::: Zany's Homepage ::: Zany Wiki | »çÀÌÆ® ÅëÇÕ °Ë»ö
 
 
 

firewall-cmd ¸¦ ÀÌ¿ëÇÏ¿© ³»ºÎ ¹æÈ­º®(firewalld) Á¦¾î.

°Ô½ÃÆÇ
Unix/Linux
ÀÛ¼ºÀÚ
helix
ÀÛ¼ºÀÏ
2017-11-23 10:17:09
ÀÐÀº¼ö
2033
ÆòÁ¡
   
Ç¥½Ã¿É¼Ç
HTML»ç¿ë | ÀÚµ¿BRűנ| °ø¹é¹®ÀÚÇã¿ë | °¡¿îµ¥Á¤·Ä | °íÁ¤Æø±Û²Ã | ÀÚµ¿URL¸µÅ© | ¸¶¿ì½º¼±ÅÃ
¡Ü °ü·Ã OS
  - Ubuntu
  - Centos 7 ÀÌ»ó
¡Ü ÇöÀç È°¼ºÈ­µÈ zone È®ÀÎ
firewall-cmd --get-active-zones
firewall-cmd --get-default-zone
[zany@hermes ~]$ firewall-cmd --get-active-zones
public
  interfaces: eno16777736

[zany@hermes ~]$ firewall-cmd --get-default-zone
public
ÇöÀç È°¼ºÈ­µÈ zone ÀÌ "public" ÀÓÀ» ¾Ë ¼ö ÀÖ´Ù.

¡Ü zone È®ÀÎ ¿É¼Ç
  --get-active-zones        Print currently active zones
  --get-default-zone        Print default zone for connections and interfaces
  --set-default-zone= Set default zone

¡Ü ¹æÈ­º® ¸ðµç zone ¸ñ·ÏÀ» º¸·Á¸é --list-all-zones ¿É¼ÇÀ» »ç¿ëÇÑ´Ù (superuser ±ÇÇÑÀÌ ÇÊ¿äÇÏ´Ù)
firewall-cmd --list-all-zones
[zany@hermes ~]$ sudo firewall-cmd --list-all-zones
... »ý·« ...
public (active)
  target: default
  icmp-block-inversion: no
  interfaces: eno16777736
  sources:
  services: dhcpv6-client ssh
  ports: 10022/tcp
  protocols:
  masquerade: no
  forward-ports:
  source-ports:
  icmp-blocks:
  rich rules:

... »ý·« ...
[zany@hermes ~]$

¡Ü ÇöÀç zone ¿¡ TCP Æ÷Æ® Çϳª OPEN (superuser ±ÇÇÑÀÌ ÇÊ¿äÇÏ´Ù)
firewall-cmd --zone=[zone-name] --add-port=[port/tcp] --permanent
[zany@hermes ~]$ sudo firewall-cmd --zone=public --add-port=2888/tcp --permanent
success

firewall-cmd --get-active-zone ¸í·ÉÀÇ °á°ú°¡ dmz ·Î ³ª¿Ã °æ¿ì
¾Æ·¡¿Í °°ÀÌ --zone ¿É¼Ç¿¡ ÀûÀýÇÑ zone À̸§À» ³Ö¾îÁØ´Ù.

[zany@hermes ~]$ sudo firewall-cmd --zone=dmz --add-port=2888/tcp --permanent
success

¡Ü ¹æÈ­º® ¼³Á¤ ´Ù½Ã ·Îµå (superuser ±ÇÇÑÀÌ ÇÊ¿äÇÏ´Ù)
firewall-cmd --reload
[zany@hermes ~]$ sudo firewall-cmd --reload
success

¡Ü Æ÷Æ® OPEN Àüü ¸í·É.
1) active zone È®ÀÎ
[zany@hermes ~]$ firewall-cmd --get-active-zones
public
  interfaces: eno16777736

2) ÇöÀç ¿­·ÁÀÖ´Â Æ÷Æ® È®ÀÎ
[zany@hermes ~]$ sudo firewall-cmd --list-ports
10022/tcp

3) »õ·Î¿î Æ÷Æ® ¿­±â (tcp, 10038 port)
[zany@hermes ~]$ firewall-cmd --zone=public --add-port=10038/tcp --permanent
success

4) ÇöÀç ¿­·ÁÀÖ´Â Æ÷Æ® È®ÀÎ (reload ¸¦ ÇÏÁö ¾Ê¾ÒÀ¸¹Ç·Î, ¾ÆÁ÷ 10038 Æ÷Æ®°¡ ¹Ý¿µµÇ¾îÀÖÁö ¾Ê´Ù)
[zany@hermes ~]$ sudo firewall-cmd --list-ports
10022/tcp

5) ¹æÈ­º® ·ê reload
[zany@hermes ~]$ sudo firewall-cmd --reload
success

6) ÇöÀç ¿­·ÁÀÖ´Â Æ÷Æ® È®ÀÎ (¹æÈ­º® ·êÀ» reload ÇßÀ¸¹Ç·Î 10038 Æ÷Æ®°¡ ¹Ý¿µµÇ¾î ÀÖ´Ù)
[zany@hermes ~]$ sudo firewall-cmd --list-ports
10022/tcp 10038/tcp

¡Ü Æ÷Æ® »èÁ¦ Àüü ¸í·É
1) ÇöÀç ¿­·ÁÀÖ´Â Æ÷Æ® È®ÀÎ
[zany@hermes ~]$ sudo firewall-cmd --list-ports
10022/tcp 10038/tcp

2) public zone ¿¡¼­ tcp 10038 Æ÷Æ® Á¦°Å
[zany@hermes ~]$ sudo firewall-cmd --zone=public --remove-port=10038/tcp --permanent
success

3) ÇöÀç ¿­·ÁÀÖ´Â Æ÷Æ® È®ÀÎ (reload ¸¦ ÇÏÁö ¾Ê¾ÒÀ¸¹Ç·Î, ¾ÆÁ÷ 10038 Æ÷Æ®°¡ Á¦°ÅµÇÁö ¾Ê¾Ò´Ù)
[zany@hermes ~]$ sudo firewall-cmd --list-ports
10022/tcp 10038/tcp

4) ¹æÈ­º® ·ê reload
[zany@hermes ~]$ sudo firewall-cmd --reload
success

5) ÇöÀç ¿­·ÁÀÖ´Â Æ÷Æ® È®ÀÎ (¹æÈ­º® ·êÀ» reload ÇßÀ¸¹Ç·Î 10038 Æ÷Æ®°¡ Á¦°ÅµÇ¾ú´Ù)
[zany@hermes ~]$ sudo firewall-cmd --list-ports
10022/tcp

¡Ü Æ÷Æ® ¹üÀ§ ¿É¼Ç
¾Æ·¡¿Í °°ÀÌ --add-port=3000-4000/tcp ¿É¼ÇÀ» »ç¿ëÇÏ¿© ¹üÀ§·Î OPEN ÇÒ ¼öµµ ÀÖ´Ù.
Æ÷Æ® ¹üÀ§´Â --add-port, --remove-port, --query-port ¿É¼Ç¿¡ ¸ðµÎ Àû¿ëµÈ´Ù.
firewall-cmd --zone=public --add-port=3000-4000/tcp --permanent

 °Ô½ÃÆÇ ±Û ¸ñ·Ï
No Subject Poster Hits Posted
14277 helix 2369 2018-03-23 10:24:50
14273 helix 2551 2018-02-07 13:36:57
14239 helix 2244 2017-12-05 17:07:33
14238 helix 1684 2017-12-05 12:27:02
14234 helix 1288 2017-11-23 13:48:45
helix 2033 2017-11-23 10:17:09
14231 helix 1510 2017-11-22 16:00:30
14228 helix 3120 2017-11-15 09:49:12
14224 helix 1695 2017-11-08 01:22:09
14220 helix 1049 2017-11-02 10:02:18
14218 helix 1727 2017-11-01 10:56:55
ÄÚ¸àÆ®
ÀÛ¼ºÀÚ
                       
 
zany.kr
  Copyright ¨Ï 2002-2010 Zany's Programming Lab. All Rights Not Reserved.
temporary This Page loads on 0.031 Secs