iptables
4表:
raw,mangle,nat,filter
5链
preouting,input,forward,output,postrouting
扩展匹配:
-p protocol
tcp,udp,icmp
-m tcp
参数----表-----源------目的–端口—协议----动作
iptables -A INPUT -s 0/0 -d 192.168.113.150 -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -s 192.168.113.150 -p tcp --sport 22 -j ACCEPT
iptables -A INPUT -s 0/0 -d 192.168.113.150 -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -s 192.168.113.150 -p tcp --sport 80 -j ACCEPT
iptables -A INPUT -s 192.168.113.150 -p tcp -m mutliport --dports 22,80 -j ACCEPT
iprang
--src-range
iptables -A INPUT 3 -d 192.168.113.150 -p tcp --dport 23 -m iprange 192.168.113.1-192.168.113.130 -m time --timestart 09:00:00 --timestop 18:00:00 --weekdays 1,2,3,4,5 -j ACCEPT
tcp-flag
标志位匹配
--tcp-flags
syn,ack,rst,