IptablesVery good and powerful. All the friends who have used it say yes. Well, this article introduces some common applications!
1. ICMP-related applications
Make yourself unable to ping 127.0.0.1
Iptables-a input-s 127.0.0.1-p icmp-j DROP
The IP address range of 192.168.0.0/24 cannot be pinged to the local machine.
Iptables-a input-s 192.168.0.0/24-p icmp-j DROP
Ii. Disable all machines
# Iptables-a input-s 0/0-p icmp-j DROP
# ICMP (PING) accept! Echo-request
/Sbin/iptables-a input-p icmp -- icmp-type! Echo-request-j ACCEPT
Accept_redirects
# Echo "0">/proc/sys/net/ipv4/conf/all/accept_redirects
Or
# Sysctl net. ipv4.conf. all. accept_redirects = "0"
3. Prohibit IP Access to yourself
[Root @ linux root] # iptables-a input-s 192.168.0.253-j DROP
Iv. Blocking MSN
/Sbin/iptables-I FORWARD-d gateway.messenger.hotmail.com-j DROP
/Sbin/iptables-I FORWARD-p tcp -- dport 1863-j DROP
5. Blocking QQ
/Sbin/iptables-a forward-p tcp-d tcpconn.tencent.com -- dport 80-j DROP
/Sbin/iptables-a forward-p tcp-d tcpconn.tencent.com -- dport 443-j DROP
/Sbin/iptables-a forward-p tcp-d tcpconn2.tencent.com-j DROP
/Sbin/iptables-a forward-I eth0-p udp -- dport 8000-j DROP