admin管理员组

文章数量:1642351

场景1、允许指定IP访问本机指定端口

firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.254.135/24" port protocol="tcp" port="22" accept'

场景2、允许指定IP段访问本机指定端口

firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.254.0/25" port protocol="tcp" port="22" accept'

场景3、拒绝指定IP访问本机指定端口

firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.254.135/24" port protocol="tcp" port="22" reject'

场景4、拒绝指定IP段访问本机指定端口

firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.254.0/24" port protocol="tcp" port="22" reject'

配置完成以后需要执行

firewall-cmd --reload
systemctl restart firewalld

查看规则

firewall-cmd --list-all

firewall启用禁ping

firewall-cmd --permanent --add-rich-rule='rule protocol value=icmp drop'

禁止某些IPping本机

firewall-cmd --permanent --add-rich-rule='rule family="ipv4" protocol value="icmp"  source  address="192.168.254.135" reject'

允许指定IPping本机

firewall-cmd --permanent --add-rich-rule='rule family="ipv4" protocol value="icmp"  source NOT address="192.168.254.135" reject'

tips:

如不需要指定端口和协议,将上述命令中的端口和协议去掉即可

如需去掉规则,执行上述命令,并将add换成remove即可

本文标签: 策略系统Linuxfirewalld