672c\u673a10050:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8221;rule family=&#8221;ipv4&#8243; source address=&#8221;172.17.134.13&#8243; port protocol=&#8221;tcp&#8221; port=&#8221;10050&#8243; accept&#8221;<\/p>\n\n\n\n<p>\u5141\u8bb8[\u6307\u5b9aIP]\u8bbf\u95ee\u672c\u673a\u5168\u90e8tcp\u7aef\u53e3\uff1a&nbsp; &nbsp; &nbsp;firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8221;rule family=&#8221;ipv4&#8243; source address=&#8221;172.17.134.13&#8243; port protocol=&#8221;tcp&#8221; port=&#8221;0-65535&#8243; accept&#8221;<\/p>\n\n\n\n<p>\u5141\u8bb8[\u6307\u5b9aIP]\u8bbf\u95ee\u672c\u673a\u5168\u90e8\u7aef\u53e3\uff1a&nbsp; &nbsp; &nbsp;&nbsp;&nbsp; firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8221;rule family=&#8221;ipv4&#8243; source address=&#8221;172.17.172.236&#8243;&nbsp; accept&#8221;<\/p>\n\n\n\n<p>\u5141\u8bb8[\u6307\u5b9aIP\u6bb5]\u8bbf\u95ee\u672c\u673a\u5168\u90e8\u7aef\u53e3\uff1a&nbsp;&nbsp; firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8221;rule family=&#8221;ipv4&#8243; source address=&#8221;192.168.1.0\/24&#8243; accept&#8221;<\/p>\n\n\n\n<p>\u5141\u8bb8[\u6307\u5b9aIP\u6bb5]\u8bbf\u95ee\u672c\u673a8080-8090\u7aef\u53e3\uff1a firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8217;rule family=&#8221;ipv4&#8243; source address=&#8221;192.168.1.0\/24&#8243; port protocol=&#8221;tcp&#8221; port=&#8221;8080-8090&#8243; accept&#8217;<\/p>\n\n\n\n<p>### \u6dfb\u52a0\u7981\u6b62\u89c4\u5219\uff1a<br>\u7981\u6b62[\u6307\u5b9aIP]\u8bbf\u95ee\u672c\u673a8080\u7aef\u53e3\uff1afirewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8217;rule family=&#8221;ipv4&#8243; source address=&#8221;192.168.1.1&#8243; port protocol=&#8221;tcp&#8221; port=&#8221;8080&#8243; reject&#8217;<br>\u5c4f\u853d[\u6307\u5b9aIP](reject)\uff1a&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8221;rule family=ipv4 source address=43.229.53.61 reject&#8221;<br>\u5c4f\u853d[\u6307\u5b9aIP\u6bb5](drop):&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8221;rule family=ipv4 source address=&#8217;x.x.x.x\/24&#8242;&nbsp; drop&#8221;<\/p>\n\n\n\n<p>###\u5220\u9664\u6dfb\u52a0\u7684\u89c4\u5219:<\/p>\n\n\n\n<p>\u5220\u9664\u7aef\u53e3\uff1a&nbsp; &nbsp;firewall-cmd &#8211;permanent &#8211;zone=public &#8211;remove-port=8080\/tcp&nbsp;<\/p>\n\n\n\n<p>\u5220\u9664IP+\u7aef\u53e3\uff1afirewall-cmd &#8211;permanent &#8211;zone=public &#8211;remove-rich-rule=&#8221;rule family=&#8221;ipv4&#8243; source address=&#8221;10.0.5.0\/24&#8243; port protocol=&#8221;tcp&#8221; port=&#8221;10050&#8243; accept&#8221;<\/p>\n\n\n\n<p>***\u6dfb\u52a0\u6216\u8005\u4fee\u6539\u5b8c\u89c4\u5219\u540e\u5fc5\u987b\u70ed\u52a0\u8f7d\u624d\u80fd\u751f\u6548\uff1afirewall-cmd &#8211;reload<br>\u67e5\u770b\u5c4f\u853d\u7ed3\u679c\uff1afirewall-cmd &#8211;list-rich-rules<br>\u56e0\u4e3a\u5728\/usr\/lib\/firewalld\/services\/\u4e2d\u4e8b\u5148\u5b9a\u4e49\u4e86ssh.xml\u7684\u76f8\u5e94\u7684\u89c4\u5219<\/p>\n\n\n\n<p>\u6765\u81ea &lt;<a href=\"https:\/\/www.cnblogs.com\/faithH\/p\/11811286.html\">https:\/\/www.cnblogs.com\/faithH\/p\/11811286.html<\/a>&gt;<\/p>\n\n\n\n<p>1.drop\u7981\u6b62\u7279\u5b9aip\u8fde\u63a5ssh\/22\u670d\u52a1<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8221;rule family=ipv4 source address=&#8217;x.x.x.x\/24&#8242; service name=&#8217;ssh&#8217; drop&#8221;<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;reload&nbsp;##\u91cd\u65b0\u52a0\u8f7d\u9632\u706b\u5899\u914d\u7f6e\uff0c\u4e0d\u7136firewall-cmd &#8211;list-all-zones\u4e0d\u4f1a\u663e\u793a\u521a\u52a0\u4e0a\u7684\u89c4\u5219<\/p>\n\n\n\n<p>2.reject\u7981\u6b62\u7279\u5b9aip\u8fde\u63a5ssh\/22\u670d\u52a1<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8221;rule family=&#8217;ipv4&#8242; source address=&#8217;x.x.x.x\/24&#8242; service name=&#8217;ssh&#8217; reject&#8221;<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8221;rule family=&#8217;ipv4&#8242; source address=&#8217;x.x.x.x\/24&#8242; port port=22 protocol=tcp reject&#8221;<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;reload<\/p>\n\n\n\n<p>3.accept\u8fd0\u884c\u7279\u5b9aip\u8fde\u63a5ssh\/22\u670d\u52a1<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-rich-rule=&#8221;rule family=ipv4 source address=&#8217;x.x.x.x\/24&#8242; port port=22 procotol=tcp accept&#8221;<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;reload<\/p>\n\n\n\n<p>\u9632\u706b\u5899\u5185\u7684\u7b56\u7565\u52a8\u4f5c\u6709DROP\u548cREJECT\u4e24\u79cd\uff0c\u533a\u522b\u5982\u4e0b\uff1a<\/p>\n\n\n\n<p>1\u3001DROP\u52a8\u4f5c\u53ea\u662f\u7b80\u5355\u7684\u76f4\u63a5\u4e22\u5f03\u6570\u636e\uff0c\u5e76\u4e0d\u53cd\u9988\u4efb\u4f55\u56de\u5e94\u3002\u9700\u8981Client\u7b49\u5f85\u8d85\u65f6\uff0cClient\u5bb9\u6613\u53d1\u73b0\u81ea\u5df1\u88ab\u9632\u706b\u5899\u6240\u963b\u6321\u3002<\/p>\n\n\n\n<p>2\u3001REJECT\u52a8\u4f5c\u5219\u4f1a\u66f4\u4e3a\u793c\u8c8c\u7684\u8fd4\u56de\u4e00\u4e2a\u62d2\u7edd(\u7ec8\u6b62)\u6570\u636e\u5305(TCP FIN\u6216UDP-ICMP-PORT-UNREACHABLE)\uff0c\u660e\u786e\u7684\u62d2\u7edd\u5bf9\u65b9\u7684\u8fde\u63a5\u52a8\u4f5c\u3002\u8fde\u63a5\u9a6c\u4e0a\u65ad\u5f00\uff0cClient\u4f1a\u8ba4\u4e3a\u8bbf\u95ee\u7684\u4e3b\u673a\u4e0d\u5b58\u5728\u3002REJECT\u5728IPTABLES\u91cc\u9762\u6709\u4e00\u4e9b\u8fd4\u56de\u53c2\u6570\uff0c\u53c2\u6570\u5982\u4e0b\uff1aICMP port-unreachable\u3001ICMP&nbsp;echo-reply \u6216\u662f tcp-reset\uff08\u8fd9\u4e2a\u5c01\u5305\u4f1a\u8981\u6c42\u5bf9\u65b9\u5173\u95ed\u8054\u673a\uff09\uff0c\u8fdb\u884c\u5b8c\u6b64\u5904\u7406\u52a8\u4f5c\u540e\uff0c\u5c06\u4e0d\u518d\u6bd4\u5bf9\u5176\u5b83\u89c4\u5219\uff0c\u76f4\u63a5\u4e2d\u65ad\u8fc7\u6ee4\u7a0b\u5e8f\u3002<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\u81f3\u4e8e\u4f7f\u7528DROP\u8fd8\u662fREJECT\u66f4\u5408\u9002\u4e00\u76f4\u672a\u6709\u5b9a\u8bba\uff0c\u56e0\u4e3a\u7684\u786e\u4e8c\u8005\u90fd\u6709\u9002\u7528\u7684\u573a\u5408\u3002REJECT\u662f\u4e00\u79cd\u66f4\u7b26\u5408\u89c4\u8303\u7684\u5904\u7406\u65b9\u5f0f\uff0c\u5e76\u4e14\u5728\u53ef\u63a7\u7684\u7f51\u7edc\u73af\u5883\u4e2d\uff0c\u66f4\u6613\u4e8e\u8bca\u65ad\u548c\u8c03\u8bd5\u7f51\u7edc\/\u9632\u706b\u5899\u6240\u4ea7\u751f\u7684\u95ee\u9898\uff1b\u800cDROP\u5219\u63d0\u4f9b\u4e86\u66f4\u9ad8\u7684\u9632\u706b\u5899\u5b89\u5168\u6027\u548c\u7a0d\u8bb8\u7684\u6548\u7387\u63d0\u9ad8\uff0c\u4f46\u662f\u7531\u4e8eDROP\u4e0d\u5f88\u89c4\u8303(\u4e0d\u5f88\u7b26\u5408TCP\u8fde\u63a5\u89c4\u8303)\u7684\u5904\u7406\u65b9\u5f0f\uff0c\u53ef\u80fd\u4f1a\u5bf9\u4f60\u7684\u7f51\u7edc\u9020\u6210\u4e00\u4e9b\u4e0d\u53ef\u9884\u671f\u6216\u96be\u4ee5\u8bca\u65ad\u7684\u95ee\u9898\u3002\u56e0\u4e3aDROP\u867d\u7136\u5355\u65b9\u9762\u7684\u4e2d\u65ad\u4e86\u8fde\u63a5\uff0c\u4f46\u662f\u5e76\u4e0d\u8fd4\u56de\u4efb\u4f55\u62d2\u7edd\u4fe1\u606f\uff0c\u56e0\u6b64\u8fde\u63a5\u5ba2\u6237\u7aef\u5c06\u88ab\u52a8\u7684\u7b49\u5230tcp session\u8d85\u65f6\u624d\u80fd\u5224\u65ad\u8fde\u63a5\u662f\u5426\u6210\u529f\uff0c\u8fd9\u6837\u65e9\u4f01\u4e1a\u5185\u90e8\u7f51\u7edc\u4e2d\u4f1a\u6709\u4e00\u4e9b\u95ee\u9898\uff0c\u4f8b\u5982\u67d0\u4e9b\u5ba2\u6237\u7aef\u7a0b\u5e8f\u6216\u5e94\u7528\u9700\u8981IDENT\u534f\u8bae\u652f\u6301(TCP Port 113, RFC 1413)\uff0c\u5982\u679c\u9632\u706b\u5899\u672a\u7ecf\u901a\u77e5\u7684\u5e94\u7528\u4e86DROP\u89c4\u5219\u7684\u8bdd\uff0c\u6240\u6709\u7684\u540c\u7c7b\u8fde\u63a5\u90fd\u4f1a\u5931\u8d25\uff0c\u5e76\u4e14\u7531\u4e8e\u8d85\u65f6\u65f6\u95f4\uff0c\u5c06\u5bfc\u81f4\u96be\u4ee5\u5224\u65ad\u662f\u7531\u4e8e\u9632\u706b\u5899\u5f15\u8d77\u7684\u95ee\u9898\u8fd8\u662f\u7f51\u7edc\u8bbe\u5907\/\u7ebf\u8def \u6545\u969c\u3002<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\u4e00\u70b9\u4e2a\u4eba\u7ecf\u9a8c\uff0c\u5728\u90e8\u7f72\u9632\u706b\u5899\u65f6\uff0c\u5982\u679c\u662f\u9762\u5411\u4f01\u4e1a\u5185\u90e8(\u6216\u90e8\u5206\u53ef\u4fe1\u4efb\u7f51\u7edc)\uff0c\u90a3\u4e48\u6700\u597d\u4f7f\u7528\u66f4\u7ec5\u58ebREJECT\u65b9\u6cd5\uff0c\u5bf9\u4e8e\u9700\u8981\u7ecf\u5e38\u53d8\u66f4\u6216\u8c03\u8bd5\u89c4\u5219\u7684\u7f51\u7edc\u4e5f\u662f\u5982\u6b64\uff1b\u800c\u5bf9\u4e8e\u9762\u5411\u5371\u9669\u7684Internet\/Extranet\u7684\u9632\u706b\u5899\uff0c\u5219\u6709\u5fc5\u8981\u4f7f\u7528\u66f4\u4e3a\u7c97\u66b4\u4f46\u662f\u5b89\u5168\u7684DROP\u65b9\u6cd5\uff0c\u53ef\u4ee5\u5728\u4e00\u5b9a\u7a0b\u5ea6\u4e0a\u5ef6\u7f13******\u7684\u8fdb\u5ea6(\u548c\u96be\u5ea6\uff0c\u81f3\u5c11\uff0cDROP\u53ef\u4ee5\u4f7f\u4ed6\u4eec\u8fdb\u884cTCP-Connect\u65b9\u5f0f\u7aef\u53e3\u626b\u63cf\u65f6\u95f4\u66f4\u957f)\u3002<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\u4fee\u6539\u9632\u706b\u5899\u914d\u7f6e\u6587\u4ef6\u4e4b\u524d\uff0c\u9700\u8981\u5bf9\u4e4b\u524d\u9632\u706b\u5899\u3010\/etc\/firewalld\/zones\/public.xml\u3011\u505a\u597d\u5907\u4efd<\/p>\n\n\n\n<p>\u91cd\u542f\u9632\u706b\u5899\u540e\uff0c\u9700\u8981\u786e\u8ba4\u9632\u706b\u5899\u72b6\u6001\u548c\u9632\u706b\u5899\u89c4\u5219\u662f\u5426\u52a0\u8f7d\uff0c\u82e5\u91cd\u542f\u5931\u8d25\u6216\u89c4\u5219\u52a0\u8f7d\u5931\u8d25\uff0c\u5219\u6240\u6709\u8bf7\u6c42\u90fd\u4f1a\u88ab\u9632\u706b\u5899\u3002<\/p>\n\n\n\n<p>1.firewall-cmd &#8211;state&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;#\u67e5\u770bfirewall\u7684\u72b6\u6001<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;list-all&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;#\u67e5\u770b\u9632\u706b\u5899\u89c4\u5219\uff08\u53ea\u663e\u793a\/etc\/firewalld\/zones\/public.xml\u4e2d\u9632\u706b\u5899\u7b56\u7565\uff09<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;list-all-zones&nbsp;&nbsp;#\u67e5\u770b\u6240\u6709\u7684\u9632\u706b\u5899\u7b56\u7565\uff08\u5373\u663e\u793a\/etc\/firewalld\/zones\/\u4e0b\u7684\u6240\u6709\u7b56\u7565\uff09<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;reload&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;#\u91cd\u65b0\u52a0\u8f7d\u914d\u7f6e\u6587\u4ef6<\/p>\n\n\n\n<p>2\u3001\u5173\u95edfirewall\uff1a<\/p>\n\n\n\n<p>&nbsp;&nbsp;systemctl stop firewalld.service&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;#\u505c\u6b62firewall<\/p>\n\n\n\n<p>&nbsp;&nbsp;systemctl disable firewalld.service&nbsp;&nbsp;&nbsp;#\u7981\u6b62firewall\u5f00\u673a\u542f\u52a8<\/p>\n\n\n\n<p>&nbsp;&nbsp;firewall-cmd &#8211;state&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;#\u67e5\u770b\u9ed8\u8ba4\u9632\u706b\u5899\u72b6\u6001\uff08\u5173\u95ed\u540e\u663e\u793anotrunning\uff0c\u5f00\u542f\u540e\u663e\u793arunning\uff09<\/p>\n\n\n\n<p>3\u3001firewalld\u7684\u57fa\u672c\u4f7f\u7528<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u542f\u52a8\uff1a systemctl start firewalld<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u67e5\u770b\u72b6\u6001\uff1a systemctl status firewalld<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u505c\u6b62\uff1a systemctl disable firewalld<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u7981\u7528\uff1a systemctl stop firewalld<\/p>\n\n\n\n<p>4.systemctl\u662fCentOS7\u7684\u670d\u52a1\u7ba1\u7406\u5de5\u5177\u4e2d\u4e3b\u8981\u7684\u5de5\u5177\uff0c\u5b83\u878d\u5408\u4e4b\u524dservice\u548cchkconfig\u7684\u529f\u80fd\u4e8e\u4e00\u4f53\u3002<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u542f\u52a8\u4e00\u4e2a\u670d\u52a1\uff1asystemctl start firewalld.service<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u5173\u95ed\u4e00\u4e2a\u670d\u52a1\uff1asystemctl stop firewalld.service<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u91cd\u542f\u4e00\u4e2a\u670d\u52a1\uff1asystemctl restart firewalld.service<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u663e\u793a\u4e00\u4e2a\u670d\u52a1\u7684\u72b6\u6001\uff1asystemctl status firewalld.service<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u5728\u5f00\u673a\u65f6\u542f\u7528\u4e00\u4e2a\u670d\u52a1\uff1asystemctl&nbsp;enable&nbsp;firewalld.service<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u5728\u5f00\u673a\u65f6\u7981\u7528\u4e00\u4e2a\u670d\u52a1\uff1asystemctl disable firewalld.service<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u67e5\u770b\u670d\u52a1\u662f\u5426\u5f00\u673a\u542f\u52a8\uff1asystemctl is-enabled firewalld.service<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u67e5\u770b\u5df2\u542f\u52a8\u7684\u670d\u52a1\u5217\u8868\uff1asystemctl list-unit-files|grep&nbsp;enabled<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u67e5\u770b\u542f\u52a8\u5931\u8d25\u7684\u670d\u52a1\u5217\u8868\uff1asystemctl &#8211;failed<\/p>\n\n\n\n<p>5.\u914d\u7f6efirewalld-cmd<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u67e5\u770b\u7248\u672c\uff1a firewall-cmd &#8211;version<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u67e5\u770b\u5e2e\u52a9\uff1a firewall-cmd &#8211;help<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u663e\u793a\u72b6\u6001\uff1a firewall-cmd &#8211;state<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u67e5\u770b\u6240\u6709\u6253\u5f00\u7684\u7aef\u53e3\uff1a firewall-cmd &#8211;zone=public &#8211;list-ports<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u66f4\u65b0\u9632\u706b\u5899\u89c4\u5219\uff1a firewall-cmd &#8211;reload<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u67e5\u770b\u533a\u57df\u4fe1\u606f:&nbsp; firewall-cmd &#8211;get-active-zones<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u67e5\u770b\u6307\u5b9a\u63a5\u53e3\u6240\u5c5e\u533a\u57df\uff1a firewall-cmd &#8211;get-zone-of-interface=eth0<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u62d2\u7edd\u6240\u6709\u5305\uff1afirewall-cmd &#8211;panic-on<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u53d6\u6d88\u62d2\u7edd\u72b6\u6001\uff1a firewall-cmd &#8211;panic-off<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u67e5\u770b\u662f\u5426\u62d2\u7edd\uff1a firewall-cmd &#8211;query-panic<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5f00\u542f\u9632\u706b\u5899\uff1asystemctl start firewalld\u67e5\u770b\u5f00\u653e\u7684\u7aef\u53e3\u548c\u670d\u52a1\u4ee5\u53ca\u5c4f\u853d\u7684IP\uff1afirewa &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/thereisno.top\/?p=458\" class=\"more-link\">\u7ee7\u7eed\u9605\u8bfb<span class=\"screen-reader-text\">\u201cCentos7\u6dfb\u52a0\u5220\u9664\u7b56\u7565\u9ed1\u540d\u5355\u201d<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[10],"class_list":["post-458","post","type-post","status-publish","format-standard","hentry","category-linux","tag-linux"],"_links":{"self":[{"href":"https:\/\/thereisno.top\/index.php?rest_route=\/wp\/v2\/posts\/458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thereisno.top\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thereisno.top\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thereisno.top\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thereisno.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=458"}],"version-history":[{"count":2,"href":"https:\/\/thereisno.top\/index.php?rest_route=\/wp\/v2\/posts\/458\/revisions"}],"predecessor-version":[{"id":552,"href":"https:\/\/thereisno.top\/index.php?rest_route=\/wp\/v2\/posts\/458\/revisions\/552"}],"wp:attachment":[{"href":"https:\/\/thereisno.top\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thereisno.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thereisno.top\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}