iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp --dport ssh -j ACCEPT
iptables -A INPUT -p tcp --dport 3000 -j ACCEPT
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -j DROP
root@xx:/home/xxxx# more /etc/iptables.rules
# Generated by iptables-save v1.3.8 on Sun Feb 8 04:00:54 2009
*filter
:INPUT ACCEPT [81:9554]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [697:71968]
[0:0] -A INPUT -i lo -j ACCEPT
[727:62440] -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
[0:0] -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
[0:0] -A INPUT -p tcp -m tcp --dport 3000 -j ACCEPT
[0:0] -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
[4:413] -A INPUT -j DROP
COMMIT
# Completed on Sun Feb 8 04:00:54 2009
###: more /etc/network/interfaces
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).
# The loopback network interface
auto lo
iface lo inet loopback
auto eth0
iface eth0 inet dhcp
pre-up iptables-restore < /etc/iptables.rules
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp --dport ssh -j ACCEPT
iptables -A INPUT -p tcp --dport 3000 -j ACCEPT
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -j DROP
root@xx:/home/xxxx# more /etc/iptables.rules
# Generated by iptables-save v1.3.8 on Sun Feb 8 04:00:54 2009
*filter
:INPUT ACCEPT [81:9554]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [697:71968]
[0:0] -A INPUT -i lo -j ACCEPT
[727:62440] -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
[0:0] -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
[0:0] -A INPUT -p tcp -m tcp --dport 3000 -j ACCEPT
[0:0] -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
[4:413] -A INPUT -j DROP
COMMIT
# Completed on Sun Feb 8 04:00:54 2009
###: more /etc/network/interfaces
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).
# The loopback network interface
auto lo
iface lo inet loopback
auto eth0
iface eth0 inet dhcp
pre-up iptables-restore < /etc/iptables.rules
本文展示了iptables防火墙的具体配置规则,包括允许特定端口如SSH、3000、80的入站流量,并对未匹配上述规则的数据包进行丢弃处理。此外还提供了网络接口配置文件的示例。
6238

被折叠的 条评论
为什么被折叠?



