标签:table 允许 sys 端口 state dna out ted eth0
iptables -F
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT ACCEPT
iptables -A INPUT -i eth0 -p tcp -m multiport --dports 22,80,443,53 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A INPUT -p icmp --icmp-type echo-reply -j ACCEPT #允许PING便允许ping的前提是能解析
iptables -A INPUT -p udp --sport 53 -j ACCEPT #允许解析
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT #允许yum install
iptables -t nat -A PREROUTING -p tcp --dport 88 -j DNAT --to 192.168.16.196:80 ##将88端口转发到80
iptables-save >/etc/sysconfig/iptables
标签:table 允许 sys 端口 state dna out ted eth0
原文地址:http://www.cnblogs.com/howhy/p/6873000.html