|
|

楼主 |
发表于 2009-5-4 14:12:46
|
显示全部楼层
这是/etc/sysconfig/iptables文件
#
# Sample iptables rules. It should be localted at:
# /etc/sysconfig/iptables
#
# Shipped within iRedMail project:
# * http://iRedMail.googlecode.com/
#
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
# Keep state.
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
# http/https, smtp/smtps, pop3/pop3s, imap/imaps, ssh
-A INPUT -p tcp -m multiport --dport 80,443,25,465,110,995,143,993,587,465,22 -j ACCEPT
# Loop device.
-A INPUT -i lo -j ACCEPT
# http/https
#-A INPUT -p tcp -m multiport --dport 80,443 -j ACCEPT
# smtp/smtps
#-A INPUT -p tcp -m multiport --dport 25,465 -j ACCEPT
# pop3/pop3s
#-A INPUT -p tcp -m multiport --dport 110,995 -j ACCEPT
# imap/imaps
#-A INPUT -p tcp -m multiport --dport 143,993 -j ACCEPT
# ldap/ldaps
#-A INPUT -p tcp -m multiport --dport 389,636 -j ACCEPT
# ftp.
#-A INPUT -p tcp -m multiport --dport 21,20 -j ACCEPT
# ssh
#-A INPUT -p tcp --dport 22 -j ACCEPT
COMMIT
44,1 Bot |
|