Linux firewalld
说明。
通过firewalld管理ipset
firewalld
默认的ipset
配置路径为/etc/firewalld/ipsets
。
1 |
# 查看ipset |
man-pages: firewalld.ipset
ubuntu: firewalld.ipset
防火墙绑定源source与区域zone
1 |
firewall-cmd --permanent --zone="drop" --add-source="xxx.xxx.xxx.xxx" |
富规则
``sh
firewall-cmd –add-rich-rule=’rule source ipset=blacklist drop’
1 |
|
Status
start # systemctl start firewalld
status # systemctl status firewalld 或者 firewall-cmd –state
disable # systemctl disable firewalld
stop # systemctl stop firewalld
Config
1 |
--permanent |