当前位置:网站首页>Iptables only allows the specified IP address to access the specified port
Iptables only allows the specified IP address to access the specified port
2022-07-07 16:12:00 【Gegwu MMQ!!】
First , Clear all presets
iptables -F# Clear preset table filter Rules of all rule chains in iptables -X# Clear preset table filter User defined rules in the chain
1.
secondly , Setting allows only specified ip Address access specified port
iptables -A INPUT -s xxx.xxx.xxx.xxx -p tcp --dport 22 -j ACCEPT iptables -A OUTPUT -d xxx.xxx.xxx.xxx -p tcp --sport 22 -j ACCEPT iptables -A INPUT -s xxx.xxx.xxx.xxx -p tcp --dport 3306 -j ACCEPT iptables -A OUTPUT -d xxx.xxx.xxx.xxx -p tcp --sport 3306 -j ACCEPT
1.
The top two , Please note that –dport For the target port , When data enters the server from the outside as the target port ; conversely , Data from the server is the data source port , Use --sport
Empathy ,-s Is to specify the source address ,-d Is to specify the destination address .
then , Close all ports
iptables -P INPUT DROP iptables -P OUTPUT DROP iptables -P FORWARD DROP
1.
Last , Save the current rule
/etc/rc.d/init.d/iptables save service iptables restart
1.
such iptables The rule setting of applies to only acting as MySQL Server management and maintenance , The external address does not provide any services .
If you wish yum If it works , You also need to add the following , allow DNS Requested 53 port , Allow to download randomly generated high ports
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT iptables -A INPUT -p udp --s
To open 8080 Port as an example :
Mode one :
Log in and copy
1、 Turn on the firewall
systemctl start firewalld
2、 Open designated port
firewall-cmd --zone=public --add-port=1935/tcp --permanent
Meaning of order :
–zone # Scope
–add-port=1935/tcp # Add port , The format is : port / Communication protocol
–permanent # permanent , Failure after restart without this parameter
3、 service iptables restart
firewall-cmd --reload
4、 View port number
netstat -ntlp // View all of the current tcp port ·
netstat -ntulp |grep 8080 // View all 8080 Port usage
Mode two :
/sbin/iptables -I INPUT -p tcp --dport 8080 -j ACCEPT
Mode three :
-A INPUT -m state --state NEW -m tcp -p tcp --dport 8080 -j ACCEPT
service iptables restart
边栏推荐
- L'application à l'échelle de la normalisation mature des produits ai des compagnies maritimes, cimc, leader mondial de l'intelligence artificielle portuaire et maritime / intelligence artificielle des
- How does geojson data merge the boundaries of regions?
- Communication mode between application program and MATLAB
- How to implement backspace in shell
- Step by step monitoring platform ZABBIX
- 47_Opencv中的轮廓查找 cv::findContours()
- Shandong old age Expo, 2022 China smart elderly care exhibition, smart elderly care and aging technology exhibition
- 分步式監控平臺zabbix
- 【花雕体验】15 尝试搭建Beetle ESP32 C3之Arduino开发环境
- Summary of knowledge points of xlua hot update solution
猜你喜欢
Dotween -- ease function
持续创作,还得靠它!
Three. JS introductory learning notes 07: external model import -c4d to JSON file for web pages -fbx import
95.(cesium篇)cesium动态单体化-3D建筑物(楼栋)
Three. JS introductory learning notes 10:three JS grid
Shipping companies' AI products are mature, standardized and applied on a large scale. CIMC, the global leader in port and shipping AI / container AI, has built a benchmark for international shipping
Three. JS introductory learning notes 19: how to import FBX static model
Unity drawing plug-in = = [support the update of the original atlas]
How does geojson data merge the boundaries of regions?
Wireless sensor networks -- ZigBee and 6LoWPAN
随机推荐
What about the pointer in neural network C language
C4D learning notes 3- animation - animation rendering process case
Detailed explanation of unity hot update knowledge points and introduction to common solution principles
TS typescript type declaration special declaration field number is handled when the key key
Xcode Revoke certificate
SysOM 案例解析:消失的内存都去哪了 !| 龙蜥技术
2022 the 4th China (Jinan) International Smart elderly care industry exhibition, Shandong old age Expo
Plate - forme de surveillance par étapes zabbix
Odoo集成Plausible埋码监控平台
Three. JS introductory learning notes 00: coordinate system, camera (temporarily understood)
Leetcode-231-2的幂
Unity3D_ Class fishing project, bullet rebound effect is achieved
保证接口数据安全的10种方案
Eye of depth (VII) -- Elementary Transformation of matrix (attachment: explanation of some mathematical models)
[wechat applet] Chapter (5): basic API interface of wechat applet
Wireless sensor networks -- ZigBee and 6LoWPAN
Three. JS introductory learning notes 03: perspective projection camera
Dotween -- ease function
hellogolang
用手机在通达信上开户靠谱吗?这样炒股有没有什么安全隐患