- 论坛徽章:
- 0
|
开放80口,其他用不到的端口drop,这样不就行了。控制服务器向外的通信没必要也没意义。
#!/bin/bash
# The config create for EzLinux Base
# About new info please to http://system.aidns.cn
export PATH=/sbin:/usr/sbin:/bin:/usr/bin
iptables -F
iptables -X
iptables -Z
iptables -t nat -F
iptables -t nat -X
## Enable local interface pass
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
##Allow forwarding
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
## To our web_server
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
## Enable sshd_server
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
## icmp
iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
## Anything else not allowed
iptables -A INPUT -j DROP
|
|