#查看版本firewall-cmd --version#查看帮助firewall-cmd --help# 查看防火墙状态firewall-cmd --statesystemctl status firewalld#开启防火墙systemctl start firewalld.service#关闭防火墙systemctl stop firewalld.service#设置防火墙开机自启systemctl enable firewalld.service#关闭防火墙开机自启systemctl disable firewalld.service#重启防火墙firewall-cmd --reloadsystemctl restart firewalld.service#查看已开放的端口firewall-cmd --list-ports#开放端口(需重启防火墙)(以8080为例)# --zone=public 指定的zone为public# --add-port 标识添加的端口,格式为:端口/通讯协议# --permanent 永久生效firewall-cmd --zone=public --add-port=8080/tcp --permanent#关闭端口firewall-cmd --zone=public --remove-port=8080/tcp --permanent