以下是虚拟机配置测试,不是线上服务器的配置
# Generated by iptables-save v1.4.7 on Thu Jan 5 10:47:19 2017
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [317413:324509565]
-A INPUT -s 132.19.43.161/32 -p tcp -m tcp -j DROP
-A INPUT -s 61.135.169.78/32 -p tcp -m tcp --dport 80 -j DROP
-A INPUT -s 59.108.229.35/32 -p tcp -m tcp --dport 80 -j DROP
-A INPUT -p tcp -m tcp --dport 9189 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
-A OUTPUT -s 192.168.152.133/32 -p tcp --sport 80 -j ACCEPT #允许服务器返回客户端的响应
-A OUTPUT -s 192.168.152.133/32 -p tcp -d 192.168.152.153 --dport 3260 -j ACCEPT #允许服务器连接远程iscsi存储
-A OUTPUT -s 192.168.152.133/32 -p tcp --sport 22 -j ACCEPT #允许服务接受SSH22
-A OUTPUT -s 192.168.152.133/32 -p tcp -d 192.168.152.163 --dport 22 -j ACCEPT #允许服务器scp文件复制到192.168.152.163:22
-A OUTPUT -s 192.168.152.133/32 -p tcp --sport 8080 -j ACCEPT #允许服务接受客户端的配置
-A OUTPUT -s 192.168.152.133/32 -j DROP
COMMIT
# Completed on Thu Jan 5 10:47:19 2017
阅读(1232) | 评论(0) | 转发(0) |