1. View Firewall
Iptables-l-N
Iptablesb-l-n--line-number show Rule line numbers
See INPUT Accept, FORWARD accept, OUTPUT accept
Ipables is made up of 3 parts
Input, forward, and output
(Policy accept) indicates that all data is fully accepted and that the firewall is not a person or a function.
2. Close
Iptables-p INPUT DROP
Iptables-p OUTPUT DROP
Drop indicates that input does not accept, is lost, and does not let him enter the data.
3. Open
Iptables-p INPUT ACCEPT
Iptables-p OUTPUT ACCEPT
4. Close input, FORWARD OUTPUT only open some ports
Iptables-p INPUT DROP
Iptables-p OUTPUT DROP
Iptables-p FORWARD DROP
All DROP But this is temporary, restarting the machine will restore the original state
5. Save
Service Iptables Save
Configuration is saved in/etc, Sysconfig, iptables
can view VI
6. See which ports are currently open
Netstat-tnl
7. Open port
Iptables-a input-p TCP--dport 22-j ACCEPT
Iptables-a output-p TCP--sport 22-j ACCEPT
-a means adding
-P indicates protocol TCP, UDP
--dport represents the destination port, when data is entered from outside the server destination port
Conversely, data from the server is the data source port
--sport represents the data source port
-j means accept or drop
Iptables also has a lot of parameters, as well as the validity of the packet validation and so on very strong.
8. Prohibit an IP access
Iptables-a input-p tcp-s 192.168.42.10-j DROP
Allow an IP access
Iptables-a input-p tcp-s 192.168.42.10-j ACCEPT
9. Delete Rule
Iptablesb-l-N--line-number
iptables-d INPUT 1
10. Filter Invalid Packets
......
Linux iptables Firewall settings