|
|
启动防火墙以后,默认状态下规则为:
- [root@testing24 root]# iptables -L -n
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
- RH-Firewall-1-INPUT all -- 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- RH-Firewall-1-INPUT all -- 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- Chain RH-Firewall-1-INPUT (2 references)
- target prot opt source destination
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 icmp type 255
- ACCEPT esp -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT ah -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
复制代码
然后使用如下操作,
- [root@testing24 root]# iptables -A OUTPUT -p tcp --dport 21 -j ACCEPT
- [root@testing24 root]# iptables -A INPUT -p tcp --sport 21 -j ACCEPT
- [root@testing24 root]# iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
- [root@testing24 root]# iptables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
复制代码
执行后IPTABLE的规则为:
- [root@testing24 root]# iptables -L -n
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
- RH-Firewall-1-INPUT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp spt:21
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- RH-Firewall-1-INPUT all -- 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:21
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- Chain RH-Firewall-1-INPUT (2 references)
- target prot opt source destination
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 icmp type 255
- ACCEPT esp -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT ah -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
复制代码
结果用FTP软件不能连接上。那位高人,指点下,谢谢!! |
|