- 论坛徽章:
- 0
|
本帖最后由 nameofhsw 于 2015-12-25 15:59 编辑
配置IPTABLES的目的是,允许所有人访问,但是输出只允许到指定IP
iptables配置内容如下:
- # Firewall configuration written by system-config-firewall
- # Manual customization of this file is not recommended.
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
- -A OUTPUT -p tcp -d 127.0.0.1 -j ACCEPT
- -A OUTPUT -p tcp -d 192.168.81.138 -j ACCEPT
- -A OUTPUT -p tcp -d 192.168.81.232 -j ACCEPT
- -A OUTPUT -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- COMMIT
复制代码 启用后,无法ping,也无法被ping,要怎么修改才能被允许的IP地址ping通呢?
|
|