1. iptables -L -v 查看,如下是正常
pkts bytes target prot opt in out source destination
606 114K ACCEPT tcp -- any any localhost anywhere tcp dpt:mysql
1440 241K ACCEPT tcp -- any any localhost anywhere tcp dpt:mysql
0 0 DROP tcp -- any any anywhere anywhere tcp dpt:mysql
2.
#保存iptables规则
service iptables save
会在/etc/sysconfig/iptables
-A INPUT -s 127.0.0.1/32 -p tcp -m tcp --dport 3306 -j ACCEPT
-A INPUT -s 127.0.0.1/32 -p tcp -m tcp --dport 3306 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 3306 -j DROP
3.通过命令增加
iptables -I INPUT -s 需要访问的IP1 -p tcp --dport 3306 -j ACCEPT
iptables -I INPUT -s 需要访问的IP2 -p tcp --dport 3306 -j ACCEPT
iptables -A INPUT -p tcp --dport 3306 -j DROPa