Linux CentOS6.5 Firewall (shuts down ports other than providing system services)
1. Allow SSH service to connect, otherwise it cannot connect remotely to the server (add input chain rule: tcp protocol opens port 22 to accept action)
#iptables -A INPUT -p tcp --dport 22 -j ACCEPT
2. Set the default rule. The default is to prohibit all inbound connections and open outbound connections.
(1) Set the default incoming packet to drop. (That is, the machine does not accept any connections by default, unless the rules for receiving are set on the INPUT chain.)
#iptables -P INPUT DROP
(2) Set default to allow outgoing packets
#iptables -P OUTPUT ACCEPT
(3) Set default rule: forward to discard
#iptables -P FORWARD DROP
3. Then open the port that needs to provide services to the outside world, such as opening port 80 (add input chain rule: allow tcp protocol to open port 80 action to accept)
#iptables -A INPUT -p tcp --dport 80 -j ACCEPT
4. Preservation rules
#service iptables save
5. Restart iptables entry into force rules
#service iptables restart
Note: Commands are automatically saved to/etc/sysconfig/iptables.