基本的服务,mail,dns,www,ssh只允许特定的ip(段)访问
#!/bin/sh
IPT='/usr/local/sbin/iptables'
$IPT -F
$IPT -X
$IPT -P FORWARD DROP
$IPT -P INPUT DROP
$IPT -P OUTPUT ACCEPT
$IPT -N logserver
$IPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
$IPT -A INPUT -i lo -j ACCEPT
$IPT -A INPUT -p tcp -m multiport --dports 25,53,80 -j logserver
$IPT -A INPUT -s 1.2.3.4 -p tcp --dport 22 -j logserver
$IPT -A INPUT -s 10.0.0.0/8 -p tcp --dport 22 -j logserver
$IPT -A INPUT -p udp --dport 53 -j logserver
$IPT -A logserver -j ULOG
$IPT -A logserver -j ACCEPT
阅读(1280) | 评论(1) | 转发(0) |