The iptables Status policy allows intranet connection to the Internet to reject the active connection from the Internet to the Intranet.

Source: Internet
Author: User

Four statuses

New

Established

Related

Invalid

NEW (a connection B is called the NEW package before B does not reply)

ESTABLISHED)

Once a and B are connected, there is a communication stream in both directions, and other packages associated with this append are regarded as in the ESTABLISHED status.

RELATED (the successful connection between a and B is called RELATED when multiple RELATED connections are generated by this connection)

The RELATED package is the packages that start new connections but are RELATED to the existing connections. The RELATED status can be used to adjust the composition of multiple connection protocols (such as ftp 21 for communication 20 data transmission) and error packets RELATED to existing connections (such as ICMP error packets RELATED to existing connections)

INVALID (INVALID package will not be discarded automatically, so write a policy to discard it)

Invalid package because this package will not be automatically discarded, You need to insert appropriate rules and set a chain policy so that these packages can be correctly processed.

Allow intranet connection to the Internet and deny Internet connection to the Intranet

Iptables-a input-m state -- state established, related-j accept

Iptables-a input-m state -- state new, invalid-j drop

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.