vi /etc/sysconfig/iptables
iptables -A INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
service iptables saveservice iptables restart
开通3306 端口的行必须在icmp-host-prohibited前