iptable防火墙配置

it2022-05-05  169

iptable防火墙配置

/etc/sysconfig/iptables /etc/init.d/iptables {start|stop|restart|condrestart|status|panic|save}

iptables -L iptables -t nat -L

单网卡/etc/sysconfig/iptables

*filter :INPUT DROP [0:0] :FORWARD DROP [0:0] :OUTPUT ACCEPT [0:0] -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT -A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT -A FORWARD -m state --state NEW -p TCP ! --syn -j DROP -A FORWARD -f -m limit --limit 100/s --limit-burst 100 -j ACCEPT -A FORWARD -p icmp -m limit --limit 1/s --limit-burst 10 -j ACCEPT COMMIT

双网卡内网接口em1, 外网接口em2 内网允许任意访问/etc/sysconfig/iptables

*filter :INPUT DROP [0:0] :FORWARD DROP [0:0] :OUTPUT ACCEPT [0:0] -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT -A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT -A FORWARD -m state --state NEW -p TCP ! --syn -j DROP -A FORWARD -f -m limit --limit 100/s --limit-burst 100 -j ACCEPT -A FORWARD -p icmp -m limit --limit 1/s --limit-burst 10 -j ACCEPT # 开放em1 INPUT&FORWARD -A INPUT -i em1 -j ACCEPT -A FORWARD -i em1 -j ACCEPT COMMIT

双网卡nat 内网接口em1, 外网接口em2 内网允许任意访问/etc/sysconfig/iptables*

# Generated by iptables-save v1.4.7 on Wed Feb 3 15:39:19 2016 *nat :PREROUTING ACCEPT [73:5089] :POSTROUTING ACCEPT [368:18857] :OUTPUT ACCEPT [368:18857] -A POSTROUTING -s 10.150.1.0/24 -o em2 -j SNAT --to-source 69.x.x.25 COMMIT # Completed on Wed Feb 3 15:39:19 2016 # Generated by iptables-save v1.4.7 on Wed Feb 3 15:39:19 2016 *filter :INPUT DROP [70:4724] :FORWARD DROP [0:0] :OUTPUT ACCEPT [3643:836416] -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 29922 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT -A INPUT -i em1 -j ACCEPT -A FORWARD -p tcp -m state --state NEW -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP -A FORWARD -f -m limit --limit 100/sec --limit-burst 100 -j ACCEPT -A FORWARD -p icmp -m limit --limit 1/sec --limit-burst 10 -j ACCEPT -A FORWARD -i em1 -j ACCEPT COMMIT # Completed on Wed Feb 3 15:39:19 2016 posted on 2014-10-22 15:51 北京涛子 阅读( ...) 评论( ...) 编辑 收藏

转载于:https://www.cnblogs.com/liujitao79/p/4043384.html

相关资源:最全的iptable防火墙详解

最新回复(0)