{"id":2789,"date":"2012-03-27T12:48:40","date_gmt":"2012-03-27T04:48:40","guid":{"rendered":"http:\/\/jpuyy.com\/?p=2789"},"modified":"2012-09-27T12:05:42","modified_gmt":"2012-09-27T04:05:42","slug":"centos6-iptables-template","status":"publish","type":"post","link":"https:\/\/jpuyy.com\/?p=2789","title":{"rendered":"centos6.2\u57fa\u672ciptables\u6a21\u7248"},"content":{"rendered":"<p>vim \/etc\/sysconfig\/iptables<\/p>\n<pre># Generated by iptables-save v1.4.7 on Mon Mar 26 09:52:21 2012\r\n*filter\r\n:INPUT ACCEPT [0:0]\r\n:FORWARD DROP [0:0]\r\n:OUTPUT ACCEPT [0:0]\r\n-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT\r\n-A INPUT -p icmp -j ACCEPT\r\n-A INPUT -i lo -j ACCEPT\r\n-A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT\r\n-A INPUT -j REJECT --reject-with icmp-host-prohibited\r\n-A FORWARD -j REJECT --reject-with icmp-host-prohibited\r\nCOMMIT\r\n# Completed on Mon Mar 26 09:52:21 2012<\/pre>\n<p>-A \u9009\u9879\u6765\u9644\u52a0\uff08\u65b0\u589e\uff09\u89c4\u5219\u5230\u67d0\u6761\u94fe<\/p>\n<p>-i \u9009\u9879\uff08interface\u300c\u754c\u9762\u300d\u4e4b\u610f\uff09\u6765\u6307\u5b9a\u90a3\u4e9b\u7b26\u5408\u6216\u6765\u81ea lo\uff08localhost\u3001127.0.0.1\uff09\u754c\u9762\u7684\u5c01\u5305<\/p>\n<p>-j\uff08jump\u300c\u8df3\u81f3\u300d\uff09\u7b26\u5408\u8fd9\u6761\u89c4\u5219\u7684\u76ee\u6807\u52a8\u4f5c<\/p>\n<p>-m \u9009\u9879\u6765\u88c5\u5165\u4e00\u4e2a\u6a21\u5757\uff08state\uff09\u3002state \u6a21\u5757\u80fd\u591f\u67e5\u770b\u4e00\u4e2a\u5c01\u5305\u5e76\u5224\u65ad\u5b83\u7684\u72b6\u6001\u662f NEW\u3001ESTABLISHED \u6291\u6216 RELATED\u3002NEW \u6307\u8fdb\u5165\u7684\u5c01\u5305\u5c5e\u4e8e\u4e0d\u662f\u7531\u4e3b\u673a\u521d\u59cb\u5316\u7684\u65b0\u589e\u8fde\u63a5\u3002ESTABLISHED \u53ca RELATED \u6307\u8fdb\u5165\u7684\u5c01\u5305\u96b6\u5c5e\u4e8e\u4e00\u6761\u73b0\u5b58\u7684\u8fde\u63a5\uff0c\u6216\u8005\u4e0e\u73b0\u5b58\u7684\u8fde\u63a5\u6709\u5173\u7cfb\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>vim \/etc\/sysconfig\/iptables # Generated by iptables-save v1.4.7 on Mon Mar 26 09:52:21 2012 *filter :INPUT ACCEPT [0:0] :FORWARD DROP [0:0] :OUTPUT ACCEPT [0:0] -A INPUT -m state &#8211;state ESTABLISHED,RELATED -j ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -m state &#8211;state NEW -m tcp -p tcp &#8211;dport 22 [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[87,23],"class_list":["post-2789","post","type-post","status-publish","format-standard","hentry","category-linux","tag-centos","tag-summary"],"_links":{"self":[{"href":"https:\/\/jpuyy.com\/index.php?rest_route=\/wp\/v2\/posts\/2789","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jpuyy.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jpuyy.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jpuyy.com\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/jpuyy.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2789"}],"version-history":[{"count":5,"href":"https:\/\/jpuyy.com\/index.php?rest_route=\/wp\/v2\/posts\/2789\/revisions"}],"predecessor-version":[{"id":2792,"href":"https:\/\/jpuyy.com\/index.php?rest_route=\/wp\/v2\/posts\/2789\/revisions\/2792"}],"wp:attachment":[{"href":"https:\/\/jpuyy.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2789"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jpuyy.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2789"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jpuyy.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2789"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}