1. 檢查防火牆經常使用命令(root權限執行):vim
a. service iptables statustcp
b. service iptables (可列出因此的iptables的經常使用命令)code
c. /etc/init.d/iptables status(效果相似)ip
2. 修改防火牆規則:it
vim /etc/sysconfig/iptablestable
1 # Generated by iptables-save v1.4.7 on Tue Mar 29 23:38:33 2016 2 3 *filter 4 :INPUT ACCEPT [0:0] 5 :FORWARD ACCEPT [0:0] 6 :OUTPUT ACCEPT [0:0] 7 :RH-Firewall-1-INPUT - [0:0] 8 9 -N whitelist 10 -A whitelist -s 192.168.10.11 -j ACCEPT 11 12 -A INPUT -j RH-Firewall-1-INPUT 13 -A FORWARD -j RH-Firewall-1-INPUT 14 -A RH-Firewall-1-INPUT -i lo -j ACCEPT 15 -A RH-Firewall-1-INPUT -p icmp --icmp-type any -j ACCEPT 16 -A RH-Firewall-1-INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT 17 -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT 18 -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT 19 -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 443 -j ACCEPT 20 -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 8001 -j whitelist 21 -A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited 22 COMMIT 23 24 # Completed on Tue Mar 29 23:38:33 2016 ~