温馨提示×

centos防火墙怎样查规则

小樊
37
2026-10-05 19:28:19
栏目: 智能运维

在 CentOS 中查看防火墙规则,主要取决于你使用的是 firewalld(CentOS 7 及以后默认)还是 iptables(老版本或手动切换过)。


一、CentOS 7/8/Stream(默认 firewalld)

1️⃣ 查看防火墙状态

systemctl status firewalld

或

firewall-cmd --state

2️⃣ 查看当前生效的规则(运行时)

firewall-cmd --list-all

查看更详细:

firewall-cmd --list-all-zones

3️⃣ 查看某个具体项

# 开放端口
firewall-cmd --list-ports

# 开放服务
firewall-cmd --list-services

# 富规则(复杂规则)
firewall-cmd --list-rich-rules

4️⃣ 查看永久规则(重启后仍生效)

firewall-cmd --list-all --permanent

二、使用 iptables(旧方式或手动关闭 firewalld)

1️⃣ 查看 iptables 规则

iptables -L -n -v

查看 NAT 表:

iptables -t nat -L -n -v

2️⃣ 如果 firewalld 没开,但 iptables 在跑

先确认:

systemctl status iptables

三、常见问题排查

firewalld 没开但规则不生效?

# 启动
systemctl start firewalld

# 开机自启
systemctl enable firewalld

想直接看底层规则(firewalld 实际用的)

iptables -L -n -v

firewalld 本质上也是在操作 iptables / nftables。


四、快速判断你用的是哪个

systemctl is-active firewalld
systemctl is-active iptables

如果你愿意,可以告诉我:

  • CentOS 版本(cat /etc/redhat-release)
  • 是想查 端口、IP、转发还是被拦截原因

我可以给你更精确的命令。

0 踩