sudo firewall-cmd --permanent --zone=trusted --add-interface=docker0
sudo firewall-cmd --permanent --zone=public --add-source=172.20.0.0/16
sudo firewall-cmd --permanent --zone=public --add-port=3306/tcp
sudo firewall-cmd --permanent --zone=public --remove-port=1-22/tcp
sudo firewall-cmd --reload
sudo firewall-cmd --zone=public --add-masquerade --permanent
firewall-cmd --list-all
sudo firewall-cmd --get-log-denied
firewall-cmd --set-log-denied=all
firewall-cmd --set-log-denied=off