linux配置放火墙开放端口
2015-09-30 20:28
579 查看
vi /etc/sysconfig/iptables
-A INPUT -m state –state NEW -m tcp -p tcp –dport 80 -j ACCEPT(允许80端口通过防火墙) -A INPUT -m state –state NEW -m tcp -p tcp –dport 3306 -j ACCEPT(允许3306端口通过防火墙) 特别提示:很多网友把这两条规则添加到防火墙配置的最后一行,导致防火墙启动失败,正确的应该是添加到默认的22端口这条规则的下面
添加好之后防火墙规则如下所示:
###################################### # Firewall configuration written by system-config-firewall # Manual customization of this file is not recommended. *filter :INPUT ACCEPT [0:0] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] -A INPUT -m state –state ESTABLISHED,RELATED -j ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -m state –state NEW -m tcp -p tcp –dport 22 -j ACCEPT -A INPUT -m state –state NEW -m tcp -p tcp –dport 80 -j ACCEPT -A INPUT -m state –state NEW -m tcp -p tcp –dport 3306 -j ACCEPT -A INPUT -j REJECT –reject-with icmp-host-prohibited -A FORWARD -j REJECT –reject-with icmp-host-prohibited COMMIT #####################################
/etc/init.d/iptables restart #最后重启防火墙使配置生效
文章来自【 http://www.myhack58.com/Article/48/66/2012/34999.htm 】
-A INPUT -m state –state NEW -m tcp -p tcp –dport 80 -j ACCEPT(允许80端口通过防火墙) -A INPUT -m state –state NEW -m tcp -p tcp –dport 3306 -j ACCEPT(允许3306端口通过防火墙) 特别提示:很多网友把这两条规则添加到防火墙配置的最后一行,导致防火墙启动失败,正确的应该是添加到默认的22端口这条规则的下面
添加好之后防火墙规则如下所示:
###################################### # Firewall configuration written by system-config-firewall # Manual customization of this file is not recommended. *filter :INPUT ACCEPT [0:0] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] -A INPUT -m state –state ESTABLISHED,RELATED -j ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -m state –state NEW -m tcp -p tcp –dport 22 -j ACCEPT -A INPUT -m state –state NEW -m tcp -p tcp –dport 80 -j ACCEPT -A INPUT -m state –state NEW -m tcp -p tcp –dport 3306 -j ACCEPT -A INPUT -j REJECT –reject-with icmp-host-prohibited -A FORWARD -j REJECT –reject-with icmp-host-prohibited COMMIT #####################################
/etc/init.d/iptables restart #最后重启防火墙使配置生效
文章来自【 http://www.myhack58.com/Article/48/66/2012/34999.htm 】
相关文章推荐
- centos7笔记
- linux在文件打包和压缩
- 安装centos 5.3 想用中文出现乱码
- Linux上的日志系统
- kali linux 2.0 AMD x64安装
- CentOS 6.3下部署LVS(NAT)+keepalived实现高性能高可用负载均衡
- linux应用编程笔记(6)库函数方式实现文件复制编程
- CentOS 5 CentOS 6 启动流程及关键步骤
- centos7下yum安装mysql5.6
- Linux下如何释放内存、swap分区满了怎么办!
- Linux系统安装MySQL
- linux命令之-pstree使用说明
- 自助Linux之问题诊断工具strace
- 【linux学习笔记八】常用命令
- Syscall系统调用Linux内核跟踪
- Linux strace命令
- Linux系统启动过程分析
- linux主机名与IP地址配置文件
- Linux系统下pxe+dhcp+nfs+kickstart无人值守安装
- Linux应用总结(1):自动删除n天前日志