標籤:linux 防火牆 iptables netfilter
一.iptables命令
規則:根據指定的匹配條件來嘗試匹配每個流經此處的報文,一旦匹配成功,則由規則後面指定的處理動作進行處理;
匹配條件:分為基本匹配條件和擴充匹配條件,擴充匹配條件又分為隱式擴充和顯式擴充;
基本匹配條件:源地址,目標地址,傳輸協議;
擴充匹配條件:需要藉助於擴充模組進行指定的匹配條件;
隱式擴充:已經在基本匹配條件中指明的協議相關的擴充;
顯式擴充:隱式擴充之外的其它擴充匹配條件;
處理動作:分為基本動作和擴充動作;
基本動作:ACCEPT,DROP,REJECT
擴充動作:需要藉助於擴充模組進行,但無須顯式指定,僅需指明動作;
二.添加規則需要思考的問題
(1) 報文流經的位置:用於判斷將規則添加至哪個鏈;
(2) 實現的功能:用於判斷將規則添加至哪個表;
(3) 報文的方向:用於判斷哪個為“源”,哪個為“目標”;
(4) 匹配條件:用於編寫能夠正確匹配目標報文的規則;
三.iptables命令使用格式
iples [-t table] {-A|-C|-D} chain rule-specification
ip6tables [-t table] {-A|-C|-D} chain rule-specification
iptables [-t table] -I chain [rulenum] rule-specification
iptables [-t table] -R chain rulenum rule-specification
iptables [-t table] -D chain rulenum
iptables [-t table] -S [chain [rulenum]]
iptables [-t table] {-F|-L|-Z} [chain [rulenum]] [options...]
iptables [-t table] -N chain
iptables [-t table] -X [chain]
iptables [-t table] -P chain target
iptables [-t table] -E old-chain-name new-chain-name
rule-specification = [matches...] [target]
match = -m matchname [per-match-options]
target = -j targetname [per-target-options]tab
規則管理格式:iptables [-t table] COMMAND chain creteria [-m -m matchname[per-match-options]] [-j targetname[per-target-options]]
-t table:指明要管理的表;預設為filter;
COMMANDS:
鏈管理:
-P:iptables [-t table] -P chain target,定義鏈的預設策略;其target一般可使用ACCEPT或DROP; -N:iptables [-t table] -N chain,自訂規則鏈;僅在預設鏈通過某規則進行調用方可生效;因此,每個自訂鏈都有其引用記數; -X:iptables [-t table] -X [chain],刪除自訂並且是空的引用計數為0的鏈; -F:iptables [-t table] -F [chain [rulenum]] [options...],清空指定的鏈,或刪除指定鏈上的規則; -E:iptables [-t table] -E old-chain-name new-chain-name,重新命名自訂的引用計數為0的鏈; -Z:iptables [-t table] -Z [chain[rulenum]] [options...],將規則計數器置0;
規則:
-A:append, iptables [-t table] -A chain rule-specification,追加規則到指定的鏈尾部; -I:insert, iptables [-t table] -I chain [rulenum] rule-specification,插入規則到指定的鏈中的指定位置,預設為鏈首; -D:delete,iptables [-t table] -D chainrule-specification或iptables [-t table] -D chain rulenum,刪除指定的鏈上的指定規則; -R:replace,iptables [-t table] -R chain rulenumrule-specification,將指定的鏈上的指定規則替換為新的規則;
查看:
-L:list, iptables [-t table] -L [chain [rulenum]] [options...] -n:數字格式; -v:verbose,詳細格式資訊; -vv、-vvv,更詳細格式資訊 --line-numbers:顯示鏈上的規則的編號; -x:exactly,顯示計數器的精確值; 顯示出的結果有這麼幾個含義: pkts bytes target prot opt in out source destination pkts:被本規則所匹配到的的報文個數; bytes:被本規則所匹配到的報文的大小之和; target:處理目標(目標可以為使用者自訂的鏈); prot:協議{tcp,udp,icmp} opt:可選項 in:資料包流入介面 out:資料包流出介面 source:源地址 destination:目標地址
四.計數器
每條規則以及鏈的預設策略分別有各自的兩個計數器:
(1) pkts:被本規則所匹配到的的報文個數;
(2) bytes:被本規則所匹配到的報文的大小之和;
五:儲存及重載規則
centos6:
儲存:
(1) service iptables save
/etc/sysconfig/iptables檔案;
(2) iptables-save > /PATH/TO/SOMEFILE
重載:
(1) service iptables restart
(2) iptables-restore < /PATH/FROM/SOMEFILE
centos7:引入了新的iptables前端管理服務工具firewalld
firewalld通過前端管理工具:firewalld-cmd和firewalld-config,其功能更強大更完善,因此其規則會更複雜,為了保持了centos6上同樣使用iptables來管理規則,先需要在centos7上關掉和禁用firewalld服務,方法如下:
(1) systemctl stop firewalld.service
(2) systemctl disable firewalld.service
本文出自 “亞成-另一個LINUXER” 部落格,請務必保留此出處http://yacheng0316.blog.51cto.com/11878883/1889979
iptables命令使用基礎(02)