1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21
| systemctl restart firewalld
firewall-cmd --permanent --zone=trusted --add-source=10.0.0.10 firewall-cmd --permanent --zone=trusted --add-source=10.0.0.11 firewall-cmd --permanent --zone=trusted --add-source=10.0.0.21 firewall-cmd --permanent --zone=trusted --add-source=10.0.0.22
firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 1 -j ACCEPT -m comment --comment "kube-proxy redirects" firewall-cmd --permanent --direct --add-rule ipv4 filter FORWARD 1 -j ACCEPT -m comment --comment "docker subnet"
firewall-cmd --add-masquerade --permanent
firewall-cmd --permanent --zone=public --add-port=30000-32767/tcp
firewall-cmd --reload
|