CentOS7 关闭防火墙,永久关闭firewalld
时间:2026-10-6 08:00 作者:emer 分类: 无
前言
刚装好的 CentOS7 默认开了防火墙,很多端口都访问不了。有时候为了省事想直接关掉防火墙,本文讲一下怎么操作,以及临时关和永久关的区别。
查看防火墙状态
先看看防火墙现在是开还是关:
systemctl status firewalld
输出里有 active (running) 就是开着,inactive (dead) 就是关了。
或者用:
firewall-cmd --state
输出 running 就是开着,not running 就是关了。
临时关闭防火墙
只关掉当前运行状态,重启后又会自动开起来:
systemctl stop firewalld
永久关闭防火墙
永久关闭,重启后也不会再开:
systemctl stop firewalld
systemctl disable firewalld
两条命令一起执行,先停掉当前的,再禁止开机自启。
重新开启防火墙
如果以后又想开起来:
systemctl start firewalld
systemctl enable firewalld
验证是否关闭成功
执行完之后再看一下状态:
systemctl status firewalld
应该显示 inactive (dead)。
常见坑
坑1:只 stop 了但没 disable
执行了 systemctl stop firewalld,但重启后防火墙又自己开起来了。
原因: 只停了当前运行,没关开机自启。
解决: 还要执行 systemctl disable firewalld。
坑2:关了防火墙但还是访问不了
防火墙关了,但外部还是访问不了网站。
原因: 除了系统防火墙,云服务商还有一层安全组。
解决: 去云服务商控制台(阿里云、腾讯云、华为云等)的安全组里,把对应的端口也开放了。
坑3:Ubuntu 用的不是 firewalld
在 Ubuntu 上执行 firewalld 命令报错。
原因: Ubuntu 默认用 ufw 防火墙,不是 firewalld。
解决: Ubuntu 关防火墙用:
ufw stop
ufw disable
坑4:关闭防火墙不安全
直接关了防火墙,服务器暴露在公网上很危险。
建议: 生产环境不要直接关防火墙,而是只开放需要的端口。比如只开 80、443、22 端口,其他都关。
总结
| 操作 | 命令 |
|---|---|
| 查看防火墙状态 | systemctl status firewalld |
| 临时关闭 | systemctl stop firewalld |
| 永久关闭 | systemctl stop firewalld && systemctl disable firewalld |
| 开启防火墙 | systemctl start firewalld |
| 开机自启 | systemctl enable firewalld |
注意: 生产环境建议不要直接关防火墙,用开放指定端口的方式更安全。
遇到问题加QQ23979811 协助处理