centos 对某ip开放 防火墙端口_CentOS防火墙iptables限制端口和来源IP地址访问的配置...
查看版本:cat /etc/centos-release#?cat?/etc/centos-release
CentOS?release?6.6?(Final)
允許訪問所有端口的配置,文件/etc/sysconfig/iptables的內(nèi)容:*filter
:INPUT?ACCEPT?[0:0]
:FORWARD?ACCEPT?[0:0]
:OUTPUT?ACCEPT?[0:0]
COMMIT
查看防火墻:iptables -L -n#?iptables?-L?-n
Chain?INPUT?(policy?ACCEPT)
target?????prot?opt?source???????????????destination
Chain?FORWARD?(policy?ACCEPT)
target?????prot?opt?source???????????????destination
Chain?OUTPUT?(policy?ACCEPT)
target?????prot?opt?source???????????????destination
禁止外部訪問TCP的40080端口:
-A INPUT -p tcp --dport 40080 -j DROP
禁止外部訪問TCP的3000到4000端口(端口范圍):
-A INPUT -p tcp --dport 3000:4000 -j DROP
禁止某個IP地址訪問所有TCP端口:
-A INPUT -p tcp -s 192.168.1.2 -j DROP
禁止某個IP地址訪問TCP的57025端口:
-A INPUT -p tcp -s 192.168.1.2 --dport 57025 -j DROP
文件/etc/sysconfig/iptables配置的所有內(nèi)容:*filter
:INPUT?ACCEPT?[0:0]
:FORWARD?ACCEPT?[0:0]
:OUTPUT?ACCEPT?[0:0]
-A?INPUT?-p?tcp?--dport?40080?-j?DROP
-A?INPUT?-p?tcp?--dport?3000:4000?-j?DROP
-A?INPUT?-p?tcp?-s?192.168.1.103?-j?DROP
-A?INPUT?-p?tcp?-s?192.168.1.2?--dport?57025?-j?DROP
COMMIT
重新啟動:service iptables restart
查看防火墻:iptables -L -n#?iptables?-L?-n
Chain?INPUT?(policy?ACCEPT)
target?????prot?opt?source???????????????destination
DROP???????tcp??--??0.0.0.0/0????????????0.0.0.0/0???????????tcp?dpt:40080
DROP???????tcp??--??0.0.0.0/0????????????0.0.0.0/0???????????tcp?dpts:3000:4000
DROP???????tcp??--??192.168.1.103????????0.0.0.0/0
DROP???????tcp??--??192.168.1.2??????????0.0.0.0/0???????????tcp?dpt:57025
Chain?FORWARD?(policy?ACCEPT)
target?????prot?opt?source???????????????destination
Chain?OUTPUT?(policy?ACCEPT)
target?????prot?opt?source???????????????destination
總結(jié)
以上是生活随笔為你收集整理的centos 对某ip开放 防火墙端口_CentOS防火墙iptables限制端口和来源IP地址访问的配置...的全部內(nèi)容,希望文章能夠幫你解決所遇到的問題。
- 上一篇: 桌面时钟代码_iOS 14 制作自己的桌
- 下一篇: vue怎么截取时间年月_Vue + El