{"id":10102,"date":"2023-12-27T12:41:14","date_gmt":"2023-12-27T09:11:14","guid":{"rendered":"https:\/\/rasanegar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/"},"modified":"2023-12-27T12:41:14","modified_gmt":"2023-12-27T09:11:14","slug":"%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7","status":"publish","type":"post","link":"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/","title":{"rendered":"\u0631\u0648\u0634 \u0631\u0627\u0647 \u0627\u0646\u062f\u0627\u0632\u06cc \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0628\u0627 FirewallD \u062f\u0631 CentOS 7"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\"><p class=\"ez-toc-title\" style=\"cursor:inherit\">\u0633\u0631\u0641\u0635\u0644\u0647\u0627\u06cc \u0645\u0637\u0644\u0628<\/p>\n<\/div><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d9%be%db%8c%d8%b4_%d9%86%db%8c%d8%a7%d8%b2%d9%87%d8%a7\" >\u067e\u06cc\u0634 \u0646\u06cc\u0627\u0632\u0647\u0627<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d9%85%d9%81%d8%a7%d9%87%db%8c%d9%85_%d9%be%d8%a7%db%8c%d9%87_%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84\" >\u0645\u0641\u0627\u0647\u06cc\u0645 \u067e\u0627\u06cc\u0647 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d9%85%d9%86%d8%a7%d8%b7%d9%82_%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84\" >\u0645\u0646\u0627\u0637\u0642 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d8%ae%d8%af%d9%85%d8%a7%d8%aa_%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84\" >\u062e\u062f\u0645\u0627\u062a \u0641\u0627\u06cc\u0631\u0648\u0627\u0644<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84%d8%af_%d8%b2%d9%85%d8%a7%d9%86_%d8%a7%d8%ac%d8%b1%d8%a7_%d9%88_%d8%aa%d9%86%d8%b8%db%8c%d9%85%d8%a7%d8%aa_%d8%af%d8%a7%d8%a6%d9%85%db%8c\" >\u0641\u0627\u06cc\u0631\u0648\u0627\u0644\u062f \u0632\u0645\u0627\u0646 \u0627\u062c\u0631\u0627 \u0648 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u062f\u0627\u0626\u0645\u06cc<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d9%86%d8%b5%d8%a8_%d9%88_%d9%81%d8%b9%d8%a7%d9%84_%da%a9%d8%b1%d8%af%d9%86_firewalld\" >\u0646\u0635\u0628 \u0648 \u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0646 FirewallD<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%da%a9%d8%a7%d8%b1_%d8%a8%d8%a7_firewalld_zones\" >\u06a9\u0627\u0631 \u0628\u0627 Firewalld Zones<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d8%aa%d8%ba%db%8c%db%8c%d8%b1_%d9%85%d9%86%d8%b7%d9%82%d9%87_%db%8c%da%a9_%d8%b1%d8%a7%d8%a8%d8%b7\" >\u062a\u063a\u06cc\u06cc\u0631 \u0645\u0646\u0637\u0642\u0647 \u06cc\u06a9 \u0631\u0627\u0628\u0637<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d8%aa%d8%ba%db%8c%db%8c%d8%b1_%d9%85%d9%86%d8%b7%d9%82%d9%87_%d9%be%db%8c%d8%b4_%d9%81%d8%b1%d8%b6\" >\u062a\u063a\u06cc\u06cc\u0631 \u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634 \u0641\u0631\u0636<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d8%a8%d8%a7%d8%b2_%da%a9%d8%b1%d8%af%d9%86_%db%8c%da%a9_%d8%a8%d9%86%d8%af%d8%b1_%db%8c%d8%a7_%d8%b3%d8%b1%d9%88%db%8c%d8%b3\" >\u0628\u0627\u0632 \u06a9\u0631\u062f\u0646 \u06cc\u06a9 \u0628\u0646\u062f\u0631 \u06cc\u0627 \u0633\u0631\u0648\u06cc\u0633<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d8%a7%db%8c%d8%ac%d8%a7%d8%af_%db%8c%da%a9_%d8%b3%d8%b1%d9%88%db%8c%d8%b3_firewalld_%d8%ac%d8%af%db%8c%d8%af\" >\u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0633\u0631\u0648\u06cc\u0633 FirewallD \u062c\u062f\u06cc\u062f<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d9%be%d9%88%d8%b1%d8%aa_%d8%ad%d9%85%d9%84_%d9%88_%d9%86%d9%82%d9%84_%d8%a8%d8%a7_%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84\" >\u067e\u0648\u0631\u062a \u062d\u0645\u0644 \u0648 \u0646\u0642\u0644 \u0628\u0627 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d8%a7%db%8c%d8%ac%d8%a7%d8%af_%db%8c%da%a9_%d9%85%d8%ac%d9%85%d9%88%d8%b9%d9%87_%d9%82%d9%88%d8%a7%d9%86%db%8c%d9%86_%d8%a8%d8%a7_%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84d\" >\u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0645\u062c\u0645\u0648\u0639\u0647 \u0642\u0648\u0627\u0646\u06cc\u0646 \u0628\u0627 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644D<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/rasanegaar.com\/blog\/%d8%b1%d9%88%d8%b4-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d8%a8%d8%a7-firewalld-%d8%af%d8%b1-centos-7\/#%d9%86%d8%aa%db%8c%d8%ac%d9%87\" >\u0646\u062a\u06cc\u062c\u0647<\/a><\/li><\/ul><\/nav><\/div>\n<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">\u0632\u0645\u0627\u0646 \u0644\u0627\u0632\u0645 \u0628\u0631\u0627\u06cc \u0645\u0637\u0627\u0644\u0639\u0647: <\/span> <span class=\"rt-time\"> 7<\/span> <span class=\"rt-label rt-postfix\">\u062f\u0642\u06cc\u0642\u0647<\/span><\/span><p> <br \/>\n<br \/><\/p>\n<div class=\"markdown\">\n<p>\u06cc\u06a9 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0628\u0627 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0645\u0646\u0627\u0633\u0628 \u06cc\u06a9\u06cc \u0627\u0632 \u0645\u0647\u0645\u062a\u0631\u06cc\u0646 \u062c\u0646\u0628\u0647 \u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a \u06a9\u0644\u06cc \u0633\u06cc\u0633\u062a\u0645 \u0627\u0633\u062a.<\/p>\n<p><a href=\"https:\/\/firewalld.org\/\" target=\"_blank\" rel=\"noopener\">\u0641\u0627\u06cc\u0631\u0648\u0627\u0644D<\/a><br \/>\n\u06cc\u06a9 \u0631\u0627\u0647 \u062d\u0644 \u06a9\u0627\u0645\u0644 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0627\u0633\u062a \u06a9\u0647 \u0642\u0648\u0627\u0646\u06cc\u0646 iptables \u0633\u06cc\u0633\u062a\u0645 \u0631\u0627 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0645\u06cc \u06a9\u0646\u062f \u0648 \u06cc\u06a9 \u0631\u0627\u0628\u0637 D-Bus \u0628\u0631\u0627\u06cc \u06a9\u0627\u0631 \u0628\u0631 \u0631\u0648\u06cc \u0622\u0646\u0647\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc \u06a9\u0646\u062f.  \u0628\u0627 \u0634\u0631\u0648\u0639 CentOS 7\u060c FirewallD \u062c\u0627\u06cc\u06af\u0632\u06cc\u0646 iptables \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0627\u0628\u0632\u0627\u0631 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u0645\u06cc \u0634\u0648\u062f.<\/p>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634\u060c \u0645\u0627 \u0628\u0647 \u0634\u0645\u0627 \u0646\u0634\u0627\u0646 \u0645\u06cc \u062f\u0647\u06cc\u0645 \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u06cc\u06a9 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0628\u0627 FirewallD \u0631\u0627 \u062f\u0631 \u0633\u06cc\u0633\u062a\u0645 CentOS 7 \u062e\u0648\u062f \u0631\u0627\u0647 \u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0646\u06cc\u062f \u0648 \u0645\u0641\u0627\u0647\u06cc\u0645 \u0627\u0648\u0644\u06cc\u0647 FirewallD \u0631\u0627 \u0628\u0631\u0627\u06cc \u0634\u0645\u0627 \u062a\u0648\u0636\u06cc\u062d \u062f\u0647\u06cc\u0645.<\/p>\n<h2 id=\"prerequisites\"><span class=\"ez-toc-section\" id=\"%d9%be%db%8c%d8%b4_%d9%86%db%8c%d8%a7%d8%b2%d9%87%d8%a7\"><\/span>\u067e\u06cc\u0634 \u0646\u06cc\u0627\u0632\u0647\u0627 <span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u0642\u0628\u0644 \u0627\u0632 \u0634\u0631\u0648\u0639 \u0628\u0627 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634\u060c \u0645\u0637\u0645\u0626\u0646 \u0634\u0648\u06cc\u062f \u06a9\u0647 \u0628\u0627 \u06cc\u06a9 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631\u06cc \u0628\u0627 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a sudo \u06cc\u0627 \u0628\u0627 \u06a9\u0627\u0631\u0628\u0631 root \u0648\u0627\u0631\u062f \u0633\u0631\u0648\u0631 \u062e\u0648\u062f \u0634\u062f\u0647 \u0627\u06cc\u062f.  \u0628\u0647\u062a\u0631\u06cc\u0646 \u0631\u0648\u0634 \u0627\u062c\u0631\u0627\u06cc \u062f\u0633\u062a\u0648\u0631\u0627\u062a \u0645\u062f\u06cc\u0631\u06cc\u062a\u06cc \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u06a9\u0627\u0631\u0628\u0631 sudo \u0628\u0647 \u062c\u0627\u06cc root \u0627\u0633\u062a.  \u0627\u06af\u0631 \u06a9\u0627\u0631\u0628\u0631 sudo \u062f\u0631 \u0633\u06cc\u0633\u062a\u0645 CentOS \u062e\u0648\u062f \u0646\u062f\u0627\u0631\u06cc\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0628\u0627 \u062f\u0646\u0628\u0627\u0644 \u06a9\u0631\u062f\u0646 \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u0627\u0644\u0639\u0645\u0644\u200c\u0647\u0627 \u06cc\u06a9 \u06a9\u0627\u0631\u0628\u0631 sudo \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f.<\/p>\n<h2 id=\"basic-firewalld-concepts\"><span class=\"ez-toc-section\" id=\"%d9%85%d9%81%d8%a7%d9%87%db%8c%d9%85_%d9%be%d8%a7%db%8c%d9%87_%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84\"><\/span>\u0645\u0641\u0627\u0647\u06cc\u0645 \u067e\u0627\u06cc\u0647 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 <span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>FirewallD \u0628\u0647 \u062c\u0627\u06cc \u0632\u0646\u062c\u06cc\u0631\u0647 \u0648 \u0642\u0648\u0627\u0646\u06cc\u0646 iptables \u0627\u0632 \u0645\u0641\u0627\u0647\u06cc\u0645 \u0645\u0646\u0627\u0637\u0642 \u0648 \u062e\u062f\u0645\u0627\u062a \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u062f.  \u0628\u0631 \u0627\u0633\u0627\u0633 \u0645\u0646\u0627\u0637\u0642 \u0648 \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc\u06cc \u06a9\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u06a9\u0646\u062a\u0631\u0644 \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u0686\u0647 \u062a\u0631\u0627\u0641\u06cc\u06a9\u06cc \u0628\u0647 \u0648 \u0627\u0632 \u0633\u06cc\u0633\u062a\u0645 \u0645\u062c\u0627\u0632 \u06cc\u0627 \u063a\u06cc\u0631\u0645\u062c\u0627\u0632 \u0627\u0633\u062a.<\/p>\n<p>FirewallD \u0631\u0627 \u0645\u06cc \u062a\u0648\u0627\u0646 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0622\u0646 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0648 \u0645\u062f\u06cc\u0631\u06cc\u062a \u06a9\u0631\u062f <code>firewall-cmd<\/code> command-line  \u0633\u0648\u062f\u0645\u0646\u062f\u06cc<\/p>\n<h3 id=\"firewalld-zones\"><span class=\"ez-toc-section\" id=\"%d9%85%d9%86%d8%a7%d8%b7%d9%82_%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84\"><\/span>\u0645\u0646\u0627\u0637\u0642 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 <span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u0645\u0646\u0627\u0637\u0642 \u0645\u062c\u0645\u0648\u0639\u0647\u200c\u0627\u06cc \u0627\u0632 \u0642\u0648\u0627\u0646\u06cc\u0646 \u0627\u0632 \u067e\u06cc\u0634 \u062a\u0639\u0631\u06cc\u0641\u200c\u0634\u062f\u0647 \u0647\u0633\u062a\u0646\u062f \u06a9\u0647 \u0645\u0634\u062e\u0635 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f \u0628\u0631 \u0627\u0633\u0627\u0633 \u0633\u0637\u062d \u0627\u0639\u062a\u0645\u0627\u062f \u0634\u0628\u06a9\u0647\u200c\u0647\u0627\u06cc\u06cc \u06a9\u0647 \u0631\u0627\u06cc\u0627\u0646\u0647 \u0634\u0645\u0627 \u0628\u0647 \u0622\u0646\u200c\u0647\u0627 \u0645\u062a\u0635\u0644 \u0627\u0633\u062a\u060c \u0686\u0647 \u062a\u0631\u0627\u0641\u06cc\u06a9\u06cc \u0628\u0627\u06cc\u062f \u0645\u062c\u0627\u0632 \u0628\u0627\u0634\u062f.  \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0631\u0627\u0628\u0637 \u0647\u0627 \u0648 \u0645\u0646\u0627\u0628\u0639 \u0634\u0628\u06a9\u0647 \u0631\u0627 \u0628\u0647 \u06cc\u06a9 \u0645\u0646\u0637\u0642\u0647 \u0627\u062e\u062a\u0635\u0627\u0635 \u062f\u0647\u06cc\u062f.<\/p>\n<p>\u062f\u0631 \u0632\u06cc\u0631 \u0645\u0646\u0627\u0637\u0642 \u0627\u0631\u0627\u0626\u0647 \u0634\u062f\u0647 \u062a\u0648\u0633\u0637 FirewallD \u0628\u0627 \u062a\u0648\u062c\u0647 \u0628\u0647 \u0633\u0637\u062d \u0627\u0639\u062a\u0645\u0627\u062f \u0645\u0646\u0637\u0642\u0647 \u0627\u0632 \u0646\u0627\u0645\u0639\u062a\u0628\u0631 \u0628\u0647 \u0642\u0627\u0628\u0644 \u0627\u0639\u062a\u0645\u0627\u062f \u0633\u0641\u0627\u0631\u0634 \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a:<\/p>\n<ul>\n<li><strong>\u0631\u0647\u0627 \u06a9\u0631\u062f\u0646<\/strong>: \u062a\u0645\u0627\u0645 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0648\u0631\u0648\u062f\u06cc \u0628\u062f\u0648\u0646 \u0647\u06cc\u0686 \u0627\u0637\u0644\u0627\u0639 \u0631\u0633\u0627\u0646\u06cc \u0642\u0637\u0639 \u0645\u06cc \u0634\u0648\u0646\u062f.  \u0641\u0642\u0637 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u062e\u0631\u0648\u062c\u06cc \u0645\u062c\u0627\u0632 \u0627\u0633\u062a.<\/li>\n<li><strong>\u0645\u0633\u062f\u0648\u062f \u06a9\u0631\u062f\u0646<\/strong>: \u062a\u0645\u0627\u0645 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0648\u0631\u0648\u062f\u06cc \u0628\u0627 \u06cc\u06a9 \u0631\u062f \u0645\u06cc \u0634\u0648\u0646\u062f <code>icmp-host-prohibited<\/code> \u067e\u06cc\u0627\u0645 \u0628\u0631\u0627\u06cc <code>IPv4<\/code> \u0648 <code>icmp6-adm-prohibited<\/code> \u0628\u0631\u0627\u06cc IPv6n  \u0641\u0642\u0637 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u062e\u0631\u0648\u062c\u06cc \u0645\u062c\u0627\u0632 \u0627\u0633\u062a.<\/li>\n<li><strong>\u0639\u0645\u0648\u0645\u06cc<\/strong>: \u0628\u0631\u0627\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062f\u0631 \u0645\u06a9\u0627\u0646 \u0647\u0627\u06cc \u0639\u0645\u0648\u0645\u06cc \u063a\u06cc\u0631 \u0642\u0627\u0628\u0644 \u0627\u0639\u062a\u0645\u0627\u062f.  \u0634\u0645\u0627 \u0628\u0647 \u0631\u0627\u06cc\u0627\u0646\u0647 \u0647\u0627\u06cc \u062f\u06cc\u06af\u0631 \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0634\u0628\u06a9\u0647 \u0627\u0639\u062a\u0645\u0627\u062f \u0646\u062f\u0627\u0631\u06cc\u062f\u060c \u0627\u0645\u0627 \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0648\u0631\u0648\u062f\u06cc \u0627\u0646\u062a\u062e\u0627\u0628 \u0634\u062f\u0647 \u0631\u0627 \u0645\u062c\u0627\u0632 \u06a9\u0646\u06cc\u062f.<\/li>\n<li><strong>\u062e\u0627\u0631\u062c\u06cc<\/strong>: \u0628\u0631\u0627\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062f\u0631 \u0634\u0628\u06a9\u0647 \u0647\u0627\u06cc \u062e\u0627\u0631\u062c\u06cc \u0628\u0627 \u067e\u0648\u0634\u0634 NAT \u0641\u0639\u0627\u0644 \u0632\u0645\u0627\u0646\u06cc \u06a9\u0647 \u0633\u06cc\u0633\u062a\u0645 \u0634\u0645\u0627 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u062f\u0631\u0648\u0627\u0632\u0647 \u06cc\u0627 \u0631\u0648\u062a\u0631 \u0639\u0645\u0644 \u0645\u06cc \u06a9\u0646\u062f.  \u0641\u0642\u0637 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0648\u0631\u0648\u062f\u06cc \u0627\u0646\u062a\u062e\u0627\u0628 \u0634\u062f\u0647 \u0645\u062c\u0627\u0632 \u0627\u0633\u062a.<\/li>\n<li><strong>\u062f\u0631\u0648\u0646\u06cc\u061b \u062f\u0627\u062e\u0644\u06cc<\/strong>: \u0628\u0631\u0627\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062f\u0631 \u0634\u0628\u06a9\u0647 \u0647\u0627\u06cc \u062f\u0627\u062e\u0644\u06cc \u0632\u0645\u0627\u0646\u06cc \u06a9\u0647 \u0633\u06cc\u0633\u062a\u0645 \u0634\u0645\u0627 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u062f\u0631\u0648\u0627\u0632\u0647 \u06cc\u0627 \u0631\u0648\u062a\u0631 \u0639\u0645\u0644 \u0645\u06cc \u06a9\u0646\u062f.  \u0633\u0627\u06cc\u0631 \u0633\u06cc\u0633\u062a\u0645 \u0647\u0627\u06cc \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0634\u0628\u06a9\u0647 \u0628\u0647 \u0637\u0648\u0631 \u06a9\u0644\u06cc \u0642\u0627\u0628\u0644 \u0627\u0639\u062a\u0645\u0627\u062f \u0647\u0633\u062a\u0646\u062f.  \u0641\u0642\u0637 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0648\u0631\u0648\u062f\u06cc \u0627\u0646\u062a\u062e\u0627\u0628 \u0634\u062f\u0647 \u0645\u062c\u0627\u0632 \u0627\u0633\u062a.<\/li>\n<li><strong>dmz<\/strong>: \u0628\u0631\u0627\u06cc \u0631\u0627\u06cc\u0627\u0646\u0647 \u0647\u0627\u06cc \u0648\u0627\u0642\u0639 \u062f\u0631 \u0645\u0646\u0637\u0642\u0647 \u063a\u06cc\u0631\u0646\u0638\u0627\u0645\u06cc \u0634\u0645\u0627 \u06a9\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u062d\u062f\u0648\u062f\u06cc \u0628\u0647 \u0628\u0642\u06cc\u0647 \u0634\u0628\u06a9\u0647 \u0634\u0645\u0627 \u062f\u0627\u0631\u0646\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u0634\u0648\u062f.  \u0641\u0642\u0637 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0648\u0631\u0648\u062f\u06cc \u0627\u0646\u062a\u062e\u0627\u0628 \u0634\u062f\u0647 \u0645\u062c\u0627\u0632 \u0627\u0633\u062a.<\/li>\n<li><strong>\u06a9\u0627\u0631 \u06a9\u0631\u062f\u0646<\/strong>: \u0628\u0631\u0627\u06cc \u0645\u0627\u0634\u06cc\u0646 \u0647\u0627\u06cc \u06a9\u0627\u0631 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u0634\u0648\u062f.  \u0633\u0627\u06cc\u0631 \u0631\u0627\u06cc\u0627\u0646\u0647 \u0647\u0627\u06cc \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0634\u0628\u06a9\u0647 \u0639\u0645\u0648\u0645\u0627\u064b \u0642\u0627\u0628\u0644 \u0627\u0639\u062a\u0645\u0627\u062f \u0647\u0633\u062a\u0646\u062f.  \u0641\u0642\u0637 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0648\u0631\u0648\u062f\u06cc \u0627\u0646\u062a\u062e\u0627\u0628 \u0634\u062f\u0647 \u0645\u062c\u0627\u0632 \u0627\u0633\u062a.<\/li>\n<li><strong>\u062e\u0627\u0646\u0647<\/strong>: \u0628\u0631\u0627\u06cc \u0645\u0627\u0634\u06cc\u0646 \u0647\u0627\u06cc \u062e\u0627\u0646\u06af\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u0634\u0648\u062f.  \u0633\u0627\u06cc\u0631 \u0631\u0627\u06cc\u0627\u0646\u0647 \u0647\u0627\u06cc \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0634\u0628\u06a9\u0647 \u0639\u0645\u0648\u0645\u0627\u064b \u0642\u0627\u0628\u0644 \u0627\u0639\u062a\u0645\u0627\u062f \u0647\u0633\u062a\u0646\u062f.  \u0641\u0642\u0637 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0648\u0631\u0648\u062f\u06cc \u0627\u0646\u062a\u062e\u0627\u0628 \u0634\u062f\u0647 \u0645\u062c\u0627\u0632 \u0627\u0633\u062a.<\/li>\n<li><strong>\u0642\u0627\u0628\u0644 \u0627\u0639\u062a\u0645\u0627\u062f<\/strong>: \u062a\u0645\u0627\u0645\u06cc \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0634\u0628\u06a9\u0647 \u067e\u0630\u06cc\u0631\u0641\u062a\u0647 \u0645\u06cc \u0634\u0648\u062f.  \u0628\u0647 \u062a\u0645\u0627\u0645 \u0631\u0627\u06cc\u0627\u0646\u0647 \u0647\u0627\u06cc \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0634\u0628\u06a9\u0647 \u0627\u0639\u062a\u0645\u0627\u062f \u06a9\u0646\u06cc\u062f.<\/li>\n<\/ul>\n<h3 id=\"firewall-services\"><span class=\"ez-toc-section\" id=\"%d8%ae%d8%af%d9%85%d8%a7%d8%aa_%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84\"><\/span>\u062e\u062f\u0645\u0627\u062a \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 <span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u0633\u0631\u0648\u06cc\u0633 \u0647\u0627\u06cc \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0642\u0648\u0627\u0646\u06cc\u0646 \u0627\u0632 \u067e\u06cc\u0634 \u062a\u0639\u0631\u06cc\u0641 \u0634\u062f\u0647 \u0627\u06cc \u0647\u0633\u062a\u0646\u062f \u06a9\u0647 \u062f\u0631 \u06cc\u06a9 \u0645\u0646\u0637\u0642\u0647 \u0627\u0639\u0645\u0627\u0644 \u0645\u06cc \u0634\u0648\u0646\u062f \u0648 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0644\u0627\u0632\u0645 \u0631\u0627 \u0628\u0631\u0627\u06cc \u0627\u062c\u0627\u0632\u0647 \u062f\u0627\u062f\u0646 \u0628\u0647 \u062a\u0631\u0627\u0641\u06cc\u06a9 \u0648\u0631\u0648\u062f\u06cc \u0628\u0631\u0627\u06cc \u06cc\u06a9 \u0633\u0631\u0648\u06cc\u0633 \u062e\u0627\u0635 \u062a\u0639\u0631\u06cc\u0641 \u0645\u06cc \u06a9\u0646\u0646\u062f.<\/p>\n<h3 id=\"firewalld-runtime-and-permanent-settings\"><span class=\"ez-toc-section\" id=\"%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84%d8%af_%d8%b2%d9%85%d8%a7%d9%86_%d8%a7%d8%ac%d8%b1%d8%a7_%d9%88_%d8%aa%d9%86%d8%b8%db%8c%d9%85%d8%a7%d8%aa_%d8%af%d8%a7%d8%a6%d9%85%db%8c\"><\/span>\u0641\u0627\u06cc\u0631\u0648\u0627\u0644\u062f \u0632\u0645\u0627\u0646 \u0627\u062c\u0631\u0627 \u0648 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u062f\u0627\u0626\u0645\u06cc <span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0627\u0632 \u062f\u0648 \u0645\u062c\u0645\u0648\u0639\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0645\u062c\u0632\u0627\u060c \u0632\u0645\u0627\u0646 \u0627\u062c\u0631\u0627 \u0648 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u062f\u0627\u0626\u0645\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u062f.<\/p>\n<p>\u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0632\u0645\u0627\u0646 \u0627\u062c\u0631\u0627\u060c \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0648\u0627\u0642\u0639\u06cc \u062f\u0631 \u062d\u0627\u0644 \u0627\u062c\u0631\u0627 \u0627\u0633\u062a\u060c \u0648 \u062f\u0631 \u0631\u0627\u0647 \u0627\u0646\u062f\u0627\u0632\u06cc \u0645\u062c\u062f\u062f \u067e\u0627\u06cc\u062f\u0627\u0631 \u0646\u06cc\u0633\u062a.  \u0647\u0646\u06af\u0627\u0645\u06cc \u06a9\u0647 \u0633\u0631\u0648\u06cc\u0633 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644\u062f \u0634\u0631\u0648\u0639 \u0645\u06cc \u0634\u0648\u062f\u060c \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u062f\u0627\u0626\u0645\u06cc \u0631\u0627 \u0628\u0627\u0631\u06af\u06cc\u0631\u06cc \u0645\u06cc \u06a9\u0646\u062f \u06a9\u0647 \u0628\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0632\u0645\u0627\u0646 \u0627\u062c\u0631\u0627 \u062a\u0628\u062f\u06cc\u0644 \u0645\u06cc \u0634\u0648\u062f.<\/p>\n<p>\u0628\u0647 \u0637\u0648\u0631 \u067e\u06cc\u0634 \u0641\u0631\u0636\u060c \u0647\u0646\u06af\u0627\u0645 \u0627\u06cc\u062c\u0627\u062f \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u062f\u0631 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0641\u0627\u06cc\u0631\u0648\u0627\u0644\u062f \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 <code>firewall-cmd<\/code> \u0627\u0628\u0632\u0627\u0631\u060c \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u062f\u0631 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0632\u0645\u0627\u0646 \u0627\u062c\u0631\u0627 \u0627\u0639\u0645\u0627\u0644 \u0645\u06cc \u0634\u0648\u062f.  \u0628\u0631\u0627\u06cc \u062f\u0627\u0626\u0645\u06cc \u06a9\u0631\u062f\u0646 \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u0628\u0627\u06cc\u062f \u0627\u0632 \u0622\u0646 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f <code>--permanent<\/code> \u06af\u0632\u06cc\u0646\u0647.<\/p>\n<h2 id=\"installing-and-enabling-firewalld\"><span class=\"ez-toc-section\" id=\"%d9%86%d8%b5%d8%a8_%d9%88_%d9%81%d8%b9%d8%a7%d9%84_%da%a9%d8%b1%d8%af%d9%86_firewalld\"><\/span>\u0646\u0635\u0628 \u0648 \u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0646 FirewallD <span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ol>\n<li>\n<p>\u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0628\u0647 \u0637\u0648\u0631 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u0631\u0648\u06cc CentOS 7 \u0646\u0635\u0628 \u0634\u062f\u0647 \u0627\u0633\u062a\u060c \u0627\u0645\u0627 \u0627\u06af\u0631 \u0631\u0648\u06cc \u0633\u06cc\u0633\u062a\u0645 \u0634\u0645\u0627 \u0646\u0635\u0628 \u0646\u06cc\u0633\u062a\u060c \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0628\u0633\u062a\u0647 \u0631\u0627 \u0628\u0627 \u062a\u0627\u06cc\u067e \u06a9\u0631\u062f\u0646 \u0632\u06cc\u0631 \u0646\u0635\u0628 \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo yum install firewalld<\/code><\/pre>\n<\/li>\n<li>\n<p>\u0633\u0631\u0648\u06cc\u0633 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0628\u0647 \u0637\u0648\u0631 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u0627\u0633\u062a.  \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0648\u0636\u0639\u06cc\u062a \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0631\u0627 \u0628\u0627 \u0645\u0648\u0627\u0631\u062f \u0632\u06cc\u0631 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --state<\/code><\/pre>\n<p>\u0627\u06af\u0631 \u0628\u0647 \u062a\u0627\u0632\u06af\u06cc \u0646\u0635\u0628 \u06a9\u0631\u062f\u0647 \u0627\u06cc\u062f \u06cc\u0627 \u0642\u0628\u0644\u0627\u064b \u0622\u0646 \u0631\u0627 \u0641\u0639\u0627\u0644 \u0646\u06a9\u0631\u062f\u0647 \u0627\u06cc\u062f\u060c \u062f\u0633\u062a\u0648\u0631 \u0686\u0627\u067e \u0645\u06cc \u0634\u0648\u062f <code>not running<\/code>.  \u062f\u0631 \u063a\u06cc\u0631 \u0627\u06cc\u0646 \u0635\u0648\u0631\u062a \u062e\u0648\u0627\u0647\u06cc\u062f \u062f\u06cc\u062f <code>running<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0628\u0631\u0627\u06cc \u0631\u0627\u0647 \u0627\u0646\u062f\u0627\u0632\u06cc \u0633\u0631\u0648\u06cc\u0633 FirewallD \u0648 \u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0646 \u0622\u0646 \u062f\u0631 \u0628\u0648\u062a \u0646\u0648\u0639:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo systemctl start firewalld<\/code><code class=\"terminal-line\" prefix=\"$\">sudo systemctl enable firewalld<\/code><\/pre>\n<\/li>\n<\/ol>\n<h2 id=\"working-with-firewalld-zones\"><span class=\"ez-toc-section\" id=\"%da%a9%d8%a7%d8%b1_%d8%a8%d8%a7_firewalld_zones\"><\/span>\u06a9\u0627\u0631 \u0628\u0627 Firewalld Zones <span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u067e\u0633 \u0627\u0632 \u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0646 \u0633\u0631\u0648\u06cc\u0633 FirewallD \u0628\u0631\u0627\u06cc \u0627\u0648\u0644\u06cc\u0646 \u0628\u0627\u0631\u060c <code>public<\/code> \u0645\u0646\u0637\u0642\u0647 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u06cc\u06a9 \u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u062a\u0646\u0638\u06cc\u0645 \u0634\u062f\u0647 \u0627\u0633\u062a.  \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u0631\u0627 \u0628\u0627 \u062a\u0627\u06cc\u067e \u06a9\u0631\u062f\u0646 \u0645\u0634\u0627\u0647\u062f\u0647 \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --get-default-zone<\/code><\/pre>\n<pre tabindex=\"0\"><code class=\"language-output\" data-lang=\"output\">public\n<\/code><\/pre>\n<p>\u0628\u0631\u0627\u06cc \u062f\u0631\u06cc\u0627\u0641\u062a \u0644\u06cc\u0633\u062a\u06cc \u0627\u0632 \u062a\u0645\u0627\u0645 \u0645\u0646\u0627\u0637\u0642 \u0645\u0648\u062c\u0648\u062f\u060c \u062a\u0627\u06cc\u067e \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --get-zones<\/code><\/pre>\n<pre tabindex=\"0\"><code class=\"language-output\" data-lang=\"output\">block dmz drop external home internal public trusted work\n<\/code><\/pre>\n<p>\u0628\u0647\u200c\u0637\u0648\u0631 \u067e\u06cc\u0634\u200c\u0641\u0631\u0636\u060c \u0647\u0645\u0647 \u0631\u0627\u0628\u0637\u200c\u0647\u0627\u06cc \u0634\u0628\u06a9\u0647 \u0628\u0647 \u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634\u200c\u0641\u0631\u0636 \u0627\u062e\u062a\u0635\u0627\u0635 \u062f\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u0646\u062f.  \u0628\u0631\u0627\u06cc \u0628\u0631\u0631\u0633\u06cc \u0627\u06cc\u0646\u06a9\u0647 \u0686\u0647 \u0645\u0646\u0627\u0637\u0642\u06cc \u062a\u0648\u0633\u0637 \u0631\u0627\u0628\u0637(\u0647\u0627\u06cc) \u0634\u0628\u06a9\u0647 \u0634\u0645\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u0634\u0648\u062f\u060c \u0646\u0648\u0639:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --get-active-zones<\/code><\/pre>\n<pre tabindex=\"0\"><code class=\"language-output\" data-lang=\"output\">public\n  interfaces: eth0 eth1\n<\/code><\/pre>\n<p>\u062e\u0631\u0648\u062c\u06cc \u0628\u0627\u0644\u0627 \u0628\u0647 \u0645\u0627 \u0645\u06cc \u06af\u0648\u06cc\u062f \u06a9\u0647 \u0647\u0631 \u062f\u0648 \u0631\u0627\u0628\u0637 <code>eth0<\/code> \u0648 <code>eth1<\/code> \u0628\u0647 \u0645\u0646\u0637\u0642\u0647 \u0639\u0645\u0648\u0645\u06cc \u0627\u062e\u062a\u0635\u0627\u0635 \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u0627\u0646\u062f.<\/p>\n<p>\u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0645\u0646\u0637\u0642\u0647 \u0631\u0627 \u0628\u0627 \u0645\u0648\u0627\u0631\u062f \u0632\u06cc\u0631 \u0686\u0627\u067e \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=public --list-all<\/code><\/pre>\n<pre tabindex=\"0\"><code class=\"language-output\" data-lang=\"output\">public (active)\n  target: default\n  icmp-block-inversion: no\n  interfaces: eth0 eth1\n  sources:\n  services: ssh dhcpv6-client\n  ports:\n  protocols:\n  masquerade: no\n  forward-ports:\n  source-ports:\n  icmp-blocks:\n  rich rules:\n<\/code><\/pre>\n<p>\u0627\u0632 \u062e\u0631\u0648\u062c\u06cc \u0628\u0627\u0644\u0627\u060c \u0645\u06cc \u0628\u06cc\u0646\u06cc\u0645 \u06a9\u0647 \u0645\u0646\u0637\u0642\u0647 \u0639\u0645\u0648\u0645\u06cc \u0641\u0639\u0627\u0644 \u0627\u0633\u062a \u0648 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u062a\u0646\u0638\u06cc\u0645 \u0634\u062f\u0647 \u0627\u0633\u062a \u06a9\u0647 \u062a\u0648\u0633\u0637 \u0647\u0631 \u062f\u0648 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u0634\u0648\u062f <code>eth0<\/code> \u0648 <code>eth1<\/code> \u0631\u0627\u0628\u0637 \u0647\u0627  \u0647\u0645\u0686\u0646\u06cc\u0646 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 \u06a9\u0644\u0627\u06cc\u0646\u062a DHCP \u0648 SSH \u0645\u062c\u0627\u0632 \u0627\u0633\u062a.<\/p>\n<p>\u0627\u06af\u0631 \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u06cc\u062f \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u062a\u0645\u0627\u0645 \u0645\u0646\u0627\u0637\u0642 \u0645\u0648\u062c\u0648\u062f \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f\u060c \u062a\u0627\u06cc\u067e \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --list-all-zones<\/code><\/pre>\n<p>\u062f\u0633\u062a\u0648\u0631 \u06cc\u06a9 \u0644\u06cc\u0633\u062a \u0628\u0632\u0631\u06af \u0628\u0627 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u062a\u0645\u0627\u0645 \u0645\u0646\u0627\u0637\u0642 \u0645\u0648\u062c\u0648\u062f \u0686\u0627\u067e \u0645\u06cc \u06a9\u0646\u062f.<\/p>\n<h3 id=\"changing-the-zone-of-an-interface\"><span class=\"ez-toc-section\" id=\"%d8%aa%d8%ba%db%8c%db%8c%d8%b1_%d9%85%d9%86%d8%b7%d9%82%d9%87_%db%8c%da%a9_%d8%b1%d8%a7%d8%a8%d8%b7\"><\/span>\u062a\u063a\u06cc\u06cc\u0631 \u0645\u0646\u0637\u0642\u0647 \u06cc\u06a9 \u0631\u0627\u0628\u0637 <span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u0634\u0645\u0627 \u0628\u0647 \u0631\u0627\u062d\u062a\u06cc \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0633\u062a\u0641\u0627\u062f\u0647\u060c \u0645\u0646\u0637\u0642\u0647 \u0631\u0627\u0628\u0637 \u0631\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u06cc\u062f <code>--zone<\/code> \u06af\u0632\u06cc\u0646\u0647 \u062f\u0631 \u062a\u0631\u06a9\u06cc\u0628 \u0628\u0627 <code>--change-interface<\/code> \u06af\u0632\u06cc\u0646\u0647.  \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0631\u0627 \u0627\u062e\u062a\u0635\u0627\u0635 \u0645\u06cc \u062f\u0647\u062f <code>eth1<\/code> \u0631\u0627\u0628\u0637 \u0628\u0647 \u0645\u0646\u0637\u0642\u0647 \u06a9\u0627\u0631:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=work --change-interface=eth1<\/code><\/pre>\n<p>\u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u0631\u0627 \u0628\u0627 \u062a\u0627\u06cc\u067e \u06a9\u0631\u062f\u0646 \u062a\u0623\u06cc\u06cc\u062f \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --get-active-zones<\/code><\/pre>\n<pre tabindex=\"0\"><code class=\"language-output\" data-lang=\"output\">work\n  interfaces: eth1\npublic\n  interfaces: eth0\n<\/code><\/pre>\n<h3 id=\"changing-the-default-zone\"><span class=\"ez-toc-section\" id=\"%d8%aa%d8%ba%db%8c%db%8c%d8%b1_%d9%85%d9%86%d8%b7%d9%82%d9%87_%d9%be%db%8c%d8%b4_%d9%81%d8%b1%d8%b6\"><\/span>\u062a\u063a\u06cc\u06cc\u0631 \u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634 \u0641\u0631\u0636 <span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u0628\u0631\u0627\u06cc \u062a\u063a\u06cc\u06cc\u0631 \u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634 \u0641\u0631\u0636\u060c \u0627\u0632 <code>--set-default-zone<\/code> \u06af\u0632\u06cc\u0646\u0647 \u0627\u06cc \u06a9\u0647 \u0628\u0647 \u062f\u0646\u0628\u0627\u0644 \u0622\u0646 \u0646\u0627\u0645 \u0645\u0646\u0637\u0642\u0647 \u0627\u06cc \u06a9\u0647 \u0645\u06cc \u062e\u0648\u0627\u0647\u06cc\u062f \u067e\u06cc\u0634 \u0641\u0631\u0636 \u06a9\u0646\u06cc\u062f.<\/p>\n<p>\u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644\u060c \u0628\u0631\u0627\u06cc \u062a\u063a\u06cc\u06cc\u0631 \u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u0628\u0647 \u062e\u0627\u0646\u0647\u060c \u0628\u0627\u06cc\u062f \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0631\u0627 \u0627\u062c\u0631\u0627 \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --set-default-zone=home<\/code><\/pre>\n<p>\u0628\u0631\u0631\u0633\u06cc \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u0628\u0627:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --get-default-zone<\/code><\/pre>\n<pre tabindex=\"0\"><code class=\"language-output\" data-lang=\"output\">home\n<\/code><\/pre>\n<h2 id=\"opening-a-port-or-service\"><span class=\"ez-toc-section\" id=\"%d8%a8%d8%a7%d8%b2_%da%a9%d8%b1%d8%af%d9%86_%db%8c%da%a9_%d8%a8%d9%86%d8%af%d8%b1_%db%8c%d8%a7_%d8%b3%d8%b1%d9%88%db%8c%d8%b3\"><\/span>\u0628\u0627\u0632 \u06a9\u0631\u062f\u0646 \u06cc\u06a9 \u0628\u0646\u062f\u0631 \u06cc\u0627 \u0633\u0631\u0648\u06cc\u0633 <span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u0628\u0627 FirewallD \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u062a\u0631\u0627\u0641\u06cc\u06a9 \u067e\u0648\u0631\u062a \u0647\u0627\u06cc \u062e\u0627\u0635 \u0631\u0627 \u0628\u0631 \u0627\u0633\u0627\u0633 \u0642\u0648\u0627\u0646\u06cc\u0646 \u0627\u0632 \u067e\u06cc\u0634 \u062a\u0639\u0631\u06cc\u0641 \u0634\u062f\u0647 \u0628\u0647 \u0646\u0627\u0645 \u0633\u0631\u0648\u06cc\u0633 \u0647\u0627 \u0645\u062c\u0627\u0632 \u06a9\u0646\u06cc\u062f.<\/p>\n<p>\u0628\u0631\u0627\u06cc \u062f\u0631\u06cc\u0627\u0641\u062a \u0644\u06cc\u0633\u062a\u06cc \u0627\u0632 \u062a\u0645\u0627\u0645 \u062e\u062f\u0645\u0627\u062a \u067e\u06cc\u0634 \u0641\u0631\u0636 \u0645\u0648\u062c\u0648\u062f\u060c \u0646\u0648\u0639:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --get-services<\/code><\/pre>\n<figure class=\"relative\">\n<div class=\"relative block w-full mx-auto my-0\">\n<div class=\"bg-gray-100 absolute inset-0 w-full h-full m-auto overflow-hidden\"><img decoding=\"async\" class=\"absolute inset-0 w-full h-full m-auto\" loading=\"lazy\" src=\"https:\/\/rasanegar.com\/blog\/wp-content\/uploads\/2023\/12\/1703668274_355_\u0646\u062d\u0648\u0647-\u0631\u0627\u0647-\u0627\u0646\u062f\u0627\u0632\u06cc-\u0641\u0627\u06cc\u0631\u0648\u0627\u0644-\u0628\u0627-FirewallD-\u062f\u0631-CentOS-7.jpg\" alt=\"\u062e\u062f\u0645\u0627\u062a \u0641\u0627\u06cc\u0631\u0648\u0627\u0644\" title=\"\"><\/div>\n<\/div>\n<\/figure>\n<p>\u0628\u0627 \u0628\u0627\u0632 \u06a9\u0631\u062f\u0646 \u0641\u0627\u06cc\u0644 xml \u0645\u0631\u062a\u0628\u0637 \u062f\u0631 \u062f\u0627\u062e\u0644 \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0628\u06cc\u0634\u062a\u0631\u06cc \u062f\u0631 \u0645\u0648\u0631\u062f \u0647\u0631 \u0633\u0631\u0648\u06cc\u0633 \u0628\u06cc\u0627\u0628\u06cc\u062f <code>\/usr\/lib\/firewalld\/services<\/code> \u0641\u0647\u0631\u0633\u062a \u0631\u0627\u0647\u0646\u0645\u0627.  \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644\u060c \u0633\u0631\u0648\u06cc\u0633 HTTP \u0628\u0647 \u0635\u0648\u0631\u062a \u0632\u06cc\u0631 \u062a\u0639\u0631\u06cc\u0641 \u0634\u062f\u0647 \u0627\u0633\u062a:<\/p>\n<div class=\"code-label\">\/usr\/lib\/firewalld\/services\/http.xml<\/div>\n<div class=\"highlight\">\n<pre tabindex=\"0\" class=\"chroma\"><code class=\"language-xml\" data-lang=\"xml\"><span class=\"line\"><span class=\"cl\"><span class=\"cp\">&lt;?xml version=\"1.0\" encoding=\"utf-8\"?&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\"><span class=\"nt\">&lt;service&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\">  <span class=\"nt\">&lt;short&gt;<\/span>WWW (HTTP)<span class=\"nt\">&lt;\/short&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\">  <span class=\"nt\">&lt;description&gt;<\/span>HTTP is the protocol used to serve Web pages. If you plan to make your Web server publicly available, enable this option. This option is not required for viewing pages locally or developing Web pages.<span class=\"nt\">&lt;\/description&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\">  <span class=\"nt\">&lt;port<\/span> <span class=\"na\">protocol=<\/span><span class=\"s\">\"tcp\"<\/span> <span class=\"na\">port=<\/span><span class=\"s\">\"80\"<\/span><span class=\"nt\">\/&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\"><span class=\"nt\">&lt;\/service&gt;<\/span>\n<\/span><\/span><\/code><\/pre>\n<\/div>\n<p>\u0628\u0631\u0627\u06cc \u0645\u062c\u0627\u0632 \u06a9\u0631\u062f\u0646 \u062a\u0631\u0627\u0641\u06cc\u06a9 HTTP \u0648\u0631\u0648\u062f\u06cc (\u067e\u0648\u0631\u062a 80) \u0628\u0631\u0627\u06cc \u0631\u0627\u0628\u0637\u200c\u0647\u0627\u06cc \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0645\u0646\u0637\u0642\u0647 \u0639\u0645\u0648\u0645\u06cc\u060c \u0641\u0642\u0637 \u0628\u0631\u0627\u06cc \u062c\u0644\u0633\u0647 \u0641\u0639\u0644\u06cc (\u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0632\u0645\u0627\u0646 \u0627\u062c\u0631\u0627) \u0646\u0648\u0639:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=public --add-service=http<\/code><\/pre>\n<div class=\"note bg-yellow-100 dark:bg-gray-800 border-l-4 border-yellow-400 dark:text-yellow-200 p-6 my-6\">\n<div class=\"flex\">\n<div class=\"font-sans w-full\">\u0627\u06af\u0631 \u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634\u200c\u0641\u0631\u0636 \u0631\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u0645\u06cc\u200c\u062f\u0647\u06cc\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0622\u0646 \u0631\u0627 \u06a9\u0646\u0627\u0631 \u0628\u06af\u0630\u0627\u0631\u06cc\u062f <code>--zone<\/code> \u06af\u0632\u06cc\u0646\u0647.<\/div>\n<\/div>\n<\/div>\n<p>\u0628\u0631\u0627\u06cc \u062a\u0623\u06cc\u06cc\u062f \u0627\u06cc\u0646\u06a9\u0647 \u0633\u0631\u0648\u06cc\u0633 \u0628\u0627 \u0645\u0648\u0641\u0642\u06cc\u062a \u0627\u0636\u0627\u0641\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a \u0627\u0632 <code>--list-services<\/code> \u06af\u0632\u06cc\u0646\u0647:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=public --list-services<\/code><\/pre>\n<pre tabindex=\"0\"><code class=\"language-output\" data-lang=\"output\">ssh dhcpv6-client http\n<\/code><\/pre>\n<p>\u0627\u06af\u0631 \u0645\u06cc \u062e\u0648\u0627\u0647\u06cc\u062f \u067e\u0648\u0631\u062a 80 \u0631\u0627 \u067e\u0633 \u0627\u0632 \u0631\u0627\u0647 \u0627\u0646\u062f\u0627\u0632\u06cc \u0645\u062c\u062f\u062f \u0628\u0627\u0632 \u0646\u06af\u0647 \u062f\u0627\u0631\u06cc\u062f\u060c \u0628\u0627\u06cc\u062f \u0647\u0645\u0627\u0646 \u062f\u0633\u062a\u0648\u0631 \u0631\u0627 \u06cc\u06a9 \u0628\u0627\u0631 \u062f\u06cc\u06af\u0631 \u062a\u0627\u06cc\u067e \u06a9\u0646\u06cc\u062f \u0627\u0645\u0627 \u0627\u06cc\u0646 \u0628\u0627\u0631 \u0628\u0627 <code>--permanent<\/code> \u06af\u0632\u06cc\u0646\u0647:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --permanent --zone=public --add-service=http<\/code><\/pre>\n<p>\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f <code>--list-services<\/code> \u0647\u0645\u0631\u0627\u0647 \u0628\u0627 <code>--permanent<\/code> \u06af\u0632\u06cc\u0646\u0647 \u0627\u06cc \u0628\u0631\u0627\u06cc \u062a\u0623\u06cc\u06cc\u062f \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u0634\u0645\u0627:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --permanent --zone=public --list-services<\/code><\/pre>\n<pre tabindex=\"0\"><code class=\"language-output\" data-lang=\"output\">ssh dhcpv6-client http\n<\/code><\/pre>\n<p>\u0646\u062d\u0648 \u062d\u0630\u0641 \u0633\u0631\u0648\u06cc\u0633 \u0645\u0627\u0646\u0646\u062f \u0647\u0646\u06af\u0627\u0645 \u0627\u0641\u0632\u0648\u062f\u0646 \u0633\u0631\u0648\u06cc\u0633 \u0627\u0633\u062a.  \u0641\u0642\u0637 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646 <code>--remove-service<\/code> \u0628\u0647 \u062c\u0627\u06cc <code>--add-service<\/code> \u06af\u0632\u06cc\u0646\u0647:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=public --remove-service=http --permanent<\/code><\/pre>\n<p>\u062f\u0633\u062a\u0648\u0631 \u0628\u0627\u0644\u0627 \u0633\u0631\u0648\u06cc\u0633 http \u0631\u0627 \u0627\u0632 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u062f\u0627\u0626\u0645\u06cc \u0645\u0646\u0637\u0642\u0647 \u0639\u0645\u0648\u0645\u06cc \u062d\u0630\u0641 \u0645\u06cc \u06a9\u0646\u062f.<\/p>\n<p>\u0627\u06af\u0631 \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0627\u06cc \u0645\u0627\u0646\u0646\u062f Plex Media Server \u0631\u0627 \u0627\u062c\u0631\u0627 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f \u06a9\u0647 \u0633\u0631\u0648\u06cc\u0633 \u0645\u0646\u0627\u0633\u0628\u06cc \u0628\u0631\u0627\u06cc \u0622\u0646 \u0648\u062c\u0648\u062f \u0646\u062f\u0627\u0631\u062f\u060c \u0686\u0647\u061f<\/p>\n<p>\u062f\u0631 \u0686\u0646\u06cc\u0646 \u0634\u0631\u0627\u06cc\u0637\u06cc\u060c \u0634\u0645\u0627 \u062f\u0648 \u06af\u0632\u06cc\u0646\u0647 \u062f\u0627\u0631\u06cc\u062f.  \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u067e\u0648\u0631\u062a \u0647\u0627\u06cc \u0645\u0646\u0627\u0633\u0628 \u0631\u0627 \u0628\u0627\u0632 \u06a9\u0646\u06cc\u062f \u06cc\u0627 \u06cc\u06a9 \u0633\u0631\u0648\u06cc\u0633 FirewallD \u062c\u062f\u06cc\u062f \u062a\u0639\u0631\u06cc\u0641 \u06a9\u0646\u06cc\u062f.<\/p>\n<p>\u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644\u060c \u0633\u0631\u0648\u0631 Plex \u0628\u0647 \u067e\u0648\u0631\u062a 32400 \u06af\u0648\u0634 \u0645\u06cc \u062f\u0647\u062f \u0648 \u0627\u0632 TCP \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u062f\u060c \u0628\u0631\u0627\u06cc \u0628\u0627\u0632 \u06a9\u0631\u062f\u0646 \u067e\u0648\u0631\u062a \u062f\u0631 \u0645\u0646\u0637\u0642\u0647 \u0639\u0645\u0648\u0645\u06cc \u0628\u0631\u0627\u06cc \u062c\u0644\u0633\u0647 \u0641\u0639\u0644\u06cc \u0627\u0632 <code>--add-port=<\/code> \u06af\u0632\u06cc\u0646\u0647:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=public --add-port=32400\/tcp<\/code><\/pre>\n<div class=\"note bg-yellow-100 dark:bg-gray-800 border-l-4 border-yellow-400 dark:text-yellow-200 p-6 my-6\">\n<div class=\"flex\">\n<div class=\"font-sans w-full\">\u067e\u0631\u0648\u062a\u06a9\u0644 \u0647\u0627 \u0645\u06cc \u062a\u0648\u0627\u0646\u0646\u062f \u0647\u0631 \u062f\u0648 \u0628\u0627\u0634\u0646\u062f <code>tcp<\/code> \u06cc\u0627 <code>udp<\/code>.<\/div>\n<\/div>\n<\/div>\n<p>\u0628\u0631\u0627\u06cc \u062a\u0623\u06cc\u06cc\u062f \u0627\u06cc\u0646\u06a9\u0647 \u067e\u0648\u0631\u062a \u0628\u0627 \u0645\u0648\u0641\u0642\u06cc\u062a \u0627\u0636\u0627\u0641\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a \u0627\u0632 <code>--list-ports<\/code> \u06af\u0632\u06cc\u0646\u0647:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=public --list-ports<\/code><\/pre>\n<pre tabindex=\"0\"><code class=\"language-output\" data-lang=\"output\">32400\/tcp\n<\/code><\/pre>\n<p>\u0628\u0631\u0627\u06cc \u062d\u0641\u0638 \u0628\u0646\u062f\u0631 <code>32400<\/code> \u067e\u0633 \u0627\u0632 \u0631\u0627\u0647 \u0627\u0646\u062f\u0627\u0632\u06cc \u0645\u062c\u062f\u062f\u060c \u0642\u0627\u0646\u0648\u0646 \u0631\u0627 \u0628\u0627 \u0627\u062c\u0631\u0627\u06cc \u0647\u0645\u0627\u0646 \u062f\u0633\u062a\u0648\u0631 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u062f\u0633\u062a\u0648\u0631 \u0628\u0647 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u062f\u0627\u0626\u0645\u06cc \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f <code>--permanent<\/code> \u06af\u0632\u06cc\u0646\u0647.<\/p>\n<p>\u0633\u06cc\u0646\u062a\u06a9\u0633 \u062d\u0630\u0641 \u067e\u0648\u0631\u062a \u0645\u0627\u0646\u0646\u062f \u0647\u0646\u06af\u0627\u0645 \u0627\u0641\u0632\u0648\u062f\u0646 \u067e\u0648\u0631\u062a \u0627\u0633\u062a.  \u0641\u0642\u0637 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646 <code>--remove-port<\/code> \u0628\u0647 \u062c\u0627\u06cc <code>--add-port<\/code> \u06af\u0632\u06cc\u0646\u0647.<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=public --remove-port=32400\/tcp<\/code><\/pre>\n<h3 id=\"creating-a-new-firewalld-service\"><span class=\"ez-toc-section\" id=\"%d8%a7%db%8c%d8%ac%d8%a7%d8%af_%db%8c%da%a9_%d8%b3%d8%b1%d9%88%db%8c%d8%b3_firewalld_%d8%ac%d8%af%db%8c%d8%af\"><\/span>\u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0633\u0631\u0648\u06cc\u0633 FirewallD \u062c\u062f\u06cc\u062f <span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u0647\u0645\u0627\u0646\u0637\u0648\u0631 \u06a9\u0647 \u0642\u0628\u0644\u0627\u064b \u0630\u06a9\u0631 \u06a9\u0631\u062f\u06cc\u0645\u060c \u0633\u0631\u0648\u06cc\u0633 \u0647\u0627\u06cc \u067e\u06cc\u0634 \u0641\u0631\u0636 \u062f\u0631 \u0642\u0633\u0645\u062a \u0630\u062e\u06cc\u0631\u0647 \u0645\u06cc \u0634\u0648\u0646\u062f <code>\/usr\/lib\/firewalld\/services<\/code> \u0641\u0647\u0631\u0633\u062a \u0631\u0627\u0647\u0646\u0645\u0627.  \u0633\u0627\u062f\u0647 \u062a\u0631\u06cc\u0646 \u0631\u0627\u0647 \u0628\u0631\u0627\u06cc \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0633\u0631\u0648\u06cc\u0633 \u062c\u062f\u06cc\u062f \u06a9\u067e\u06cc \u06a9\u0631\u062f\u0646 \u06cc\u06a9 \u0641\u0627\u06cc\u0644 \u0633\u0631\u0648\u06cc\u0633 \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0622\u0646 \u0627\u0633\u062a <code>\/etc\/firewalld\/services<\/code> \u062f\u0627\u06cc\u0631\u06a9\u062a\u0648\u0631\u06cc\u060c \u06a9\u0647 \u0645\u062d\u0644 \u0633\u0631\u0648\u06cc\u0633 \u0647\u0627\u06cc \u0627\u06cc\u062c\u0627\u062f \u0634\u062f\u0647 \u062a\u0648\u0633\u0637 \u06a9\u0627\u0631\u0628\u0631 \u0648 \u062a\u063a\u06cc\u06cc\u0631 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0641\u0627\u06cc\u0644 \u0627\u0633\u062a.<\/p>\n<p>\u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644\u060c \u0628\u0631\u0627\u06cc \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u062a\u0639\u0631\u06cc\u0641 \u0633\u0631\u0648\u06cc\u0633 \u0628\u0631\u0627\u06cc Plex Media Server\u060c \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u0645 \u0627\u0632 \u0641\u0627\u06cc\u0644 \u0633\u0631\u0648\u06cc\u0633 SSH \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo cp \/usr\/lib\/firewalld\/services\/ssh.xml \/etc\/firewalld\/services\/plexmediaserver.xml<\/code><\/pre>\n<p>\u062c\u062f\u06cc\u062f \u0627\u06cc\u062c\u0627\u062f \u0634\u062f\u0647 \u0631\u0627 \u0628\u0627\u0632 \u06a9\u0646\u06cc\u062f <code>plexmediaserver.xml<\/code> \u0631\u0627 \u0641\u0627\u06cc\u0644 \u06a9\u0646\u06cc\u062f \u0648 \u0646\u0627\u0645 \u06a9\u0648\u062a\u0627\u0647 \u0648 \u062a\u0648\u0636\u06cc\u062d\u0627\u062a \u0633\u0631\u0648\u06cc\u0633 \u0631\u0627 \u062f\u0631 \u062f\u0627\u062e\u0644 \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u06cc\u062f <code>&lt;short&gt;<\/code> \u0648 <code>&lt;description&gt;<\/code> \u0628\u0631\u0686\u0633\u0628 \u0647\u0627  \u0645\u0647\u0645\u062a\u0631\u06cc\u0646 \u0628\u0631\u0686\u0633\u0628\u06cc \u06a9\u0647 \u0628\u0627\u06cc\u062f \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u06cc\u062f \u0627\u06cc\u0646 \u0627\u0633\u062a <code>port<\/code> \u062a\u06af\u060c \u06a9\u0647 \u0634\u0645\u0627\u0631\u0647 \u067e\u0648\u0631\u062a \u0648 \u067e\u0631\u0648\u062a\u06a9\u0644\u06cc \u0631\u0627 \u06a9\u0647 \u0645\u06cc \u062e\u0648\u0627\u0647\u06cc\u062f \u0628\u0627\u0632 \u06a9\u0646\u06cc\u062f \u0631\u0627 \u0645\u0634\u062e\u0635 \u0645\u06cc \u06a9\u0646\u062f.<\/p>\n<p>\u062f\u0631 \u0645\u062b\u0627\u0644 \u0632\u06cc\u0631 \u062f\u0631 \u062d\u0627\u0644 \u0628\u0627\u0632 \u06a9\u0631\u062f\u0646 \u067e\u0648\u0631\u062a \u0647\u0627 \u0647\u0633\u062a\u06cc\u0645 <code>1900<\/code> UDP \u0648 <code>32400<\/code> TCP.<\/p>\n<div class=\"code-label\">\/etc\/firewalld\/services\/plexmediaserver.xml<\/div>\n<div class=\"highlight\">\n<pre tabindex=\"0\" class=\"chroma\"><code class=\"language-xml\" data-lang=\"xml\"><span class=\"line\"><span class=\"cl\"><span class=\"cp\">&lt;?xml version=\"1.0\" encoding=\"utf-8\"?&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\"><span class=\"nt\">&lt;service<\/span> <span class=\"na\">version=<\/span><span class=\"s\">\"1.0\"<\/span><span class=\"nt\">&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\"><span class=\"nt\">&lt;short&gt;<\/span>plexmediaserver<span class=\"nt\">&lt;\/short&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\"><span class=\"nt\">&lt;description&gt;<\/span>Plex is a streaming media server that brings all your video, music and photo collections together and stream them to your devices at anytime and from anywhere.<span class=\"nt\">&lt;\/description&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\"><span class=\"nt\">&lt;port<\/span> <span class=\"na\">protocol=<\/span><span class=\"s\">\"udp\"<\/span> <span class=\"na\">port=<\/span><span class=\"s\">\"1900\"<\/span><span class=\"nt\">\/&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\"><span class=\"nt\">&lt;port<\/span> <span class=\"na\">protocol=<\/span><span class=\"s\">\"tcp\"<\/span> <span class=\"na\">port=<\/span><span class=\"s\">\"32400\"<\/span><span class=\"nt\">\/&gt;<\/span>\n<\/span><\/span><span class=\"line\"><span class=\"cl\"><span class=\"nt\">&lt;\/service&gt;<\/span>\n<\/span><\/span><\/code><\/pre>\n<\/div>\n<p>\u0641\u0627\u06cc\u0644 \u0631\u0627 \u0630\u062e\u06cc\u0631\u0647 \u06a9\u0631\u062f\u0647 \u0648 \u0633\u0631\u0648\u06cc\u0633 FirewallD \u0631\u0627 \u0645\u062c\u062f\u062f\u0627\u064b \u0628\u0627\u0631\u06af\u06cc\u0631\u06cc \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --reload<\/code><\/pre>\n<p>\u0627\u06a9\u0646\u0648\u0646 \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u0632 <code>plexmediaserver<\/code> \u062e\u062f\u0645\u0627\u062a \u062f\u0631 \u0645\u0646\u0627\u0637\u0642 \u0634\u0645\u0627 \u0645\u0627\u0646\u0646\u062f \u0647\u0631 \u0633\u0631\u0648\u06cc\u0633 \u062f\u06cc\u06af\u0631\u06cc..<\/p>\n<h2 id=\"forwarding-port-with-firewalld\"><span class=\"ez-toc-section\" id=\"%d9%be%d9%88%d8%b1%d8%aa_%d8%ad%d9%85%d9%84_%d9%88_%d9%86%d9%82%d9%84_%d8%a8%d8%a7_%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84\"><\/span>\u067e\u0648\u0631\u062a \u062d\u0645\u0644 \u0648 \u0646\u0642\u0644 \u0628\u0627 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 <span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u0628\u0631\u0627\u06cc \u0647\u062f\u0627\u06cc\u062a \u062a\u0631\u0627\u0641\u06cc\u06a9 \u0627\u0632 \u06cc\u06a9 \u067e\u0648\u0631\u062a \u0628\u0647 \u067e\u0648\u0631\u062a \u06cc\u0627 \u0622\u062f\u0631\u0633 \u062f\u06cc\u06af\u0631\u060c \u0627\u0628\u062a\u062f\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06af\u0632\u06cc\u0646\u0647\u060c \u062a\u063a\u06cc\u06cc\u0631 \u0638\u0627\u0647\u0631 \u0631\u0627 \u0628\u0631\u0627\u06cc \u0645\u0646\u0637\u0642\u0647 \u0645\u0648\u0631\u062f \u0646\u0638\u0631 \u0641\u0639\u0627\u0644 \u06a9\u0646\u06cc\u062f <code>--add-masquerade<\/code> \u062a\u0639\u0648\u06cc\u0636.  \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644 \u0628\u0631\u0627\u06cc \u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0646 maskarading \u0628\u0631\u0627\u06cc <code>external<\/code> \u0646\u0648\u0639 \u0645\u0646\u0637\u0642\u0647:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=external --add-masquerade<\/code><\/pre>\n<ul>\n<li><strong>\u0627\u0646\u062a\u0642\u0627\u0644 \u062a\u0631\u0627\u0641\u06cc\u06a9 \u0627\u0632 \u06cc\u06a9 \u067e\u0648\u0631\u062a \u0628\u0647 \u067e\u0648\u0631\u062a \u062f\u06cc\u06af\u0631 \u062f\u0631 \u0647\u0645\u0627\u0646 \u0633\u0631\u0648\u0631<\/strong><\/li>\n<\/ul>\n<p>\u062f\u0631 \u0645\u062b\u0627\u0644 \u0632\u06cc\u0631 \u0645\u0627 \u062a\u0631\u0627\u0641\u06cc\u06a9 \u0631\u0627 \u0627\u0632 \u067e\u0648\u0631\u062a \u0641\u0648\u0631\u0648\u0627\u0631\u062f \u0645\u06cc \u06a9\u0646\u06cc\u0645 <code>80<\/code> \u0628\u0647 \u0628\u0646\u062f\u0631 <code>8080<\/code> \u062f\u0631 \u0647\u0645\u0627\u0646 \u0633\u0631\u0648\u0631:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=external --add-forward-port=port=80:proto=tcp:toport=8080<\/code><\/pre>\n<ul>\n<li><strong>\u062a\u0631\u0627\u0641\u06cc\u06a9 \u0631\u0627 \u0628\u0647 \u0633\u0631\u0648\u0631 \u062f\u06cc\u06af\u0631\u06cc \u0647\u062f\u0627\u06cc\u062a \u06a9\u0646\u06cc\u062f<\/strong><\/li>\n<\/ul>\n<p>\u062f\u0631 \u0645\u062b\u0627\u0644 \u0632\u06cc\u0631 \u0645\u0627 \u062a\u0631\u0627\u0641\u06cc\u06a9 \u0631\u0627 \u0627\u0632 \u067e\u0648\u0631\u062a \u0641\u0648\u0631\u0648\u0627\u0631\u062f \u0645\u06cc \u06a9\u0646\u06cc\u0645 <code>80<\/code> \u0628\u0647 \u0628\u0646\u062f\u0631 <code>80<\/code> \u0631\u0648\u06cc \u0633\u0631\u0648\u0631 \u0628\u0627 IP <code>10.10.10.2<\/code>:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=external --add-forward-port=port=80:proto=tcp:toaddr=10.10.10.2<\/code><\/pre>\n<ul>\n<li><strong>\u062a\u0631\u0627\u0641\u06cc\u06a9 \u0631\u0627 \u0628\u0647 \u0633\u0631\u0648\u0631 \u062f\u06cc\u06af\u0631\u06cc \u062f\u0631 \u067e\u0648\u0631\u062a \u062f\u06cc\u06af\u0631\u06cc \u0647\u062f\u0627\u06cc\u062a \u06a9\u0646\u06cc\u062f<\/strong><\/li>\n<\/ul>\n<p>\u062f\u0631 \u0645\u062b\u0627\u0644 \u0632\u06cc\u0631 \u0645\u0627 \u062a\u0631\u0627\u0641\u06cc\u06a9 \u0631\u0627 \u0627\u0632 \u067e\u0648\u0631\u062a \u0641\u0648\u0631\u0648\u0627\u0631\u062f \u0645\u06cc \u06a9\u0646\u06cc\u0645 <code>80<\/code> \u0628\u0647 \u0628\u0646\u062f\u0631 <code>8080<\/code> \u0631\u0648\u06cc \u0633\u0631\u0648\u0631 \u0628\u0627 IP <code>10.10.10.2<\/code>:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=external --add-forward-port=port=80:proto=tcp:toport=8080:toaddr=10.10.10.2<\/code><\/pre>\n<p>\u0627\u06af\u0631 \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u06cc\u062f \u0641\u0648\u0631\u0648\u0627\u0631\u062f \u0631\u0627 \u062f\u0627\u0626\u0645\u06cc \u06a9\u0646\u06cc\u062f\u060c \u0641\u0642\u0637 \u0622\u0646 \u0631\u0627 \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f <code>--permanent<\/code> \u06af\u0632\u06cc\u0646\u0647.<\/p>\n<h2 id=\"creating-a-ruleset-with-firewalld\"><span class=\"ez-toc-section\" id=\"%d8%a7%db%8c%d8%ac%d8%a7%d8%af_%db%8c%da%a9_%d9%85%d8%ac%d9%85%d9%88%d8%b9%d9%87_%d9%82%d9%88%d8%a7%d9%86%db%8c%d9%86_%d8%a8%d8%a7_%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84d\"><\/span>\u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0645\u062c\u0645\u0648\u0639\u0647 \u0642\u0648\u0627\u0646\u06cc\u0646 \u0628\u0627 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644D <span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u062f\u0631 \u0645\u062b\u0627\u0644 \u0632\u06cc\u0631\u060c \u0631\u0648\u0634 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u062e\u0648\u062f \u0631\u0627 \u062f\u0631 \u0635\u0648\u0631\u062a\u06cc \u06a9\u0647 \u0633\u0631\u0648\u0631 \u0648\u0628 \u0631\u0627 \u0627\u062c\u0631\u0627 \u0645\u06cc\u200c\u06a9\u0631\u062f\u06cc\u062f\u060c \u0646\u0634\u0627\u0646 \u062e\u0648\u0627\u0647\u06cc\u0645 \u062f\u0627\u062f.  \u0645\u0627 \u0641\u0631\u0636 \u0645\u06cc \u06a9\u0646\u06cc\u0645 \u0633\u0631\u0648\u0631 \u0634\u0645\u0627 \u0641\u0642\u0637 \u06cc\u06a9 \u0631\u0627\u0628\u0637 \u062f\u0627\u0631\u062f <code>eth0<\/code>\u060c \u0648 \u0645\u06cc \u062e\u0648\u0627\u0647\u06cc\u062f \u062a\u0631\u0627\u0641\u06cc\u06a9 \u0648\u0631\u0648\u062f\u06cc \u0631\u0627 \u0641\u0642\u0637 \u062f\u0631 \u067e\u0648\u0631\u062a \u0647\u0627\u06cc SSH\u060c HTTP \u0648 HTTPS \u0645\u062c\u0627\u0632 \u06a9\u0646\u06cc\u062f.<\/p>\n<ol>\n<li>\n<p>\u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u0631\u0627 \u0628\u0647 dmz \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u06cc\u062f<\/p>\n<p>\u0645\u0627 \u0627\u0632 \u0645\u0646\u0637\u0642\u0647 dmz (\u063a\u06cc\u0631 \u0646\u0638\u0627\u0645\u06cc \u0634\u062f\u0647) \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u0632\u06cc\u0631\u0627 \u0628\u0647 \u0637\u0648\u0631 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u0641\u0642\u0637 \u0628\u0647 \u062a\u0631\u0627\u0641\u06cc\u06a9 SSH \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc \u062f\u0647\u062f.  \u0628\u0631\u0627\u06cc \u062a\u063a\u06cc\u06cc\u0631 \u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u0628\u0647 dmz \u0648 \u0627\u062e\u062a\u0635\u0627\u0635 \u0622\u0646 \u0628\u0647 <code>eth0<\/code> \u0631\u0627\u0628\u0637\u060c \u062f\u0633\u062a\u0648\u0631\u0627\u062a \u0632\u06cc\u0631 \u0631\u0627 \u0627\u062c\u0631\u0627 \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --set-default-zone=dmz<\/code><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=dmz --add-interface=eth0<\/code><\/pre>\n<\/li>\n<li>\n<p>\u067e\u0648\u0631\u062a \u0647\u0627\u06cc HTTP \u0648 HTTPS \u0631\u0627 \u0628\u0627\u0632 \u06a9\u0646\u06cc\u062f:<\/p>\n<p>\u0628\u0631\u0627\u06cc \u0628\u0627\u0632 \u06a9\u0631\u062f\u0646 \u067e\u0648\u0631\u062a \u0647\u0627\u06cc HTTP \u0648 HTTPS \u0642\u0648\u0627\u0646\u06cc\u0646 \u0633\u0631\u0648\u06cc\u0633 \u062f\u0627\u0626\u0645\u06cc \u0631\u0627 \u0628\u0647 \u0645\u0646\u0637\u0642\u0647 dmz \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --permanent --zone=dmz --add-service=http<\/code><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --permanent --zone=dmz --add-service=https<\/code><\/pre>\n<p>\u0628\u0627 \u0628\u0627\u0631\u06af\u0630\u0627\u0631\u06cc \u0645\u062c\u062f\u062f \u0641\u0627\u06cc\u0631\u0648\u0627\u0644\u060c \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u0631\u0627 \u0628\u0644\u0627\u0641\u0627\u0635\u0644\u0647 \u0627\u0639\u0645\u0627\u0644 \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --reload<\/code><\/pre>\n<\/li>\n<li>\n<p>\u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u0631\u0627 \u062a\u0623\u06cc\u06cc\u062f \u06a9\u0646\u06cc\u062f<\/p>\n<p>\u0628\u0631\u0627\u06cc \u0628\u0631\u0631\u0633\u06cc \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0645\u0646\u0637\u0642\u0647 dmz \u0646\u0648\u0639:<\/p>\n<pre class=\"terminal\"><code class=\"terminal-line\" prefix=\"$\">sudo firewall-cmd --zone=dmz --list-all<\/code><\/pre>\n<pre tabindex=\"0\"><code class=\"language-output\" data-lang=\"output\">dmz (active)\n  target: default\n  icmp-block-inversion: no\n  interfaces: eth0\n  sources:\n  services: ssh http https\n  ports:\n  protocols:\n  masquerade: no\n  forward-ports:\n  source-ports:\n  icmp-blocks:\n  rich rules:<\/code><\/pre>\n<p>\u062e\u0631\u0648\u062c\u06cc \u0628\u0627\u0644\u0627 \u0628\u0647 \u0645\u0627 \u0645\u06cc \u06af\u0648\u06cc\u062f \u06a9\u0647 dmz \u0645\u0646\u0637\u0642\u0647 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u0627\u0633\u062a \u06a9\u0647 \u0628\u0647 \u0622\u0646 \u0627\u0639\u0645\u0627\u0644 \u0645\u06cc \u0634\u0648\u062f <code>eth0<\/code> \u0631\u0627\u0628\u0637 \u0648 \u067e\u0648\u0631\u062a \u0647\u0627\u06cc ssh (22) http (80) \u0648 https (443) \u0628\u0627\u0632 \u0647\u0633\u062a\u0646\u062f.<\/p>\n<\/li>\n<\/ol>\n<h2 id=\"conclusion\"><span class=\"ez-toc-section\" id=\"%d9%86%d8%aa%db%8c%d8%ac%d9%87\"><\/span>\u0646\u062a\u06cc\u062c\u0647 <span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u0634\u0645\u0627 \u06cc\u0627\u062f \u06af\u0631\u0641\u062a\u0647 \u0627\u06cc\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0633\u0631\u0648\u06cc\u0633 FirewallD \u0631\u0627 \u062f\u0631 \u0633\u06cc\u0633\u062a\u0645 CentOS \u062e\u0648\u062f \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0648 \u0645\u062f\u06cc\u0631\u06cc\u062a \u06a9\u0646\u06cc\u062f.<\/p>\n<p>\u0627\u0637\u0645\u06cc\u0646\u0627\u0646 \u062d\u0627\u0635\u0644 \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u062a\u0645\u0627\u0645 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0648\u0631\u0648\u062f\u06cc \u0631\u0627 \u06a9\u0647 \u0628\u0631\u0627\u06cc \u0639\u0645\u0644\u06a9\u0631\u062f \u0635\u062d\u06cc\u062d \u0633\u06cc\u0633\u062a\u0645 \u0634\u0645\u0627 \u0636\u0631\u0648\u0631\u06cc \u0647\u0633\u062a\u0646\u062f\u060c \u0645\u062c\u0627\u0632 \u06a9\u0646\u06cc\u062f\u060c \u062f\u0631 \u062d\u0627\u0644\u06cc \u06a9\u0647 \u062a\u0645\u0627\u0645 \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u063a\u06cc\u0631 \u0636\u0631\u0648\u0631\u06cc \u0631\u0627 \u0645\u062d\u062f\u0648\u062f \u06a9\u0646\u06cc\u062f.<\/p>\n<p>\u0627\u06af\u0631 \u0633\u0648\u0627\u0644\u06cc \u062f\u0627\u0631\u06cc\u062f\u060c \u062f\u0631 \u0632\u06cc\u0631 \u0646\u0638\u0631 \u062f\u0647\u06cc\u062f.<\/p>\n<div class=\"flex flex-wrap my-8\">\u0641\u0627\u06cc\u0631\u0648\u0627\u0644\u062f \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0627\u0645\u0646\u06cc\u062a iptables centos<\/div>\n<\/div>\n\n<div>\u0628\u0631\u0627\u06cc \u0646\u06af\u0627\u0631\u0634 \u0628\u062e\u0634\u0647\u0627\u06cc\u06cc \u0627\u0632 \u0627\u06cc\u0646 \u0645\u062a\u0646 \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0627\u0632 \u062a\u0631\u062c\u0645\u0647 \u0645\u0627\u0634\u06cc\u0646\u06cc \u06cc\u0627 \u0647\u0648\u0634 \u0645\u0635\u0646\u0648\u0639\u06cc GPT \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0634\u062f\u0647 \u0628\u0627\u0634\u062f <br \/>\n\u0644\u0637\u0641\u0627 \u062f\u0631 \u0635\u0648\u0631\u062a \u0648\u062c\u0648\u062f \u0645\u0634\u06a9\u0644 \u062f\u0631 \u0645\u062a\u0646 \u06cc\u0627 \u0645\u0641\u0647\u0648\u0645 \u0646\u0628\u0648\u062f\u0646 \u062a\u0648\u0636\u06cc\u062d\u0627\u062a\u060c \u0627\u0632 \u0637\u0631\u06cc\u0642 \u062f\u06a9\u0645\u0647 \u06af\u0632\u0627\u0631\u0634 \u0646\u0648\u0634\u062a\u0627\u0631 \u06cc\u0627 \u062f\u0631\u062c \u0646\u0638\u0631 \u0631\u0648\u06cc \u0627\u06cc\u0646 \u0645\u0637\u0644\u0628 \u0645\u0627 \u0631\u0627 \u0627\u0632 \u062c\u0632\u06cc\u06cc\u0627\u062a \u0645\u0634\u06a9\u0644 \u0645\u0634\u0627\u0647\u062f\u0647 \u0634\u062f\u0647 \u0645\u0637\u0644\u0639 \u06a9\u0646\u06cc\u062f \u062a\u0627 \u0628\u0647 \u0622\u0646 \u0631\u0633\u06cc\u062f\u06af\u06cc \u06a9\u0646\u06cc\u0645\n<\/div>\n<p>\u0632\u0645\u0627\u0646 \u0627\u0646\u062a\u0634\u0627\u0631: 1402-12-27 12:41:03<br \/>\n<\/p>\n\n\n<div class=\"kk-star-ratings kksr-auto kksr-align-center kksr-valign-bottom\"\n    data-payload='{&quot;align&quot;:&quot;center&quot;,&quot;id&quot;:&quot;10102&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;0&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;0&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0627\u0645\u062a\u06cc\u0627\u0632 \u0634\u0645\u0627 \u0628\u0647 \u0627\u06cc\u0646 \u0645\u0637\u0644\u0628&quot;,&quot;legend&quot;:&quot;0\\\/5 (0 \u0631\u0627\u06cc)&quot;,&quot;size&quot;:&quot;30&quot;,&quot;title&quot;:&quot;\u0631\u0648\u0634 \u0631\u0627\u0647 \u0627\u0646\u062f\u0627\u0632\u06cc \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0628\u0627 FirewallD \u062f\u0631 CentOS 7&quot;,&quot;width&quot;:&quot;0&quot;,&quot;_legend&quot;:&quot;{score}\\\/{best} ({count} \u0631\u0627\u06cc)&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}'>\n            \n<div class=\"kksr-stars\">\n    \n<div class=\"kksr-stars-inactive\">\n            <div class=\"kksr-star\" data-star=\"1\" style=\"padding-left: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"2\" style=\"padding-left: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"3\" style=\"padding-left: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"4\" style=\"padding-left: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"5\" style=\"padding-left: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n    <\/div>\n    \n<div class=\"kksr-stars-active\" style=\"width: 0px;\">\n            <div class=\"kksr-star\" style=\"padding-left: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-left: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-left: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-left: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-left: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n    <\/div>\n<\/div>\n                \n\n<div class=\"kksr-legend\" style=\"font-size: 24px;\">\n            <span class=\"kksr-muted\">\u0627\u0645\u062a\u06cc\u0627\u0632 \u0634\u0645\u0627 \u0628\u0647 \u0627\u06cc\u0646 \u0645\u0637\u0644\u0628<\/span>\n    <\/div>\n    <\/div>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">\u0632\u0645\u0627\u0646 \u0644\u0627\u0632\u0645 \u0628\u0631\u0627\u06cc \u0645\u0637\u0627\u0644\u0639\u0647: <\/span> <span class=\"rt-time\"> 7<\/span> <span class=\"rt-label rt-postfix\">\u062f\u0642\u06cc\u0642\u0647<\/span><\/span>\u06cc\u06a9 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0628\u0627 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0645\u0646\u0627\u0633\u0628 \u06cc\u06a9\u06cc \u0627\u0632 \u0645\u0647\u0645\u062a\u0631\u06cc\u0646 \u062c\u0646\u0628\u0647 \u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a \u06a9\u0644\u06cc \u0633\u06cc\u0633\u062a\u0645 \u0627\u0633\u062a. \u0641\u0627\u06cc\u0631\u0648\u0627\u0644D \u06cc\u06a9 \u0631\u0627\u0647 \u062d\u0644 \u06a9\u0627\u0645\u0644 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0627\u0633\u062a \u06a9\u0647 \u0642\u0648\u0627\u0646\u06cc\u0646 iptables \u0633\u06cc\u0633\u062a\u0645 \u0631\u0627 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0645\u06cc \u06a9\u0646\u062f \u0648 \u06cc\u06a9 \u0631\u0627\u0628\u0637 D-Bus \u0628\u0631\u0627\u06cc \u06a9\u0627\u0631 \u0628\u0631 \u0631\u0648\u06cc \u0622\u0646\u0647\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc \u06a9\u0646\u062f. \u0628\u0627 \u0634\u0631\u0648\u0639 CentOS 7\u060c FirewallD \u062c\u0627\u06cc\u06af\u0632\u06cc\u0646 iptables \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0627\u0628\u0632\u0627\u0631 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u067e\u06cc\u0634 \u0641\u0631\u0636 [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":10103,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[202,95,1686],"tags":[2619,1291,1220,348,2536,2538,2539,182,1854],"class_list":["post-10102","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-os","category-linux","category-ai","tag-iptables","tag--linux","tag-1220","tag-348","tag-2536","tag---linux","tag-2539","tag-182","tag-1854"],"acf":[],"_links":{"self":[{"href":"https:\/\/rasanegaar.com\/blog\/wp-json\/wp\/v2\/posts\/10102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rasanegaar.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rasanegaar.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rasanegaar.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/rasanegaar.com\/blog\/wp-json\/wp\/v2\/comments?post=10102"}],"version-history":[{"count":0,"href":"https:\/\/rasanegaar.com\/blog\/wp-json\/wp\/v2\/posts\/10102\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rasanegaar.com\/blog\/wp-json\/wp\/v2\/media\/10103"}],"wp:attachment":[{"href":"https:\/\/rasanegaar.com\/blog\/wp-json\/wp\/v2\/media?parent=10102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rasanegaar.com\/blog\/wp-json\/wp\/v2\/categories?post=10102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rasanegaar.com\/blog\/wp-json\/wp\/v2\/tags?post=10102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}