分类: LINUX
2014-02-14 10:07:00
iptables –A INPUT –p icmp –icmp-type echo-reply –j ACCEPT
iptables –A OUTPUT –p icmp –icmp-type echo-request –j ACCEPT
iptables –A INPUT –i lo –p all –j ACCEPT
iptables –A OUTPUT –o lo –p all –j ACCEPT
上面做完后可以ping 外部的IP地址和本机127.0.0.1了,但是不能ping域名,如等,这个时候需要增加如下规则:
iptables –A INPUT –p udp –sport 53 –j ACCEPT
iptables –A OUTPUT –p udp –dport 53 –j ACCEPT
现在就可以ping域名了,最后保存规则,重启防火墙
service iptables save
service iptables restart