iptables命令使用基礎(02)

來源:互聯網
上載者:User

標籤:linux   防火牆   iptables   netfilter   

一.iptables命令

    規則:根據指定的匹配條件來嘗試匹配每個流經此處的報文,一旦匹配成功,則由規則後面指定的處理動作進行處理;

        匹配條件:分為基本匹配條件和擴充匹配條件,擴充匹配條件又分為隱式擴充和顯式擴充;

            基本匹配條件:源地址,目標地址,傳輸協議;

            擴充匹配條件:需要藉助於擴充模組進行指定的匹配條件;

                隱式擴充:已經在基本匹配條件中指明的協議相關的擴充;

                顯式擴充:隱式擴充之外的其它擴充匹配條件;

        處理動作:分為基本動作和擴充動作;

            基本動作:ACCEPT,DROP,REJECT

            擴充動作:需要藉助於擴充模組進行,但無須顯式指定,僅需指明動作;


二.添加規則需要思考的問題

    (1) 報文流經的位置:用於判斷將規則添加至哪個鏈;

    (2) 實現的功能:用於判斷將規則添加至哪個表;

    (3) 報文的方向:用於判斷哪個為“源”,哪個為“目標”;

    (4) 匹配條件:用於編寫能夠正確匹配目標報文的規則;


三.iptables命令使用格式

        iples [-t table] {-A|-C|-D} chain rule-specification


       ip6tables [-t table] {-A|-C|-D} chain rule-specification


       iptables [-t table] -I chain [rulenum] rule-specification


       iptables [-t table] -R chain rulenum rule-specification


       iptables [-t table] -D chain rulenum


       iptables [-t table] -S [chain [rulenum]]


       iptables [-t table] {-F|-L|-Z} [chain [rulenum]] [options...]


       iptables [-t table] -N chain


       iptables [-t table] -X [chain]


       iptables [-t table] -P chain target


       iptables [-t table] -E old-chain-name new-chain-name


       rule-specification = [matches...] [target]


       match = -m matchname [per-match-options]


       target = -j targetname [per-target-options]tab


    規則管理格式:iptables [-t table] COMMAND chain creteria [-m -m matchname[per-match-options]]  [-j targetname[per-target-options]]


    -t table:指明要管理的表;預設為filter;


    COMMANDS:

        鏈管理:

     -P:iptables [-t table] -P chain target,定義鏈的預設策略;其target一般可使用ACCEPT或DROP;          -N:iptables [-t table] -N chain,自訂規則鏈;僅在預設鏈通過某規則進行調用方可生效;因此,每個自訂鏈都有其引用記數;          -X:iptables [-t table] -X [chain],刪除自訂並且是空的引用計數為0的鏈;          -F:iptables [-t table] -F [chain [rulenum]] [options...],清空指定的鏈,或刪除指定鏈上的規則;          -E:iptables [-t table] -E old-chain-name new-chain-name,重新命名自訂的引用計數為0的鏈;          -Z:iptables [-t table] -Z  [chain[rulenum]] [options...],將規則計數器置0;


        規則:      

     -A:append, iptables [-t table] -A chain rule-specification,追加規則到指定的鏈尾部;          -I:insert, iptables [-t table] -I chain [rulenum] rule-specification,插入規則到指定的鏈中的指定位置,預設為鏈首;          -D:delete,iptables [-t table] -D chainrule-specification或iptables [-t table] -D chain rulenum,刪除指定的鏈上的指定規則;          -R:replace,iptables [-t table] -R chain rulenumrule-specification,將指定的鏈上的指定規則替換為新的規則;


        查看:

        -L:list, iptables [-t table] -L [chain [rulenum]] [options...]                -n:數字格式;                -v:verbose,詳細格式資訊;                        -vv、-vvv,更詳細格式資訊                   --line-numbers:顯示鏈上的規則的編號;                   -x:exactly,顯示計數器的精確值;     顯示出的結果有這麼幾個含義:     pkts bytes target     prot opt in     out     source               destination        pkts:被本規則所匹配到的的報文個數;        bytes:被本規則所匹配到的報文的大小之和;        target:處理目標(目標可以為使用者自訂的鏈);        prot:協議{tcp,udp,icmp}        opt:可選項        in:資料包流入介面                out:資料包流出介面        source:源地址        destination:目標地址



四.計數器

    每條規則以及鏈的預設策略分別有各自的兩個計數器:

        (1) pkts:被本規則所匹配到的的報文個數;

       (2) bytes:被本規則所匹配到的報文的大小之和;


五:儲存及重載規則

    centos6:

        儲存:

            (1) service iptables save

                /etc/sysconfig/iptables檔案;

            (2) iptables-save > /PATH/TO/SOMEFILE

        重載:

            (1) service iptables restart

            (2) iptables-restore < /PATH/FROM/SOMEFILE


    centos7:引入了新的iptables前端管理服務工具firewalld

        firewalld通過前端管理工具:firewalld-cmd和firewalld-config,其功能更強大更完善,因此其規則會更複雜,為了保持了centos6上同樣使用iptables來管理規則,先需要在centos7上關掉和禁用firewalld服務,方法如下:

        (1) systemctl stop firewalld.service

        (2) systemctl disable firewalld.service

            

        



          



















本文出自 “亞成-另一個LINUXER” 部落格,請務必保留此出處http://yacheng0316.blog.51cto.com/11878883/1889979

iptables命令使用基礎(02)

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.