当前位置:网站首页>对iptables进行常规操作
对iptables进行常规操作
2022-07-06 09:26:00 【一一空】
一、梳理允许访问的IP地址
1、ES客户端IP地址
192.168.32.120 192.168.32.121
2、集群中节点的IP地址
192.168.32.122 192.168.32.123 192.168.32.124
二、登录ES主机(ubantu为例),执行以下命令
# 创建iptables策略保存路径
mkdir -p /etc/iptables
# 允许集群内主机IP访问本机9200端口
iptables -A INPUT -s 192.168.32.123 -p tcp --dport 9200 -j ACCEPT
iptables -A INPUT -s 192.168.32.124 -p tcp --dport 9200 -j ACCEPT
# 允许ES客户端IP地址访问本机9200端口
iptables -A INPUT -s 192.168.32.120 -p tcp --dport 9200 -j ACCEPT
iptables -A INPUT -s 192.168.32.121 -p tcp --dport 9200 -j ACCEPT
# 禁止除上面策略外的所有IP访问本机9200端口(最后一条)
iptables -A INPUT -p tcp --dport 9200 -j REJECT
# 如果要在以上策略基本上新增iptables策略,使用-I参数
iptables -I INPUT -s 192.168.32.121 -p tcp --dport 9200 -j ACCEPT
# 查看已添加的iptables规则
iptables -L -n --line-numbers
# 删除已添加的某条iptables规则
iptables -D INPUT 1
#保存已添加的iptables规则到本地文件路径
iptables-save > /etc/iptables/iptables.rules
#从已保存的文件中恢复iptables规则
iptables-restore < /etc/iptables/iptables.rules
#配置开机后自动执行加载iptables策略文件
编辑iptables后
输入完iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080 后
执行iptables-save
注意:iptables-save是连在一起的,是一个命令,不是参数
iptables-save 仅仅是列出当前设置,并不是将配置保存
若你用的是 RedHat 系列,应该使用 service iptables save 保存,用 chkconfig iptables on 实现开机启动启用
若不是 RedHat 系列,可以使用下面方法手动保存/恢复配置
保存
iptables-save > /root/iptables.conf
恢复
iptables-restore < /root/iptables.conf
边栏推荐
- VS2019初步使用
- Market trend report, technical innovation and market forecast of Chinese hospital respiratory humidification equipment
- Matlab comprehensive exercise: application in signal and system
- Learning record: use STM32 external input interrupt
- JS --- all knowledge of JS objects and built-in objects (III)
- Alice and Bob (2021牛客暑期多校训练营1)
- Cost accounting [23]
- Research Report on pharmaceutical R & D outsourcing service industry - market status analysis and development prospect forecast
- Shell脚本编程
- JS --- BOM details of JS (V)
猜你喜欢
LeetCode#19. Delete the penultimate node of the linked list
ucorelab3
Es6---es6 content details
UCORE Lab 1 system software startup process
ucore lab7
VS2019初步使用
12306: mom, don't worry about me getting the ticket any more (1)
STM32 how to use stlink download program: light LED running light (Library version)
学习记录:STM32F103 时钟系统概述工作原理
信息安全-威胁检测引擎-常见规则引擎底座性能比较
随机推荐
UCORE Lab 1 system software startup process
Cost accounting [19]
Opencv learning log 14 - count the number of coins in the picture (regardless of overlap)
C语言数组的概念
Printing quality inspection and verification system Industry Research Report - market status analysis and development prospect forecast
学习记录:使用STM32外部输入中断
Flex --- detailed explanation of flex layout attributes
Matlab example: two expressions of step function
VS2019初步使用
Market trend report, technological innovation and market forecast of pneumonia drugs obtained by Chinese hospitals
Flink 使用之 CEP
Research Report on market supply and demand and strategy of China's medical chair industry
Learning record: USART serial communication
Cost accounting [14]
nodejs爬虫
用C语言写网页游戏
Crawler series (9): item+pipeline data storage
Matlab comprehensive exercise: application in signal and system
Research Report on market supply and demand and strategy of China's Medical Automation Industry
Determine the Photo Position