Iptabls production environment
1. Clear the iptables settings.
Iptables-F
Iptables-X
Iptables-Z
2. Configure to allow login port 22 to enter.
Iptables-t filter-An INPUT-p tcp-- dport 22-s 10.10.70.103-j ACCEPT
3. Set to allow native lo communication.
Iptables-t filter-An INPUT-I lo-j ACCEPT
Iptables-t filter-An OUTPUT-o lo-j ACCEPT
4. Set the default firewall prohibition and permission rules.
Iptables-P INPUT DROP
Iptables-P OUTPUT ACCEPT
Iptables-P FORWARD DROP
5. Enable the trusted iP segment
Iptables-An INPUT-s 10.10.69.0 take 24-p all-j ACCEPT
(including office fixed ip, IDC internal network segment, IDC external network segment)
6. Allow external access to the business service port (run the http service unconditionally)
Iptables-An INPUT-p tcp-- dport 80-j ACCEPT
7. Allow icmp type protocols to pass according to the circumstances
Iptables-An INPUT-p icmp--icmp-type any-j ACCEPT
8. Allow associated status packets to pass (do not use FTP services for web services)
Iptables-An INPUT-m state-- state ESTABLISHED,RELATED-j ACCEPT
Iptables-An OUTPUT-m state-- state ESTABLISHED,RELATED-j ACCEPT
9. Check: nmap 10.10.70.60-p 1-65535
10. Just save it.
/ etc/init.d/iptables save
Location: / etc/sysconfig/iptables