1.查看开放的端口firewall-cmd --list-ports
2.防护墙放行3306端口firewall-cmd --zone=public --add-port=3306/tcp --permanent
3.重启防火墙,使设置生效systemctl reload firewalld