- 论坛徽章:
- 0
|
leo4364088 谢谢你,请问
# !/bin/bash
# leo4364088, 11/14/2006
export PATH=/sbin:/usr/sbin:/bin:/usr/bin
echo 1 >/proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
echo 0 >/proc/sys/net/ipv4/conf/all/accept_source_route
echo 0 >/proc/sys/net/ipv4/conf/all/accept_redirects
echo 1 >/proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
echo 1 >/proc/sys/net/ipv4/conf/all/log_martians
echo 1 >/proc/sys/net/ipv4/tcp_syncookies
echo 1 >/proc/sys/net/ipv4/ip_forward
iptables -F
iptables -X
iptables -Z
iptables -t nat -F
iptables -t nat -X
## Enable local interface pass
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
##Allow State
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
## http_service
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
## https_service
#iptables -A INPUT -p tcp --dport 443 -j ACCEPT
## mysql_service
#iptables -A INPUT -p tcp --dport 3306 -j ACCEPT
## smb_service
#iptables -A INPUT -p tcp --dport 139 -j ACCEPT
#iptables -A INPUT -p tcp --dport 901 -j ACCEPT
## sshd_service
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
## DNS_service
iptables -A INPUT -p udp --dport 53 -j ACCEPT
## smtp_service
iptables -A INPUT -p tcp --dport 25 -j ACCEPT
## pop3_service
iptables -A INPUT -p tcp --dport 110 -j ACCEPT
## Anything else not allowed
iptables -A INPUT -j DROP
这上面的是不是都是firewall文件里面的内容 |
|