您的位置:首页 > 运维架构 > Linux

centos 防火墙规则开放22 80 ,8080

2015-07-03 12:19 561 查看
# Firewall configuration written by system-config-firewall

# Manual customization of this file is not recommended.

*filter

:INPUT ACCEPT [0:0]

:FORWARD ACCEPT [0:0]

:OUTPUT ACCEPT [0:0]

-A INPUT -s 61.160.247.180/32 -j DROP

-A INPUT -s 222.186.56.40/32 -j DROP

-A INPUT -s 222.186.34.245/32 -j DROP

-A INPUT -s 217.146.14.42/32 -j DROP

-A INPUT -s 173.194.127.212/32 -j DROP

-A INPUT -s 115.231.17.9/32 -j DROP

-A INPUT -s 115.231.17.13/32 -j DROP

-A INPUT -s 5.9.50.203/32 -j DROP

-A INPUT -s 122.225.97.88/32 -j DROP

-A INPUT -s 213.39.44.243/32 -j DROP

-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

-A INPUT -p icmp -j ACCEPT

-A INPUT -i lo -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp --dport 8080 -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp --dport 61616 -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp --dport 3306 -j ACCEPT

-A INPUT -j REJECT --reject-with icmp-host-prohibited

-A FORWARD -d 115.231.17.9/32 -j DROP

-A FORWARD -s 115.231.17.9/32 -j DROP

-A FORWARD -d 115.231.17.13/32 -j DROP

-A FORWARD -s 115.231.17.13/32 -j DROP

-A FORWARD -d 173.194.127.212/32 -j DROP

-A FORWARD -s 173.194.127.212/32 -j DROP

-A FORWARD -d 5.9.50.203/32 -j DROP

-A FORWARD -s 5.9.50.203/32 -j DROP

-A FORWARD -s 217.146.14.42/32 -j DROP

-A FORWARD -d 217.146.14.42/32 -j DROP

-A FORWARD -s 61.160.247.180/32 -j DROP

-A FORWARD -d 61.160.247.180/32 -j DROP

-A FORWARD -s 213.39.44.243/32 -j DROP

-A FORWARD -d 213.39.44.243/32 -j DROP

-A FORWARD -j REJECT --reject-with icmp-host-prohibited

-A OUTPUT -s 217.146.14.42/32 -j DROP

-A OUTPUT -d 122.225.97.88/32 -j DROP

-A OUTPUT -d 173.194.127.212/32 -j DROP

-A OUTPUT -d 115.231.17.9/32 -j DROP

-A OUTPUT -d 115.231.17.13/32 -j DROP

-A OUTPUT -d 5.9.50.203/32 -j DROP

-A OUTPUT -d 61.160.247.180/32 -j DROP

-A OUTPUT -d 213.39.44.243/32 -j DROP

COMMIT
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签: