设置内网ip白名单 a.编辑 vim /etc/sysconfig/iptables b.添加内容:
# sample configuration for iptables service# you can edit this manually or use system-config-firewall# please do not ask us to add additional ports/services to this default configuration
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
# 白名单
-A whitelist -s 10.0.1.16 -j ACCEPT
COMMIT
重启iptables:systemctl restart iptables.service
CentoOs配置防火墙(firewall)
查看以开放的端口:firewall-cmd --zone=public --list-ports
添加8081端口到白名单:firewall-cmd --permanent --zone=public --add-port=8081/tcp a. --zone:作用域 b. --add-port=8081/tcp:添加端口,格式:端口/通讯协议 c. --permanent:永久有效,没有此参数重启后失效