☰
Linux防火墙 firewalld 实战
2026/9/28 20:44:27 网站建设 项目流程

Linux防火墙 firewalld 实战

📖简介:讲解 Linux 内核 Netfilter 框架,firewalld 核心概念 zone 区域,runtime 运行时与 permanent 永久配置;放行服务端口、源 / 网卡绑定、MASQUERADE 源地址转换、端口转发 DNAT、ICMP 控制、rich‑rule 富规则。

一、防火墙基础概念

防火墙分类

  1. 按保护范围
  • 主机防火墙:只保护本机,firewalld、iptables。
  • 网络防火墙:保护整个局域网,硬件防火墙设备。
  1. 按实现方式
  • 硬件防火墙:专用硬件设备,华为、华三、天融信等。
  • 软件防火墙:运行在通用操作系统之上,firewalld、iptables。
  1. 按 OSI 模型
  • 网络层(包过滤防火墙):工作在四层,检查源 IP、目的 IP、端口、协议,速度快;无法解析应用层内容。
  • 应用层 WAF:Web 应用防火墙,解析 HTTP/HTTPS,防御 SQL 注入、XSS 等 Web 攻击,消耗 CPU 高。

Netfilter 内核子系统

Netfilter 是Linux 内核态网络过滤子系统,真正负责处理数据包;用户空间工具只是编写规则交给内核执行。 配套用户层工具:

  • iptables:IPv4 包过滤
  • ip6tables:IPv6
  • arptables:ARP 协议过滤,防 ARP 欺骗
  • ebtables:二层数据链路过滤,多用于桥接、VLAN 环境
[root@centos7 ~]# ls -1 /sbin/*tables -rwxr-xr-x 1 root root 59872 11月 6 2016 /sbin/arptables -rwxr-xr-x. 1 root root 7016 4月 11 2018 /sbin/ebtables lrwxrwxrwx. 1 root root 13 8月 1 15:45 /sbin/ip6tables -> xtables-multi lrwxrwxrwx. 1 root root 13 8月 1 15:45 /sbin/iptables -> xtables-multi

Nftables:新一代 netfilter 增强框架,CentOS7 firewalld 底层可使用 nftables 后端。

静态防火墙 vs 动态防火墙

  1. 静态防火墙(iptables‑service):修改规则后要完整 reload 全部规则,会中断现有 TCP 连接。
  2. 动态防火墙(firewalld):只增量更新变更的规则,不中断已有连接,生产环境优势大。

注意:不要同时混用 firewalld 和 iptables 两套服务,两套规则会互相干扰。

二、firewalld 核心:Zone 区域

zone 就是一套预定义的规则集合,把网卡、源 IP 流量绑定到不同 zone,实现不同安全策略。

全部 zone 说明

表格

zone 名称策略说明
trusted全部流量允许通过
public默认 zone;仅允许 ssh、dhcpv6‑client,其余拒绝
external允许 ssh,开启 IPv4 地址伪装 SNAT,适合路由器外网网卡
home家庭内网,放行 ssh、samba‑client 等
internal同 home
work工作环境,放行 ssh
dmz隔离区,仅允许 ssh 访问
block拒绝入站数据包,返回拒绝应答包
drop直接丢弃数据包,不回复任何 ICMP 错误报文,对方看不到拒绝提示

数据包匹配 zone 优先级

  1. 如果数据包源 IP 匹配 zone 配置的 source 源地址 → 使用该 zone 规则。
  2. 不匹配 source,则看数据包进入的网卡接口绑定哪个 zone。
  3. 都不匹配,使用系统default 默认 zone(默认 public)。

lo 本地回环网卡默认绑定 trusted。 不匹配允许规则的流量,默认拒绝(trusted 除外)。

规则内部优先级

  1. 端口转发、伪装
  2. 普通允许规则(service、port)
  3. 普通拒绝规则
  4. 日志审计
  5. ✅富规则 rich‑rule 优先级高于普通 zone 规则
  6. 全部规则不匹配,默认拒绝

三、runtime 运行时 vs permanent 永久配置

非常重要,实操最容易踩坑!

  1. runtime(运行时):不加--permanent,规则立即生效;重启 firewalld 服务全部丢失。
  2. permanent(永久):加--permanent参数,写入磁盘配置文件;不会立刻生效,需要执行firewall‑cmd --reload加载。

reload vs complete‑reload

  • firewall‑cmd --reload:加载永久规则,不切断已经建立好的 TCP 连接。
  • firewall‑cmd --complete‑reload:全部重新加载,现有连接全部断开。

推荐实操写法,两条一起执行,立刻生效同时保存永久配置:

# 示例放行http服务,永久+立即生效 [root@centos7 ~]# firewall-cmd --permanent --add-service=http [root@centos7 ~]# firewall-cmd --add-service=http

另一种方式:先只写 permanent,reload;或者运行时配置完成后,--runtime‑to‑permanent把内存规则保存到磁盘。

四、zone 区域基础管理命令

# 列出全部可用zone [root@centos7 ~]# firewall-cmd --get-zones # 查看当前激活的zone(绑定网卡/源) [root@centos7 ~]# firewall-cmd --get-active-zones # 查看系统默认zone [root@centos7 ~]# firewall-cmd --get-default-zone # 修改系统默认zone(同时会写永久配置) [root@centos7 ~]# firewall-cmd --set-default-zone=public # 查看默认zone完整规则 [root@centos7 ~]# firewall-cmd --list-all # 查看指定zone完整规则 [root@centos7 ~]# firewall-cmd --list-all --zone=home

五、source 源地址管理(按源 IP 网段匹配 zone)

来自指定源 IP / 网段的流量,交给对应 zone 处理。

# 将10.1.1.0/24网段流量交给home zone,运行时 [root@centos7 ~]# firewall-cmd --add-source=10.1.1.0/24 --zone=home # 永久生效 [root@centos7 ~]# firewall-cmd --permanent --add-source=10.1.1.0/24 --zone=home # 查看home zone绑定的source [root@centos7 ~]# firewall-cmd --list-sources --zone=home # 查询网段属于哪个zone [root@centos7 ~]# firewall-cmd --get-zone-of-source=10.1.1.0/24 # 删除source绑定 [root@centos7 ~]# firewall-cmd --remove-source=10.1.1.0/24 --zone=home [root@centos7 ~]# firewall-cmd --permanent --remove-source=10.1.1.0/24 --zone=home

六、interface 网卡接口管理

网卡设备绑定 zone,流量从该网卡进来就使用对应 zone 策略。

# 查看绑定网卡 [root@centos7 ~]# firewall-cmd --list-interfaces # 查询网卡属于哪个zone [root@centos7 ~]# firewall-cmd --get-zone-of-interface=ens32 # 修改网卡归属zone [root@centos7 ~]# firewall-cmd --change-interface=ens32 --zone=home # 删除网卡和zone绑定 [root@centos7 ~]# firewall-cmd --remove-interface=ens32 --zone=home [root@centos7 ~]# firewall-cmd --permanent --remove-interface=ens32 --zone=home

七、放行服务 service 管理

firewalld 内置服务定义,对应端口写在/usr/lib/firewalld/services/*.xml,例如 http 对应 80/tcp,https 对应 443/tcp。

# 查看系统预定义全部服务 [root@centos7 ~]# firewall-cmd --get-services # 放行http服务(运行时) [root@centos7 ~]# firewall-cmd --add-service=http # 永久放行http [root@centos7 ~]# firewall-cmd --permanent --add-service=http # 查看当前zone放行的服务 [root@centos7 ~]# firewall-cmd --list-services # 查询是否放行http [root@centos7 ~]# firewall-cmd --query-service=http # 移除放行 [root@centos7 ~]# firewall-cmd --remove-service=http [root@centos7 ~]# firewall-cmd --permanent --remove-service=http

八、直接放行端口 port 管理

没有预定义 service,直接放行端口 / 端口范围。格式:端口号/协议(tcp/udp)

# 放行5900/tcp端口,运行时 [root@centos7 ~]# firewall-cmd --add-port=5900/tcp # 永久放行 [root@centos7 ~]# firewall-cmd --permanent --add-port=5900/tcp # 查看放行端口列表 [root@centos7 ~]# firewall-cmd --list-ports # 查询端口是否放行 [root@centos7 ~]# firewall-cmd --query-port=5900/tcp # 删除端口放行 [root@centos7 ~]# firewall-cmd --remove-port=5900/tcp [root@centos7 ~]# firewall-cmd --permanent --remove-port=5900/tcp

九、MASQUERADE 地址伪装

路由器功能:内网机器经过本机上网,把内网源 IP 替换成本机公网 IP;external zone 默认自带 masquerade。

# 查看是否开启masquerade [root@centos7 ~]# firewall-cmd --query-masquerade # 开启masquerade(运行时) [root@centos7 ~]# firewall-cmd --add-masquerade # 永久开启 [root@centos7 ~]# firewall-cmd --permanent --add-masquerade # 关闭 [root@centos7 ~]# firewall-cmd --remove-masquerade [root@centos7 ~]# firewall-cmd --permanent --remove-masquerade

⚠️端口转发 forward‑port必须当前 zone 开启 masquerade 才会生效。

十、forward‑port 端口转发 DNAT

把访问本机某端口的流量转发到其他 IP:port,可以转发到本机端口,也转发内网其他服务器。 语法:--add-forward‑port=port=源端口:proto=tcp:toport=目标端口[:toaddr=目标IP]

# 示例1:访问本机8000端口,转发到本机80端口 [root@centos7 ~]# firewall-cmd --add-forward-port=port=8000:proto=tcp:toport=80 # 示例2:访问本机1022,转发到内网机器10.1.1.11的22端口 [root@centos7 ~]# firewall-cmd --add-forward-port=port=1022:proto=tcp:toport=22:toaddr=10.1.1.11 # 永久配置,加上--permanent [root@centos7 ~]# firewall-cmd --permanent --add-forward-port=port=1022:proto=tcp:toport=22:toaddr=10.1.1.11 # 查看端口转发规则 [root@centos7 ~]# firewall-cmd --list-forward-ports # 删除端口转发 [root@centos7 ~]# firewall-cmd --remove-forward-port=port=8000:proto=tcp:toport=80 [root@centos7 ~]# firewall-cmd --permanent --remove-forward-port=port=1022:proto=tcp:toport=22:toaddr=10.1.1.11

十一、ICMP 控制

icmp‑block‑inversion 总开关

  • 默认no:放行全部 ICMP,可以单独 block 某类 icmp 类型。
  • 设置yes:全部 ICMP 默认禁止,再通过规则放行部分 icmp 类型。
# 查看状态 [root@centos7 ~]# firewall-cmd --query-icmp-block-inversion # 开启全局禁止ICMP [root@centos7 ~]# firewall-cmd --add-icmp-block-inversion [root@centos7 ~]# firewall-cmd --permanent --add-icmp-block-inversion # 恢复默认关闭 [root@centos7 ~]# firewall-cmd --remove-icmp-block-inversion [root@centos7 ~]# firewall-cmd --permanent --remove-icmp-block-inversion

icmp‑block,屏蔽指定 ICMP 类型

echo‑request就是 ping 请求报文,屏蔽它别人无法 ping 通本机。

# 查看系统支持的icmp类型 [root@centos7 ~]# firewall-cmd --get-icmptypes # 禁止ping,屏蔽echo‑request [root@centos7 ~]# firewall-cmd --add-icmp-block echo-request [root@centos7 ~]# firewall-cmd --permanent --add-icmp-block echo-request # 查看被屏蔽的icmp清单 [root@centos7 ~]# firewall-cmd --list-icmp-blocks # 删除屏蔽,恢复ping [root@centos7 ~]# firewall-cmd --remove-icmp-block echo-request [root@centos7 ~]# firewall-cmd --permanent --remove-icmp-block echo-request

注意:修改 icmp‑block 后,如果旧连接还能 ping 通,执行--complete‑reload完全重载,清空连接状态。

[root@centos7 ~]# firewall-cmd --complete-reload

十二、rich‑rule 富规则

普通 service/port 只能对整个 zone 生效;富规则可以精细控制源 IP、目的 IP、协议、日志、限流、审计,优先级高于普通 zone 规则。

富规则基础语法:

rule [source] [destination] service|port|protocol|icmp‑type [log][audit][accept|reject|drop]

实操示例

示例 1:拒绝所有 IPv4 的 icmp(所有人无法 ping 本机)

[root@centos7 ~]# firewall-cmd --add-rich-rule='rule family=ipv4 protocol value=icmp drop' [root@centos7 ~]# firewall-cmd --permanent --add-rich-rule='rule family=ipv4 protocol value=icmp drop' # 查看富规则列表 [root@centos7 ~]# firewall-cmd --list-rich-rules # 删除富规则 [root@centos7 ~]# firewall-cmd --remove-rich-rule='rule family=ipv4 protocol value=icmp drop' [root@centos7 ~]# firewall-cmd --permanent --remove-rich-rule='rule family=ipv4 protocol value=icmp drop'

示例 2:只允许 10.1.8.10 这台主机 ping 本机,其他全部禁止 ping

# 全局禁止ping [root@centos7 ~]# firewall-cmd --permanent --add-icmp-block-inversion # 允许指定源IP的ping请求 [root@centos7 ~]# firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address="10.1.8.10" icmp-type name="echo-request" accept' # 完全重载规则 [root@centos7 ~]# firewall-cmd --complete-reload

示例 3:只允许 10.1.8.0/24 网段访问 http 服务,其他源拒绝访问 80

[root@centos7 ~]# firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.1.8.0/24" service name="http" accept'

十三、direct 直接规则

direct 直接规则优先级最高,直接使用类似iptables语法,用来做补充,业务优先使用 firewalld 自身 zone/rich‑rule。

# 查看全部direct规则 [root@centos7 ~]# firewall-cmd --direct --get-all-rules

简单示例,把 192.168.0.0/24 网段拉黑,每分钟限制一次日志输出,然后 drop。

[root@centos7 ~]# firewall-cmd --direct --permanent --add-chain ipv4 raw blacklist [root@centos7 ~]# firewall-cmd --direct --permanent --add-rule ipv4 raw PREROUTING 0 -s 192.168.0.0/24 -j blacklist [root@centos7 ~]# firewall-cmd --direct --permanent --add-rule ipv4 raw blacklist 0 -m limit --limit 1/min -j LOG --log-prefix "blacklisted " [root@centos7 ~]# firewall-cmd --direct --permanent --add-rule ipv4 raw blacklist 1 -j DROP [root@centos7 ~]# firewall-cmd --reload

清理 direct 规则:

[root@centos7 ~]# firewall-cmd --permanent --direct --remove-rules ipv4 raw blacklist [root@centos7 ~]# firewall-cmd --permanent --direct --remove-rules ipv4 raw PREROUTING [root@centos7 ~]# firewall-cmd --direct --remove-chain ipv4 raw blacklist [root@centos7 ~]# firewall-cmd --reload

十四、其他实用功能

panic 应急模式,全部网络丢弃,被入侵应急断网

# 开启panic,所有进出数据包全部丢弃 [root@centos7 ~]# firewall-cmd --panic-on # 查询panic状态 [root@centos7 ~]# firewall-cmd --query-panic # 关闭panic恢复网络 [root@centos7 ~]# firewall-cmd --panic-off

runtime 配置写入永久磁盘

调试全部使用运行时规则,确认没问题,一键保存到永久配置,不用每条加 --permanent。

[root@centos7 ~]# firewall-cmd --runtime-to-permanent

临时生效的超时规则,调试用,单位秒

# http服务放行,10秒之后自动失效,不需要手动删除 [root@centos7 ~]# firewall-cmd --add-service=http --timeout=10

需要专业的网站建设服务?

联系我们获取免费的网站建设咨询和方案报价,让我们帮助您实现业务目标

立即咨询