1.屏蔽指定ip:firewall-cmd --permanent --add-rich-rule="rule family='ipv4' source address='1.1.1.1' reject"
2.解除屏蔽ip: firewall-cmd --permanent --remove-rich-rule="rule family='ipv4' source address='1.1.1.1' reject"
3.屏蔽某段ip:firewall-cmd --permanent --add-rich-rule="rule family=ipv4 source address=x.x.x.x/24 reject"
ps:屏蔽使用reject或drop测试都可以。
4.重新加载:firewall-cmd --reload
5.查看:firewall-cmd --list-all/firewall-cmd --list-rich-rules
6.开放端口:firewall-cmd --zone=public --add-port=80/tcp --permanent
7.移除端口:firewall-cmd --permanent --remove-port=80/tcp