- 論壇徽章:
- 0
|
本帖最后由 nameofhsw 于 2015-12-25 15:59 編輯
配置IPTABLES的目的是,允許所有人訪問,但是輸出只允許到指定IP
iptables配置內(nèi)容如下:
- # Firewall configuration written by system-config-firewall
- # Manual customization of this file is not recommended.
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
- -A OUTPUT -p tcp -d 127.0.0.1 -j ACCEPT
- -A OUTPUT -p tcp -d 192.168.81.138 -j ACCEPT
- -A OUTPUT -p tcp -d 192.168.81.232 -j ACCEPT
- -A OUTPUT -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- COMMIT
復制代碼 啟用后,無法ping,也無法被ping,要怎么修改才能被允許的IP地址ping通呢?
|
|