必须同时执行 systemctl stop firewalld 和 systemctl disable firewalld 才能彻底停用,否则重启后自动恢复;SELinux 需修改 /etc/selinux/config 并更新 GRUB 参数后重启才真正生效。
firewalld 临时停用但重启又开?必须两步一起做
只执行 systemctl stop firewalld,防火墙确实会立刻失效,但下次服务器一重启,它就自动回来了。这不是 bug,是 systemd 的默认行为——服务启用状态和运行状态是分开管理的。
-
systemctl stop firewalld:立即终止进程,当前会话生效 -
systemctl disable firewalld:删掉开机自启链接,确保 reboot 后不拉起 - 漏掉第二步,Oracle 客户端连不上
1521端口时,大概率就是它偷偷复活了
SELinux 没关干净,getenforce 显示 Enforcing 却连 ping 都不通
很多人改完 /etc/selinux/config 里的 SELINUX=disabled 就以为完事了,结果 reboot 后 getenforce 还是返回 Enforcing。这是因为配置文件改对了,但内核启动参数没同步——GRUB 里可能还带着 selinux=1 或 enforcing=1。
- 先确认当前状态:
getenforce(返回Disabled才算真关) - 检查启动参数:
cat /proc/cmdline | grep -i selinux,如果看到enforcing=1,得进/etc/default/grub改GRUB_CMDLINE_LINUX,删掉或改成enforcing=0,再grub2-mkconfig -o /boot/grub2/grub.cfg - 临时救急可用
setenforce 0,但它在重启后失效,不能替代配置文件修改
Oracle 连接失败,别急着关防火墙——先查端口是否放行
不是所有 Oracle 连接问题都源于“防火墙开着”,更常见的是 firewalld 默认没放行 1521,而你又没用 rich rule 或 zone 配置,导致连接被静默丢弃。此时关整个防火墙属于过度操作,反而掩盖真实权限模型问题。
- 检查当前开放端口:
firewall-cmd --zone=public --list-ports - 加一条永久规则:
firewall-cmd --permanent --add-port=1521/tcp,再firewall-cmd --reload - 若需限制来源 IP(比如只允许 DBA 主机访问),用 rich rule:
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.3.18" port port="1521" protocol="tcp" accept' - 注意:
--permanent不加的话,--reload会把规则清空
CentOS 6/7 混用命令?service iptables 在 CentOS 7 上基本无效
很多老教程还在写 service iptables stop 或 chkconfig iptables off,但在 CentOS 7+ 默认用 firewalld,iptables 服务压根没装或处于 masked 状态。强行执行只会报 Unit iptables.service could not be found,浪费排查时间。
- 先确认实际使用的防火墙:
systemctl list-unit-files | grep -E "(firewalld|iptables)" - Oracle Linux 7 / RHEL 7 / CentOS 7:认准
firewalld,别碰iptables服务名 - Oracle Linux 6 / RHEL 6:才用
service iptables stop和chkconfig iptables off - 不确定版本?直接看输出:
cat /etc/redhat-release
最常被忽略的一点:改完 SELinux 配置后,必须重启,setenforce 0 只是内存态切换;而 firewalld 的 disable 必须配合 stop,少一个,Oracle 监听就卡在“能 bind 但收不到 SYN”这种玄学状态。










