Drop INPUT, FORWARD
# iptables -P INPUT DROP
# iptables -P FORWARD DROPAccept establised
# iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPTAccept loopback
# iptables -A INPUT -s 127.0.0.0/8 -d 127.0.0.0/8 -i lo -j ACCEPTAccept SSH
# iptables -A INPUT -p tcp --dport 22 -i eth0 -j ACCEPTAccept ICMP
# iptables -A INPUT -p icmp -j ACCEPTView
# iptables -LWith line numbers
# iptables -L --line-numbersSave
# iptables-save > /root/fw.confTo enable on next boot, add line to
/etc/rc.d/rc.localiptables-restore < /root/fw.conf
Nav komentāru:
Ierakstīt komentāru