html tool

2019年3月28日星期四

firewall-cmd 规则修改



参考:https://blog.51cto.com/andyxu/2137046


添加指定ip的指定端口访问
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="10.4.2.190" port port="9210" protocol="tcp" accept"

即rich rules
允许192.168.2.208主机的所有流量
firewall-cmd --zone=drop --add-rich-rule="rule family="ipv4" source address="192.168.2.208" accept"
允许192.168.2.208主机的icmp协议,即允许192.168.2.208主机ping
firewall-cmd --add-rich-rule="rule family="ipv4" source address="192.168.2.208" protocol value="icmp" accept"
取消允许192.168.2.208主机的所有流量
firewall-cmd --zone=drop --remove-rich-rule="rule family="ipv4" source address="192.168.2.208" accept"
允许192.168.2.208主机访问ssh服务
firewall-cmd --zone=drop --add-rich-rule="rule family="ipv4" source address="192.168.2.208" service name="ssh" accept"

没有评论:

发表评论