开启防火墙

sudo systemctl start firewalld

关闭防火墙

systemctl stop firewalld.service
#或者
sudo systemctl stop firewalld

查看已开放的端口

firewall-cmd --list-ports

开放端口

# public(作用域),permanent(永久生效)
firewall-cmd --zone=public --add-port=80/tcp --permanent
firewall-cmd --zone=public --add-port=443/tcp --permanent
# 记得重载配置
firewall-cmd --reload

关闭端口

firewall-cmd --zone=public --remove-port=80/tcp --permanent
# 记得重载配置
firewall-cmd --reload