CentOS7开启iptables

版权声明:本文为博主原创文章,遵循 CC 4.0 BY-SA 版权协议,转载请附上原文出处链接和本声明。
本文链接: https://blog.csdn.net/lynnyq/article/details/102497351

CentOS7开启iptables

参考

1.安装

systemctl stop firewalld && systemctl mask firewalld && yum install -y iptables iptables-services

2.配置

#!/bin/sh
iptables -P INPUT ACCEPT
iptables -F
iptables -X
iptables -Z
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j ACCEPT
iptables -A INPUT -p icmp --icmp-type 8 -j ACCEPT
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD DROP
iptables -A INPUT -p tcp -s 127.0.0.1 -j ACCEPT
iptables -A INPUT -p udp -s 127.0.0.1 -j ACCEPT
service iptables save
systemctl restart iptables.service
systemctl enable iptables.service

3.导入导出

  • 导出规则
iptables-save > iptables.txt
  • 导入规则
iptables-restore < iptables.txt 
service iptables save

猜你喜欢

转载自blog.csdn.net/lynnyq/article/details/102497351