Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Iptabls production environment

Shulou Source: shulou.com Published: 2022-06-01 10:00:25 10月02日 Update

1. Clear the iptables settings.

Iptables-F

Iptables-X

Iptables-Z

2. Configure to allow login port 22 to enter.

Iptables-t filter-An INPUT-p tcp-- dport 22-s 10.10.70.103-j ACCEPT

3. Set to allow native lo communication.

Iptables-t filter-An INPUT-I lo-j ACCEPT

Iptables-t filter-An OUTPUT-o lo-j ACCEPT

4. Set the default firewall prohibition and permission rules.

Iptables-P INPUT DROP

Iptables-P OUTPUT ACCEPT

Iptables-P FORWARD DROP

5. Enable the trusted iP segment

Iptables-An INPUT-s 10.10.69.0 take 24-p all-j ACCEPT

(including office fixed ip, IDC internal network segment, IDC external network segment)

6. Allow external access to the business service port (run the http service unconditionally)

Iptables-An INPUT-p tcp-- dport 80-j ACCEPT

7. Allow icmp type protocols to pass according to the circumstances

Iptables-An INPUT-p icmp--icmp-type any-j ACCEPT

8. Allow associated status packets to pass (do not use FTP services for web services)

Iptables-An INPUT-m state-- state ESTABLISHED,RELATED-j ACCEPT

Iptables-An OUTPUT-m state-- state ESTABLISHED,RELATED-j ACCEPT

9. Check: nmap 10.10.70.60-p 1-65535

10. Just save it.

/ etc/init.d/iptables save

Location: / etc/sysconfig/iptables

Tags: Service network segment port business location office situation computer room status type rules firewall local machine association office external inspection login operation communication Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno MySQL MariaDB OPPO Reno Shulou Tech Info Redmi