• 查看防火墙某个端口是否开放

    firewall-cmd –query-port=3306/tcp

  • 开放防火墙端口3306

    firewall-cmd –zone=public –add-port=3306/tcp –permanent

    注意:开放端口后要重启防火墙生效

  • 重启防火墙

    systemctl restart firewalld

  • 关闭防火墙端口

    firewall-cmd –remove-port=3306/tcp –permanent

  • 查看防火墙状态

    systemctl status firewalld

  • 关闭防火墙

    systemctl stop firewalld

  • 打开防火墙

    systemctl start firewalld

  • 开放一段端口

    firewall-cmd –zone=public –add-port=40000-45000/tcp –permanent

  • 查看开放的端口列表

    firewall-cmd –zone=public –list-ports