当前位置:网站首页>对iptables进行常规操作
对iptables进行常规操作
2022-07-06 09:26:00 【一一空】
一、梳理允许访问的IP地址
1、ES客户端IP地址
192.168.32.120 192.168.32.121
2、集群中节点的IP地址
192.168.32.122 192.168.32.123 192.168.32.124
二、登录ES主机(ubantu为例),执行以下命令
# 创建iptables策略保存路径
mkdir -p /etc/iptables
# 允许集群内主机IP访问本机9200端口
iptables -A INPUT -s 192.168.32.123 -p tcp --dport 9200 -j ACCEPT
iptables -A INPUT -s 192.168.32.124 -p tcp --dport 9200 -j ACCEPT
# 允许ES客户端IP地址访问本机9200端口
iptables -A INPUT -s 192.168.32.120 -p tcp --dport 9200 -j ACCEPT
iptables -A INPUT -s 192.168.32.121 -p tcp --dport 9200 -j ACCEPT
# 禁止除上面策略外的所有IP访问本机9200端口(最后一条)
iptables -A INPUT -p tcp --dport 9200 -j REJECT
# 如果要在以上策略基本上新增iptables策略,使用-I参数
iptables -I INPUT -s 192.168.32.121 -p tcp --dport 9200 -j ACCEPT
# 查看已添加的iptables规则
iptables -L -n --line-numbers
# 删除已添加的某条iptables规则
iptables -D INPUT 1
#保存已添加的iptables规则到本地文件路径
iptables-save > /etc/iptables/iptables.rules
#从已保存的文件中恢复iptables规则
iptables-restore < /etc/iptables/iptables.rules
#配置开机后自动执行加载iptables策略文件编辑iptables后
输入完iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080 后
执行iptables-save
注意:iptables-save是连在一起的,是一个命令,不是参数
iptables-save 仅仅是列出当前设置,并不是将配置保存
若你用的是 RedHat 系列,应该使用 service iptables save 保存,用 chkconfig iptables on 实现开机启动启用
若不是 RedHat 系列,可以使用下面方法手动保存/恢复配置
保存
iptables-save > /root/iptables.conf
恢复
iptables-restore < /root/iptables.conf边栏推荐
- Interesting drink
- D - Function(HDU - 6546)女生赛
- Opencv learning log 12 binarization of Otsu method
- Research Report on printed circuit board (PCB) connector industry - market status analysis and development prospect forecast
- Cost accounting [13]
- nodejs爬虫
- Learning records: serial communication and solutions to errors encountered
- Medical colposcope Industry Research Report - market status analysis and development prospect forecast
- LeetCode#237. Delete nodes in the linked list
- Research Report on shell heater industry - market status analysis and development prospect forecast
猜你喜欢

Matlab comprehensive exercise: application in signal and system

MATLAB实例:阶跃函数的两种表达方式

1010 things that college students majoring in it must do before graduation

FSM和i2c实验报告

基于web的照片数码冲印网站

学习记录:STM32F103 时钟系统概述工作原理

JS --- all knowledge of JS objects and built-in objects (III)

Flex --- detailed explanation of flex layout attributes

ucore lab 2

STM32如何使用STLINK下载程序:点亮LED跑马灯(库版本)
随机推荐
信息安全-威胁检测-flink广播流BroadcastState双流合并应用在过滤安全日志
LeetCode#198. raid homes and plunder houses
0-1 knapsack problem (I)
Find 3-friendly Integers
Es6--- two methods of capturing promise status as failed
0-1背包問題(一)
Research Report on market supply and demand and strategy of China's medical chair industry
Research Report of pharmaceutical solvent industry - market status analysis and development prospect prediction
Cost accounting [17]
Learning records: serial communication and solutions to errors encountered
HDU - 6024 Building Shops(女生赛)
Nodejs+vue网上鲜花店销售信息系统express+mysql
ucorelab3
ucore lab 2
ucore lab5
学习记录:使用STM32F1看门狗
Opencv learning log 12 binarization of Otsu method
JS --- detailed explanation of JS DOM (IV)
VS2019初步使用
信息安全-威胁检测-NAT日志接入威胁检测平台详细设计