防火牆iptables 設定

來源:互聯網
上載者:User

標籤:des   style   blog   color   io   使用   ar   檔案   art   

在伺服器上架了一個tomcat,指定好連接埠號碼,我就開始訪問,未果! 公司對伺服器(RedHat)連接埠限制,可謂是滴水不漏! 用iptables 查看防火牆設定: Shell代碼  iptables -nL  我需要一個8880連接埠,看來是不能訪問了! 直接修改設定檔: Shell代碼  vi /etc/sysconfig/iptables   照貓畫虎,增加紅框中的內容! 這樣做還不保險,詭異狀況下這個連接埠還是會被屏蔽! 強制儲存: Shell代碼  service iptables save   然後,重啟服務: Shell代碼  service iptables restart     再看看防火牆設定: Shell代碼  iptables -nL  OK,現在就可以通過ip+連接埠在區域網路內訪問了! 來點實際的,限制外網非80連接埠的一切訪問 使用命令 Shell代碼  #接受80連接埠的tcp訪問,且指定網卡為eth1  iptables -A INPUT -p tcp -m tcp --dport 80 -i eth1 -j ACCEPT  #拒絕非內網地址的一切訪問,指定網卡為eth1  iptables -A INPUT -s ! 10.0.0.0/255.0.0.0 -i eth1 -j DROP  使用iptables-save強制生效,但我無論如何使用該命令,重啟ipatbles服務後,都是根據設定檔走的。 來個直接的,編輯iptables Shell代碼  vim /etc/sysconfig/iptables  追加以下內容: Shell代碼  #接受80連接埠的tcp訪問,且指定網卡為eth1  -A INPUT -p tcp -m tcp --dport 80 -i eth1 -j ACCEPT  #拒絕非內網地址的一切訪問,指定網卡為eth1  -A INPUT -s ! 10.0.0.0/255.0.0.0 -i eth1 -j DROP  重啟iptables: Shell代碼  service iptables restart  查看iptables狀態: Shell代碼  iptables -nL  引用Chain INPUT (policy ACCEPT) target     prot opt source               destination         ACCEPT     all  --  127.0.0.1            0.0.0.0/0           ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:80           DROP       all  -- !10.0.0.0/8           0.0.0.0/0一定要注意順序,一定是先做ACCEPT的配置,最後做DROP的配置!!! 否則,配置錯誤了,連SSH都沒得用! 最後,最關鍵的一步,使得iptable配置隨系統啟動: Shell代碼  service iptables save  引用# service iptables save 將當前規則儲存到 /etc/sysconfig/iptables:                 [確定]據說Shell代碼  chkconfig iptables on  也可以達到自動啟動作用,即啟動iptables就會自動讀取設定檔(/etc/sysconfig/iptables) 。 引用Iptables的命令選項        iptables [-t tables] command option parameter target        -A    在鏈尾添加一條規則        -C    將規則添加到使用者定義鏈之前對其進行檢查        -D   從鏈中刪除一條規則        -E    重新命名使用者定義的鏈,不改變鏈本身        -F    清空鏈,刪除鏈上的所有規則        -I     在鏈中插入一條規則        -L    列出某個鏈上的規則,如iptables –L INPUT 列出INPUT鏈的規則        -N   建立一個新鏈        -P    定義某個鏈的預設策略        -R    替換鏈上的某條規則        -X   刪除某個使用者相關的鏈        -Z    將所有表的所有 查看圖片附件

 

防火牆iptables 設定

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.