回覆列表
  • 1 # 使用者9186333210396

    開啟配置檔案

    命令程式碼

    [root@localhost ~]# vi /etc/sysconfig/iptables

    正確的配置檔案

    配置程式碼

    # Firewall configuration written by system-config-firewall

    # Manual customization of this file is not recommended.

    *filter

    :INPUT ACCEPT [0:0]

    :FORWARD ACCEPT [0:0]

    :OUTPUT ACCEPT [0:0]

    -A INPUT -m state –state ESTABLISHED,RELATED -j ACCEPT

    -A INPUT -p icmp -j ACCEPT

    -A INPUT -i lo -j ACCEPT

    -A INPUT -m state –state NEW -m tcp -p tcp –dport 22 -j ACCEPT

    -A INPUT -m state –state NEW -m tcp -p tcp –dport 80 -j ACCEPT

    -A INPUT -j REJECT –reject-with icmp-host-prohibited

    -A FORWARD -j REJECT –reject-with icmp-host-prohibited

    COMMIT

    配置[*]通配程式碼

    -A INPUT -m state –state NEW -m tcp -p tcp –dport * -j ACCEPT

    注意點:新開放的埠一定要在埠22後面

    重啟防火牆使配置生效

    命令程式碼

    [root@localhost ~]# /etc/init.d/iptables restart

    其它

    檢視開放埠

    命令程式碼

    [root@localhost ~]# /etc/init.d/iptables status

    關閉防火牆

    命令程式碼

    [root@localhost ~]# /etc/init.d/iptables stop

  • 中秋節和大豐收的關聯?
  • 春運返程,無論是火車還是飛機上,有哪些讓你印象深刻的事情呢?