#!/bin/bash  

firewall-cmd --permanent --zone=public --add-rich-rule="rule family="ipv4" source address="172.16.1.252/32" port protocol="tcp" port="22" accept"

firewall-cmd --permanent --zone=public --add-rich-rule="rule family="ipv4" source address="100.100.100.0/24" port protocol="tcp" port="22" accept"

firewall-cmd --permanent --zone=public --add-rich-rule="rule family="ipv4" source address="0.0.0.0/0" port protocol="tcp" port="22" reject"

firewall-cmd --reload

#sudo firewall-cmd --permanent --zone=public --add-rich-rule 'rule family="ipv4" source address="10.8.0.8" port port=22 protocol=tcp accept'



https://www.51cto.com/article/707726.html