[root@kvm5 ~]# systemctl mask iptables.service ln -s '/dev/null' '/etc/systemd/system/iptables.service' [root@kvm5 ~]# systemctl mask ip6tables.service ln -s '/dev/null' '/etc/systemd/system/ip6tables.service'
[root@kvm5 ~]# systemctl status firewalld.service firewalld.service - firewalld - dynamic firewall daemon Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled) Active: active (running) since Thu 2014-08-21 18:51:18 CST; 3min 18s ago Main PID: 569 (firewalld) CGroup: /system.slice/firewalld.service └─569 /usr/bin/python -Es /usr/sbin/firewalld --nofork --nopid Aug 21 18:51:18 kvm5.deyu.wang systemd[1]: Started firewalld - dynamic firew.... Hint: Some lines were ellipsized, use -l to show in full.
[root@kvm5 ~]# systemctl start firewalld.service [root@kvm5 ~]# systemctl enable firewalld.service
[root@kvm5 ~]# firewall-cmd --get-default-zone public
[root@kvm5 ~]# firewall-cmd --set-default-zone public Warning: ZONE_ALREADY_SET: public
[root@kvm5 ~]# firewall-cmd --permanent --zone=public --list-all public (default) interfaces: sources: services: dhcpv6-client ssh ports: masquerade: no forward-ports: icmp-blocks: rich rules:
[root@kvm5 ~]# firewall-cmd --permanent --zone=public --add-port=80/tcp success
[root@kvm5 ~]# firewall-cmd --permanent --zone=public --list-all public (default) interfaces: sources: services: dhcpv6-client ssh ports: 80/tcp masquerade: no forward-ports: icmp-blocks: rich rules:
[root@kvm5 ~]# firewall-cmd --reload success
[root@dywH ~]# curl http://kvm5.deyu.wang firewall test