当前位置:   article > 正文

centos7_firewalld使用_firewall-cmd icmp-block

firewall-cmd icmp-block

查看命令:

firewall-cmd --list-ports

firewall-cmd --list-all
 

  1. [root@localhost ~]# firewall-cmd --list-ports
  2. 22/tcp 80/tcp
  3. [root@localhost ~]# firewall-cmd --list-all
  4. public (active)
  5. target: default
  6. icmp-block-inversion: no
  7. interfaces: ens33
  8. sources:
  9. services: ssh dhcpv6-client
  10. ports: 22/tcp 80/tcp
  11. protocols:
  12. masquerade: no
  13. forward-ports:
  14. source-ports:
  15. icmp-blocks:
  16. rich rules:

 

 

zone区

zone概念:

硬件防火墙默认一般有三个区,firewalld引入这一概念系统默认存在以下区域(根据文档自己理解,如果有误请指正):

drop:默认丢弃所有包

block:拒绝所有外部连接,允许内部发起的连接

public:指定外部连接可以进入

external:这个不太明白,功能上和上面相同,允许指定的外部连接

dmz:和硬件防火墙一样,受限制的公共连接可以进入

work:工作区,概念和workgoup一样,也是指定的外部连接允许

home:类似家庭组

internal:信任所有连接

对防火墙不算太熟悉,还没想明白public、external、dmz、work、home从功能上都需要自定义允许连接,具体使用上的区别还需高人指点

  1. [root@localhost ~]# firewall-cmd --list-all-zones
  2. block
  3. target: %%REJECT%%
  4. icmp-block-inversion: no
  5. interfaces:
  6. sources:
  7. services:
  8. ports:
  9. protocols:
  10. masquerade: no
  11. forward-ports:
  12. source-ports:
  13. icmp-blocks:
  14. rich rules:
  15. dmz
  16. target: default
  17. icmp-block-inversion: no
  18. interfaces:
  19. sources:
  20. services: ssh
  21. ports:
  22. protocols:
  23. masquerade: no
  24. forward-ports:
  25. source-ports:
  26. icmp-blocks:
  27. rich rules:
  28. drop
  29. target: DROP
  30. icmp-block-inversion: no
  31. interfaces:
  32. sources:
  33. services:
  34. ports:
  35. protocols:
  36. masquerade: no
  37. forward-ports:
  38. source-ports:
  39. icmp-blocks:
  40. rich rules:
  41. external
  42. target: default
  43. icmp-block-inversion: no
  44. interfaces:
  45. sources:
  46. services: ssh
  47. ports:
  48. protocols:
  49. masquerade: yes
  50. forward-ports:
  51. source-ports:
  52. icmp-blocks:
  53. rich rules:
  54. home
  55. target: default
  56. icmp-block-inversion: no
  57. interfaces:
  58. sources:
  59. services: ssh mdns samba-client dhcpv6-client
  60. ports:
  61. protocols:
  62. masquerade: no
  63. forward-ports:
  64. source-ports:
  65. icmp-blocks:
  66. rich rules:
  67. internal
  68. target: default
  69. icmp-block-inversion: no
  70. interfaces:
  71. sources:
  72. services: ssh mdns samba-client dhcpv6-client
  73. ports:
  74. protocols:
  75. masquerade: no
  76. forward-ports:
  77. source-ports:
  78. icmp-blocks:
  79. rich rules:
  80. public (active)
  81. target: default
  82. icmp-block-inversion: no
  83. interfaces: ens33
  84. sources:
  85. services: ssh dhcpv6-client
  86. ports: 22/tcp 80/tcp
  87. protocols:
  88. masquerade: no
  89. forward-ports:
  90. source-ports:
  91. icmp-blocks:
  92. rich rules:
  93. trusted
  94. target: ACCEPT
  95. icmp-block-inversion: no
  96. interfaces:
  97. sources:
  98. services:
  99. ports:
  100. protocols:
  101. masquerade: no
  102. forward-ports:
  103. source-ports:
  104. icmp-blocks:
  105. rich rules:
  106. work
  107. target: default
  108. icmp-block-inversion: no
  109. interfaces:
  110. sources:
  111. services: ssh dhcpv6-client
  112. ports:
  113. protocols:
  114. masquerade: no
  115. forward-ports:
  116. source-ports:
  117. icmp-blocks:
  118. rich rules:

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

声明:本文内容由网友自发贡献,不代表【wpsshop博客】立场,版权归原作者所有,本站不承担相应法律责任。如您发现有侵权的内容,请联系我们。转载请注明出处:https://www.wpsshop.cn/w/花生_TL007/article/detail/552559
推荐阅读
相关标签
  

闽ICP备14008679号