centos7防火墻怎么樣關(guān)閉
centos7防火墻怎么樣關(guān)閉
有時(shí)候不想用centos 7 防火墻了,想要關(guān)閉該怎么辦呢?下面由學(xué)習(xí)啦小編給你做出詳細(xì)的centos 7防火墻 關(guān)閉方法介紹!希望對(duì)你有幫助!
centos 7防火墻 關(guān)閉方法一:
1、關(guān)閉firewall:
systemctl stop firewalld.service #停止firewall
systemctl disable firewalld.service #禁止firewall開機(jī)啟動(dòng)
firewall-cmd --state #查看默認(rèn)防火墻狀態(tài)(關(guān)閉后顯示notrunning,開啟后顯示running)
2、iptables防火墻(這里iptables已經(jīng)安裝,下面進(jìn)行配置)
vi/etc/sysconfig/iptables #編輯防火墻配置文件
# sampleconfiguration for iptables service
# you can edit thismanually or use system-config-firewall
# please do not askus to add additional ports/services to this default configuration
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT[0:0]
:OUTPUT ACCEPT[0:0]
-A INPUT -m state--state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -jACCEPT
-A INPUT -i lo -jACCEPT
-A INPUT -p tcp -mstate --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -jACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 8080-j ACCEPT
-A INPUT -j REJECT--reject-with icmp-host-prohibited
-A FORWARD -jREJECT --reject-with icmp-host-prohibited
COMMIT
:wq! #保存退出
centos 7 防火墻關(guān)閉方法二:
CentOS是Linux發(fā)行版之一,剛開始接觸的朋友可能都還不知道centos關(guān)閉防火墻方法是什么吧?接下來本文就將為大家介紹使用命令行關(guān)閉centos防火墻的方法。
我們可以使用以下命令:
#/sbin/iptables -I INPUT -p tcp --dport 80 -j ACCEPT
#/sbin/iptables -I INPUT -p tcp --dport 22 -j ACCEPT
#/etc/rc.d/init.d/iptables save
重啟計(jì)算機(jī)后,防火墻默認(rèn)已經(jīng)開放了80和22兩個(gè)端口。
臨時(shí)性的完全關(guān)閉防火墻,可以不重啟機(jī)器:
#/etc/init.d/iptables status ##查看防火墻狀態(tài)
#/etc/init.d/iptable stop ##本次關(guān)閉防火墻
#/etc/init.d/iptable restart ##重啟防火墻
永久性關(guān)閉防火墻:
#chkconfig --level 35 iptables off (注意中間的是兩個(gè)英式小短線;重啟)
設(shè)置防火墻開放端口的方法如下:
vi /etc/sysconfig/iptables
修改防火墻時(shí)注意最好留下VNC和SSH的管理端口。
下面是一個(gè)iptables的示例:
# Firewall configuration written by system-config-securitylevel
# Manual customization of this file is not recommended.*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:RH-Firewall-1-INPUT - [0:0]
-A INPUT -j RH-Firewall-1-INPUT
-A FORWARD -j RH-Firewall-1-INPUT
-A RH-Firewall-1-INPUT -i lo -j ACCEPT
-A RH-Firewall-1-INPUT -p icmp –icmp-type any -j ACCEPT
-A RH-Firewall-1-INPUT -p 50 -j ACCEPT
-A RH-Firewall-1-INPUT -p 51 -j ACCEPT
-A RH-Firewall-1-INPUT -m state –state ESTABLISHED,RELATED -j ACCEPT
-A RH-Firewall-1-INPUT -m state –state NEW -m tcp -p tcp –dport 53 -j ACCEPT
-A RH-Firewall-1-INPUT -m state –state NEW -m udp -p udp –dport 53 -j ACCEPT
-A RH-Firewall-1-INPUT -m state –state NEW -m tcp -p tcp –dport 22 -j ACCEPT
-A RH-Firewall-1-INPUT -m state –state NEW -m tcp -p tcp –dport 25 -j ACCEPT
-A RH-Firewall-1-INPUT -m state –state NEW -m tcp -p tcp –dport 80 -j ACCEPT
-A RH-Firewall-1-INPUT -m state –state NEW -m tcp -p tcp –dport 443 -j ACCEPT
-A RH-Firewall-1-INPUT -j REJECT –reject-with icmp-host-prohibited
COMMIT
要根據(jù)自己需求情況來修改這個(gè)文件,舉例來說,如果你不希望開放80端口提供web服務(wù),那么應(yīng)該相應(yīng)的刪除這一行:
-A RH-Firewall-1-INPUT -m state –state NEW -m tcp -p tcp –dport 80 -j ACCEPT
全部修改完之后重啟iptables:
service iptables restart
你可以驗(yàn)證一下是否規(guī)則都已經(jīng)生效:iptables -L
這樣,我們就完成了CentOS防火墻的設(shè)置修改。
看了“centos 7防火墻 怎么樣關(guān)閉”文章的還看了: