#清空iptables规则
Iptables-f Iptables-x
Iptables-z
Iptables-t nat-f
Iptables-t Nat-x
Iptables-t nat-z
Iptables-p INPUT DROP
Iptables-p OUTPUT DROP
Iptables-p FORWARD DROP
#开放回环网卡lo
Iptables-a input-i lo-j ACCEPT
Iptables-a Output-o lo-j ACCEPT
#开放web80端口
Iptables-a input-p TCP--dport 80-j ACCEPT
Iptables-a output-p TCP--sport 80-j ACCEPT
Iptables-a input-p TCP--dport 8080-j ACCEPT
Iptables-a output-p TCP--sport 8080-j ACCEPT
Iptables-a input-p TCP--dport 8081-j ACCEPT
Iptables-a output-p TCP--sport 8081-j ACCEPT
Iptables-a input-p TCP--dport 8888-j ACCEPT
Iptables-a output-p TCP--sport 8888-j ACCEPT
#开放ping
Iptables-a input-p icmp-j ACCEPT
Iptables-a output-p icmp-j ACCEPT
#开放ssh
Iptables-a input-p TCP--dport 22-j ACCEPT
Iptables-a output-p TCP--sport 22-j ACCEPT
Iptables-a input-p TCP--dport 2222-j ACCEPT
Iptables-a output-p TCP--sport 2222-j ACCEPT
#开放某IP所有连接端口
Iptables-a input-s 127.0.0.1-p tcp-j ACCEPT
Iptables-a output-d 127.0.01-p tcp-j ACCEPT
Iptables-a input-m State--state established,related-j ACCEPT
Iptables-a output-m State--state established,related-j ACCEPT
Iptables-a input-m State--state invalid-j DROP
Iptables-a output-m State--state invalid-j DROP
#保存IPTABLES设置
Service Iptables Save
#重启IPTABLES服务
Service Iptables Restart
#设置开机启动IPTABLES
Chkconfig iptables on