# Generated by iptables-save v1.2.11 on Wed Jun 25 15:59:56 2008
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [24051664:30813220318]
:RH-Firewall-1-INPUT - [0:0]
-A INPUT -j RH-Firewall-1-INPUT
-A FORWARD -j RH-Firewall-1-INPUT
-A RH-Firewall-1-INPUT -i lo -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 81 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT
-A RH-Firewall-1-INPUT -s 59.60.153.86 -m state --state NEW -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j DROP
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m multiport --dports 25,110 -j DROP
-A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m multiport --dports 3306,161,873,20 -j DROP
COMMIT
# Completed on Wed Jun 25 15:59:56 2008
参数:d 目的地地址
s 出发点地址
m 保存状态的,已经访问过的
p 协议
j 动作
dport 端口
重启服务生效
cat /etc/sysconfig/iptables
>/etc/sysconfig/iptables
vi /etc/sysconfig/iptables
service iptables restart
cat /etc/sysconfig/iptables
阅读(571) | 评论(0) | 转发(0) |