当前位置:网站首页>iptables 配置
iptables 配置
2022-07-28 17:02:00 【水月清辉】
1)保存防火墙配置文件信息
cp /etc/sysconfig/iptables{,.bak}
2)清除配置规则
iptables -F <- 清空iptables所有规则信息(清除filter)
iptables -X <- 清空iptables自定义链配置(清除filter)
iptables -Z <- 清空iptables计数器信息(清除filter)
3)别把自己踢出到门外
iptables -A INPUT -s 10.0.0.1 -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -s 10.0.0.0/24 -p tcp --dport 22 -j ACCEPT
4)配置防火墙filter上各个链的默认规则
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT ACCEPT
-P ---指定相应链的默认规则策略,是允许还是阻止
5)允许iptables服务端ping自己的网卡地址
iptables -A INPUT -i lo -j ACCEPT --- 让自己可以ping自己
6)指定外网可以访问的端口信息
iptables -A INPUT -p tcp -m multiport --dport 80,443 -j ACCEPT
7)企业中内网之间不要配置防火墙策略
iptables -A INPUT -s 172.16.1.0/24 -j ACCEPT --- 允许架构内部服务进行访问
8)企业之间有合作关系的,不要将友商的网络禁止(主要经常改动)
iptables -A INPUT -s 10.0.1.0/24 -j ACCEPT --- 允许一些合作企业的外网服务器进行访问
iptables -A INPUT -s 10.0.2.0/24 -j ACCEPT
9)如果防火墙上配置了FTP服务,需要配置网络状态机制
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT --- 允许web服务与ftp服务器建立连接
10)实现iptables策略配置永久保存
①. 利用防火墙启动脚本命令参数,实现永久保存
/etc/init.d/iptables save
②. 利用防火墙配置信息保存命令,实现永久保存
iptables-save >/etc/sysconfig/iptables
边栏推荐
- 七个步骤,深入解读数据含义
- Introduction to USB type-C PD fast charging
- 天线的原理、分类及要求
- Outdoor activities in hot weather are exquisite! Here comes the safety guide for citizens' fitness in midsummer
- 1.08 billion dollars! TCL technology acquires Samsung Suzhou 8.5 generation line: the production capacity will increase by 60% in the next year!
- Electrotechnics digital circuit self study notes 1.24
- Video Number Xiaobai starting operation guide
- Video number from 2-3 games per week to 3 games per day
- 这么多开源框架,该用哪个好?
- Ren Zhengfei's latest voice: American politicians hope Huawei will die, and the desire to survive inspires Huawei
猜你喜欢

How to sharpen a knife simply by yourself

频谱仪原理简介二

天线的原理、分类及要求

如何简简单单地自己动手磨刀

信号源原理简介

Centos8 uses docker to install WordPress in wordpress+mysql configuration file_ DB_ Understanding of host

Digital filter (IV) -- converting analog filter into digital filter

Seven steps, in-depth interpretation of data meaning

Digital filter (V) -- design IIR filter

食品安全 | 面包含盐量也会超标?几招教你正确吃面包!
随机推荐
Musk uses live pigs to show a new brain computer interface technology: it can read pig brain information in real time
centos8使用docker安装wordpress+mysql配置文件中WORDPRESS_DB_HOST的理解
Members who have opened a website need to download e-book messages for free
USB Type-C 之CC线简介
Video number one video broadcast 260million
[reading notes] - 2 learn machine learning classification through naive Bayesian model
Strong performance growth! Wentai technology's net profit in the first half of the year was 1.7 billion yuan, a sharp increase of 767.19% year-on-year!
Jetson Nano 上安装 tensorflow2.1 和 pytorch1.4
busybox最新版(busybox apk)
1.08 billion dollars! TCL technology acquires Samsung Suzhou 8.5 generation line: the production capacity will increase by 60% in the next year!
The video number is more like a official account of version 2.0
示波器探头详解
Self study notes of electrical engineering, data and electricity 1.25
横向listview的最佳实现——RecycleView
Import the database backup of MySQL 8 into MySQL 5
How does the video Number import the public domain traffic to the private domain
[dry goods] how to establish a close relationship between support and products?
2023年网络安全预算规划的五个关键考虑因素
Association between enterprise wechat and video Number
Changjiang storage launched its own storage brand "Zhiti", and the first SSD product was exposed