配置linux 防火牆,只有固定IP和端口才能能訪問完美解決

//添加開放的端口和固定iptcp

vi  /etc/sysconfig/iptablesspa

 

[root@root220156 /]# echo "unset MAILCHECK">> /etc/profile 禁止彈出發郵件rest

開啓固定ip和端口訪問配置:ip

-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPTit

-A INPUT -p icmp -j ACCEPTtable

-A INPUT -i lo -j ACCEPT配置

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.137.5 -m multiport --dports 10102,80 -j ACCEPTfile

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.137.21 -m multiport --dports 10102,80 -j ACCEPTiptables

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.137.1 -m multiport --dports 10102,80 -j ACCEPTservice

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.17.157 -m multiport --dports 10102,80 -j ACCEPT

 

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.115.23  --dport 80 -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.107.233  --dport 80 -j ACCEPT

-A INPUT -j REJECT --reject-with icmp-host-prohibited

-A FORWARD -j REJECT --reject-with icmp-host-prohibited

COMMIT

service iptables restart  重啓防火牆

相關文章
相關標籤/搜索