墨少离 - 个人小站,分享一些资源以及心得~ - IPTABLES 2021-02-21T16:35:33+08:00 Typecho https://www.msl.la/feed/atom/tag/IPTABLES/ <![CDATA[送上一个自用的IPTABLES规则,适合网站服务器]]> https://www.msl.la/archives/154/ 2021-02-21T16:35:33+08:00 2021-02-21T16:35:33+08:00 墨少离 https://www.msl.la/ IPT="/sbin/iptables" $IPT --delete-chain $IPT --flush $IPT -P INPUT DROP $IPT -P FORWARD DROP $IPT -P OUTPUT DROP $IPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT $IPT -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT $IPT -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT $IPT -A INPUT -p tcp -m tcp --dport 21 -j ACCEPT $IPT -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT $IPT -A INPUT -i lo -j ACCEPT $IPT -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT $IPT -A INPUT -p icmp -m icmp --icmp-type 11 -j ACCEPT $IPT -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT $IPT -A OUTPUT -p udp -m udp --dport 53 -j ACCEPT $IPT -A OUTPUT -o lo -j ACCEPT $IPT -A OUTPUT -p tcp -m tcp --dport 80 -j ACCEPT $IPT -A OUTPUT -p tcp -m tcp --dport 25 -j ACCEPT $IPT -A OUTPUT -p tcp -m tcp --dport 443 -j ACCEPT $IPT -A OUTPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT $IPT -A OUTPUT -p icmp -m icmp --icmp-type 11 -j ACCEPT service iptables save service iptables restart ]]>