- 论坛徽章:
- 0
|
本帖最后由 szhw520 于 2013-09-07 16:12 编辑
大家好!小弟配置了iptables .想在公司里面给服务器安装下,然后做些策略。可是策略都搞好了,如果一条一条地在bash里面加入就可以..
可当我重启iptables 的时候,就会恢复成一个iptables文件里面都是这些行:
# Generated by iptables-save v1.4.1.1 on Wed Dec 24 02:09:08 2008
*nat
REROUTING ACCEPT [229:34076]
OSTROUTING ACCEPT [110:7392]
:OUTPUT ACCEPT [110:7392]
[0:0] -A POSTROUTING -s 192.168.122.0/24 -d ! 192.168.122.0/24 -j MASQUERADE
COMMIT
# Completed on Wed Dec 24 02:09:08 2008
# Generated by iptables-save v1.4.1.1 on Wed Dec 24 02:09:08 2008
*mangle
REROUTING ACCEPT [8942:1066240]
:INPUT ACCEPT [8942:1066240]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [7774:879339]
OSTROUTING ACCEPT [7774:879339]
COMMIT
# Completed on Wed Dec 24 02:09:08 2008
# Generated by iptables-save v1.4.1.1 on Wed Dec 24 02:09:08 2008
*filter
:INPUT ACCEPT [8942:1066240]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [7774:879339]
[0:0] -A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
[0:0] -A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
[0:0] -A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
[0:0] -A INPUT -s 192.168.0.8/32 -j ACCEPT
[0:0] -A FORWARD -d 192.168.122.0/24 -o virbr0 -m state --state RELATED,ESTABLISHED -j ACCEPT
[0:0] -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
[0:0] -A FORWARD -i virbr0 -o virbr0 -j ACCEPT
[0:0] -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
[0:0] -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
COMMIT
# Completed on Wed Dec 24 02:09:08 2008
为什么会这样,原来的策略很长的,我在vi里面保存了一下。然后重启了service iptables restart 就会变成以上的文件。
我查看/etc/sysconfig/里面有很多.iptables.conf.swp /.iptables.config.swi 等文件。它们怎么删除不掉啊?
源文件载下来的一些:
# Generated by iptables-save v1.4.1.1 on Tue Dec 23 13:16:04 2008
*nat
REROUTING ACCEPT [43869:2698271]
OSTROUTING ACCEPT [1050:70277]
:OUTPUT ACCEPT [1050:70277]
COMMIT
# Completed on Tue Dec 23 13:16:04 2008
# Generated by iptables-save v1.4.1.1 on Tue Dec 23 13:16:04 2008
*mangle
REROUTING ACCEPT [67690:12749105]
:INPUT ACCEPT [67690:12749105]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [51529:2974597]
OSTROUTING ACCEPT [51529:2974597]
COMMIT
# Completed on Tue Dec 23 13:16:04 2008
# Generated by iptables-save v1.4.1.1 on Tue Dec 23 13:16:04 2008
*filter
:INPUT ACCEPT [67688:12749009]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [49897:2754008]
[0:0] -A FORWARD -p tcp -m multiport --dports 25 -j ACCEPT
[0:0] -A FORWARD -p tcp -m multiport --dports 110 -j ACCEPT
[0:0] -A FORWARD -p udp -m multiport --dports 25 -j ACCEPT
[0:0] -A FORWARD -p udp -m multiport --dports 110 -j ACCEPT
[0:0] -A FORWARD -p udp -m multiport --dports 53 -j ACCEPT
[0:0] -A FORWARD -p tcp -m multiport --dports 53 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.9/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.10/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.11/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.12/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.13/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.14/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.15/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.16/32 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.20/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.8/32 -p tcp -m multiport --dports 80 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.8/32 -p tcp -m multiport --dports 80,225 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.17/32 -p tcp -m multiport --dports 25,53,80,110,443,1863,8000,8001,8002,8080 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.18/32 -p tcp -m multiport --dports 25,53,80,110,443,1863,8000,8001,8002,8080 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.19/32 -p tcp -m multiport --dports 25,53,80,110,443,1863,8000,8001,8002,8080 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.20/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.21/32 -p tcp -m multiport --dports 25,53,80,110,443,1863,8000,8001,8002,8080 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.22/32 -p tcp -m multiport --dports 25,53,80,110,443,1863,8000,8001,8002,8080 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.23/32 -p tcp -m multiport --dports 25,53,80,110,443,1863,8000,8001,8002,8080 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.24/32 -p tcp -m multiport --dports 25,53,80,110,443,1863,8000,8001,8002,8080 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.25/32 -p tcp -m multiport --dports 25,53,80,110,443,1863,8000,8001,8002,8080 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.26/32 -p tcp -m multiport --dports 25,53,80,110,443,1863,8000,8001,8002,8080 -j ACCEPT
[0:0] -A FORWARD -s 192.168.0.27/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.28/32 -j DROP
[0:0] -A FORWARD -s 192.168.0.29/32 -j DROP
救救我。 |
|