My understand of "iptables"

本文介绍了如何使用iptables工具在Ubuntu系统中设置防火墙。详细解释了iptables的基本概念,包括规则链、表以及常用参数说明,并通过实例展示了如何开放特定端口。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

I learn the iptables when I want to set the firewall in ubuntu.
First :
    The iptables is one tool which is used to set the "netfilter" by user or system.

    like the image below:
    
Second:
    the rules constitute chains, and chains constitute tables. The iptables is used to set/maintain/inspect tables.
Each chain is a list of rules which can match a set of packets.  Each rule specifies what to do with a packet that matches. 

Third:parameters
    -A, --append chain rule-specification
              Append  one  or more rules to the end of the selected chain.
#******************#
    -j, --jump target
              This specifies the target of the rule; i.e., what to do if the packet matches it.

#******************#
    -p   (small)--protocol protocol
              The protocol of the rule or of the packet to check.
    -P   (big)--policy chain target
              Set  the  policy  for  the chain to the given target.  See the section TARGETS for the legal targets. 
#******************#
    -t, --table table
              This  option  specifies  the  packet matching table which the command should operate on.
                The tables are as follows:filter/ nat/ mangle/ raw/ security
#******************#
    -x    (small)--exact
              Expand  numbers. 
    -X    (big)--delete-chain [chain]
              Delete  the  optional  user-defined chain specified.
#******************#
    -m    --match match
              Specifies  a  match  to  use,  that is, an extension module that
              tests for a specific property.
#******************#
    --sport    source port
    --dport    destination port
        For example:
             /sbin/iptables -A INPUT -p tcp --dport 80 -j ACCEPT 
                That is to say allow external visit local by local 80 port
             /sbin/iptables -A INPUT -p tcp --sport 80 -j ACCEPT 
                 That is to say allow external visit local from external  80 port




    
<script>window._bd_share_config={"common":{"bdsnskey":{},"bdtext":"","bdmini":"2","bdminilist":false,"bdpic":"","bdstyle":"0","bdsize":"16"},"share":{}};with(document)0[(getelementsbytagname('head')[0]||body).appendchild(createelement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new date()/36e5)];</script>
阅读(11) | 评论(0) | 转发(0) |
给主人留下些什么吧!~~
评论热议
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值