#Floors Actions
OSI:3/4 ==>Packets Filter
OSI:7 ==>Contents Filter
# Policy Manager
-A append
-D num delete
-I num insert
-R replace
-Z zero counter
# Chain Manager
-P policy
-F flush
-N new
-X delete a chain(which was user defined and have no policy,and you can delete)
# Display Policy
-L list -n -v -x -line-numbers
# Display nat table
[root@station12 ~]# iptables -t nat -L
# Display raw table
[root@station12 ~]# iptables -t raw -L -n
# Delete filter's FORWARD's first policy
[root@station12 ~]# iptables -D FORWARD 1
# Display verbose messages
[root@station12 ~]# iptables -L -n -x --line-numbers -vvv
#
iptables -p icmp --icmp-type 8 (request)
iptables -p icmp --icmp-type 0 (reply)
#
# POP3
#
iptables -A INPUT -p tcp -s 192.168.0.0/24 --dport 110 -j ACCEPT
iptables -A INPUT -p tcp -s 192.168.1.0/24 --dport 110 -j REJECT
iptables -A INPUT -s 0/0 --dport 110 -j REJECT
iptables -A OUTPUT -p tcp -d 192.168.0.0/24 --sport 110 -j ACCEPT
iptables -A OUTPUT -d 0/0 --sport 110 -j REJECT
#
# SAMBA
#
iptables -A INPUT -p tcp -s 192.168.0.0/24 --dport 139 -j ACCEPT
iptables -A INPUT -s 0/0 --dport 139 -j REJECT
iptables -A OUTPUT -p tcp -d 192.168.0.0/24 --sport 139 -j ACCEPT
iptables -A OUTPUT -p tcp -d 0/0 --sport 139 -j REJECT
iptables -A INPUT -p tcp -s 192.168.0.0/24 --dport 445 -j ACCEPT
iptables -A OUTPUT -p tcp -d 192.168.0.0/24 --sport 445 -j ACCEPT
iptables -A INPUT -p udp -s 192.168.0.0/24 --dport 137:138 -j ACCEPT
iptables -A OUTPUT -p udp -d 192.168.0.0/24 --sport 137:138 -j ACCEPT
阅读(427) | 评论(0) | 转发(0) |