亲测有效!!!
禁止某个ip地址ping本机:
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.127.7" protocol value="icmp" drop'
删除上面配置的禁止ping本机的防火墙规则:(恢复某个ip地址ping本机)
firewall-cmd --permanent --remove-rich-rule='rule family="ipv4" source address="192.168.127.7" protocol value="icmp" drop'