direct方式
firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -s 172.16.10.4 -j ACCEPT
对应/etc/firewalld/direct.xml
<?xml version="1.0" encoding="utf-8"?>
<direct>
<rule priority="0" table="filter" ipv="ipv4" chain="INPUT">-s 172.16.10.4 -j ACCEPT</rule>
</direct>
firewall-cmd --permanent --add-port=8080/tcp
对应/etc/firewalld/zones/public.xml
<?xml version="1.0" encoding="utf-8"?>
<zone>
<short>Public</short>
<description>For use in public areas. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description>
<service name="dhcpv6-client"/>
<service name="ssh"/>
<port protocol="tcp" port="8080"/>
</zone>