CentOS直接寫入iptables的位置
CentOS直接寫入iptables的位置,不過不建議直接使用檔案修改
而是用iptables的指令修改,不過還是留存一下!
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
# 設定讓使用[PORT]的服務可以通過
-A INPUT -m state --state NEW -m tcp -p tcp --dport [PORT] -j ACCEPT
# 設定讓使用[PORT2]的TCP/UDP服務可以通過
-A INPUT -p tcp --dport [PORT2] -j ACCEPT
-A INPUT -p udp --dport [PORT2] -j ACCEPT
# 設定其餘服務都REJECT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
如果要檢視routing table的內容,使用Mac的朋友可以試試看:
# route -rn
會有類似下面的output:
# netstat -rn
Routing tables
Internet:
Destination Gateway Flags Refs Use Netif Expire
default 10.42.0.252 UGSc 27 0 en0
10.42/20 link#5 UCS 3 0 en0
10.42.0.221 127.0.0.1 UHS 0 0 lo0
10.42.0.252 0:1d:aa:29:71:30 UHLWIi 26 2 en0 1200
10.42.15.255 ff:ff:ff:ff:ff:ff UHLWbI 0 4 en0
127 127.0.0.1 UCS 0 0 lo0
127.0.0.1 127.0.0.1 UH 15 276338 lo0
169.254 link#5 UCS 0 0 en0
Internet6:
Destination Gateway Flags Netif Expire
::1 link#1 UHL lo0
fe80::%lo0/64 fe80::1%lo0 UcI lo0
fe80::1%lo0 link#1 UHLI lo0
fe80::%en0/64 link#5 UCI en0
fe80::1240:f3ff:fe8b:a9bc%en0 10:40:f3:8b:a9:bc UHLI lo0
ff01::%lo0/32 fe80::1%lo0 UmCI lo0
ff01::%en0/32 link#5 UmCI en0
ff02::%lo0/32 fe80::1%lo0 UmCI lo0
ff02::%en0/32 link#5 UmCI en0
如果要檢視routing table的內容,使用Mac的朋友可以試試看:
# route -rn
會有類似下面的output:
# netstat -rn
Routing tables
Internet:
Destination Gateway Flags Refs Use Netif Expire
default 10.42.0.252 UGSc 27 0 en0
10.42/20 link#5 UCS 3 0 en0
10.42.0.221 127.0.0.1 UHS 0 0 lo0
10.42.0.252 0:1d:aa:29:71:30 UHLWIi 26 2 en0 1200
10.42.15.255 ff:ff:ff:ff:ff:ff UHLWbI 0 4 en0
127 127.0.0.1 UCS 0 0 lo0
127.0.0.1 127.0.0.1 UH 15 276338 lo0
169.254 link#5 UCS 0 0 en0
Internet6:
Destination Gateway Flags Netif Expire
::1 link#1 UHL lo0
fe80::%lo0/64 fe80::1%lo0 UcI lo0
fe80::1%lo0 link#1 UHLI lo0
fe80::%en0/64 link#5 UCI en0
fe80::1240:f3ff:fe8b:a9bc%en0 10:40:f3:8b:a9:bc UHLI lo0
ff01::%lo0/32 fe80::1%lo0 UmCI lo0
ff01::%en0/32 link#5 UmCI en0
ff02::%lo0/32 fe80::1%lo0 UmCI lo0
ff02::%en0/32 link#5 UmCI en0