iptables 开放80端口

2012-02-17 22:13  1574人阅读  评论 (0)

快速设置脚本:

yum install -y iptables-services

iptables -P INPUT ACCEPT
iptables -F
iptables -X
iptables -Z

iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p icmp -j ACCEPT
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -j REJECT --reject-with icmp-host-prohibited
iptables -A FORWARD -j REJECT --reject-with icmp-host-prohibited
iptables -P INPUT DROP

service iptables save

systemctl enable iptables
systemctl start iptables

iptables -vnL

原始的 /etc/sysconfig/iptables

# Firewall configuration written by system-config-firewall
# Manual customization of this file is not recommended.
*filter
:INPUT DROP [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT

centos7安装iptables服务

yum install -y iptables-services
systemctl enable iptables
systemctl start iptables

常用命令

# 添加80端口
iptables -A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
# 插入80端口
iptables -I INPUT 3 -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
# 删除规则
iptables -D INPUT 3
# 保存修改
service iptables save
# 重启
service iptables restart
# 查看状态
service iptables status
# 端口转发 注意规则顺序
iptables -I INPUT 5 -m state --state NEW -m tcp -p tcp --dport 4025 -j ACCEPT
iptables -t nat -A PREROUTING -i enp0s3 -p tcp --dport 25 -j REDIRECT --to-ports 4025
# 查看nat规则
iptables -t nat -vnL

iptables 流程

iptables流程图

参考地址

https://wiki.centos.org/zh/HowTos/Network/IPTables https://www.centos.org/docs/5/html/Deployment_Guide-en-US/ch-fw.html https://www.centos.org/docs/5/html/Deployment_Guide-en-US/ch-iptables.html

注意:

在 /etc/sysconfig/iptables 文件中

-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT

不能放在

-A INPUT -j REJECT --reject-with icmp-host-prohibited

的后边,否则不能访问。