墨少离 - 个人小站,分享一些资源以及心得~ - IPTABLES https://www.msl.la/tag/IPTABLES/ zh-CN Sun, 21 Feb 2021 16:35:33 +0800 Sun, 21 Feb 2021 16:35:33 +0800 送上一个自用的IPTABLES规则,适合网站服务器 https://www.msl.la/archives/154/ https://www.msl.la/archives/154/ Sun, 21 Feb 2021 16:35:33 +0800 墨少离 IPT="/sbin/iptables" $IPT --delete-chain $IPT --flush $IPT -P INPUT DROP $IPT -P FORWARD DROP $IPT -P OUTPUT DROP $IPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT $IPT -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT $IPT -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT $IPT -A INPUT -p tcp -m tcp --dport 21 -j ACCEPT $IPT -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT $IPT -A INPUT -i lo -j ACCEPT $IPT -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT $IPT -A INPUT -p icmp -m icmp --icmp-type 11 -j ACCEPT $IPT -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT $IPT -A OUTPUT -p udp -m udp --dport 53 -j ACCEPT $IPT -A OUTPUT -o lo -j ACCEPT $IPT -A OUTPUT -p tcp -m tcp --dport 80 -j ACCEPT $IPT -A OUTPUT -p tcp -m tcp --dport 25 -j ACCEPT $IPT -A OUTPUT -p tcp -m tcp --dport 443 -j ACCEPT $IPT -A OUTPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT $IPT -A OUTPUT -p icmp -m icmp --icmp-type 11 -j ACCEPT service iptables save service iptables restart ]]> 0 https://www.msl.la/archives/154/#comments https://www.msl.la/feed/tag/IPTABLES/