- 论坛徽章:
- 0
|
我有台redhat9的机器我用依次用以下命令
iptables -F
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWORD DROP
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -A OUTPUT -P udp --sport 22 -j ACCEPT
service iptables save
service iptables restart
结果22 端口就是打不开 远程连接不上.
/etc/sysconfig/iptables 的内容为
# Generated by iptables-save v1.2.7a on Sat May 21 13:31:30 2005
*filter
:INPUT ACCEPT [0]
:FORWARD DROP [0]
:OUTPUT ACCEPT [599]
:RH-Lokkit-0-50-INPUT - [0]
[0] -A INPUT -j RH-Lokkit-0-50-INPUT
[2] -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
[0] -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
[0] -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
[0] -A FORWARD -p udp -m udp --sport 22 -j ACCEPT
[0] -A FORWARD -j RH-Lokkit-0-50-INPUT
[0] -A OUTPUT -p udp -m udp --sport 22 -j ACCEPT
[58] -A RH-Lokkit-0-50-INPUT -i lo -j ACCEPT
[11] -A RH-Lokkit-0-50-INPUT -s 61.153.177.196 -p udp -m udp --sport 53 -j ACCEPT
[1647] -A RH-Lokkit-0-50-INPUT -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j REJECT --reject-with icmp-port-unreachable
[618] -A RH-Lokkit-0-50-INPUT -p udp -m udp -j REJECT --reject-with icmp-port-unreachable
COMMIT
我是初用IPTABLES 哪为朋友能告诉我哪里有问题? 先谢了! |
|