A Simple Firewall (iptables) instance and iptables instance

Source: Internet
Author: User

A Simple Firewall (iptables) instance and iptables instance

#! /Bin/bash
#
# For centos7 iptables table
#
# Yum install iptables-services-y
#
#
# Rule arrangement is ordered.
#
# Clearing default rules

Iptables-F
Iptables-X
Iptables-Z

# Setting policies

Iptables-P INPUT DROP
# Iptables-P INPUT ACCEPT
Iptables-P OUTPUT ACCEPT
Iptables-P FORWARD ACCEPT

# Custom rules
Iptables-a input-I lo-j ACCEPT
Iptables-a input-I eth0-s 10.44.148.0/21-j ACCEPT
Iptables-a input-I eth0-s 10.51.177.0/21-j ACCEPT
Iptables-a input-I eth0-s 10.51.181.0/21-j ACCEPT
Iptables-a input-I eth0-s 10.44.148.0/21-j ACCEPT
Iptables-a input-I eth0-s 10.51.179.0/21-j ACCEPT
Iptables-a input-I eth0-s 10.44.167.0/21-j ACCEPT
Iptables-a input-I eth0-s 10.44.200.0/21-j ACCEPT

# Eth1 custom rules
Iptables-a input-I eth1-p tcp -- dport 80-j ACCEPT
Iptables-a input-I eth1-p tcp -- dport 443-j ACCEPT
Iptables-a input-I eth1-p tcp -- dport 52113-j ACCEPT
Iptables-a input-I eth1-p tcp -- dport 21-j ACCEPT
# Mysql
Iptables-a input-I eth1-p tcp -- dport 3306-j ACCEPT
# Redis
Iptables-a input-I eth1-p tcp -- dport 6380-j ACCEPT
# Mongodb
Iptables-a input-I eth1-p tcp -- dport 27017-j ACCEPT
# Svn
Iptables-a input-I eth1-p tcp -- dport 3690-j ACCEPT
# Address
Iptables-a input-I eth1-p tcp -- dport 7070-j ACCEPT
# Admin117
Iptables-a input-I eth1-p tcp -- dport 7474-j ACCEPT
# Bigscreen
Iptables-a input-I eth1-p tcp -- dport 9999-j ACCEPT
# Bss
Iptables-a input-I eth1-p tcp -- dport 9191-j ACCEPT
# Callcenter
Iptables-a input-I eth1-p tcp -- dport 7171-j ACCEPT
# Employee
Iptables-a input-I eth1-p tcp -- dport 9292-j ACCEPT
# Jenkins
Iptables-a input-I eth1-p tcp -- dport 9595-j ACCEPT
# Mobile
Iptables-a input-I eth1-p tcp -- dport 9393-j ACCEPT
# Oa
Iptables-a input-I eth1-p tcp -- dport 9494-j ACCEPT
# Site Selection Analysis
Iptables-a input-I eth1-p tcp -- dport 7373-j ACCEPT
# Mysql-tool
Iptables-a input-I eth1-p tcp -- dport 9797-j ACCEPT
# Universiyt
Iptables-a input-I eth1-p tcp -- dport 9696-j ACCEPT
# University_test
Iptables-a input-I eth1-p tcp -- dport 7272-j ACCEPT

 


Iptables-a input-I eth1-m state -- state RELATED, ESTABLISHED-j ACCEPT
# Iptables-a output-o eth1-m state -- state RELATED, ESTABLISHED-j ACCEPT
# Iptables-a input-p tcp -- dport 80-m limit -- limit 25/minute -- limit-burst 100-j ACCEPT

# NAT rules

# The secondary rule only needs to be configured on the NAT server, and the gateway specified by other Intranet machines is the Intranet IP address.

# Clearing NAT table rules

# Iptables-F-t nat
# Iptables-X-t nat
# Iptables-Z-t nat
# Iptables-t nat-P PREROUTING ACCEPT
# Iptables-t nat-P POSTROUTING ACCEPT
# Iptables-t nat-P OUTPUT ACCEPT

 

# Iptables-a input-I eth1-j ACCEPT
# Echo "0">/proc/sys/net/ipv4/ip_forward


# Send all received packets SNAT to 101.200.177.83

# Iptables-t nat-a postrouting-o eth1-j SNAT -- to-source 101.200.177.83
# Iptables-t nat-a postrouting-o eth1-j SNAT -- to-source 101.200.177.83


# DNAT conversion. The public IP address is 192.168.1.10 in eth0 Intranet (pay attention to intranet firewall)

# Iptables-t nat-a prerouting-I eth1-p tcp -- dport 13306-j DNAT -- to-destination 10.51.177.139: 3306
# Iptables-t nat-a prerouting-I eth1-d 101.200.177.83-p tcp -- dport 13306-j DNAT -- to-destination 115.28.134.12: 3306


# Write firewall rules
#/Etc/init. d/iptables save
#/Usr/libexec/iptables. init save
Service iptables save

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.