<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>iptables &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/iptables/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Tue, 30 Aug 2022 14:09:12 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>CentOS 8/Oracle Linux 8使用iptables防火牆</title>
		<link>https://ailog.tw/lifelog/2022/08/30/ol8-iptables/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Tue, 30 Aug 2022 14:09:12 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Centos 8]]></category>
		<category><![CDATA[firewalld]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[Oracle Linux 8]]></category>
		<category><![CDATA[指定網卡]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=13382</guid>

					<description><![CDATA[小編在Linux系統使用iptables已經很多年了，但新版的Linux預設是採用firewalld，難免還是 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2022/08/30/ol8-iptables/" class="more-link">閱讀全文<span class="screen-reader-text">〈CentOS 8/Oracle Linux 8使用iptables防火牆〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva; font-size: 14pt;">小編在Linux系統使用iptables已經很多年了，但新版的Linux預設是採用firewalld，難免還是有些不習慣，如果你跟小編一樣是懷舊的人，那就不可錯過這一篇在新版Linux啟用iptables的文章。<span id="more-13382"></span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set01、停用firewalld服務</strong></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">語法：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">systemctl stop firewalld<br />
<img fetchpriority="high" decoding="async" class="alignnone wp-image-13386 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-01.png" alt="" width="643" height="95" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-01.png 643w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-01-300x44.png 300w" sizes="(max-width: 643px) 100vw, 643px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set02、關閉firewalld服務</strong><br />
語法：<br />
systemctl mask firewalld<br />
<img decoding="async" class="alignnone wp-image-13387 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-02.png" alt="" width="934" height="126" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-02.png 934w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-02-300x40.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-02-768x104.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set03、安裝iptables套件</strong><br />
語法：<br />
yum install -y iptables<br />
<img decoding="async" class="alignnone wp-image-13388 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-03.png" alt="" width="880" height="103" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-03.png 880w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-03-300x35.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-03-768x90.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set04、更新iptables套件</strong><br />
語法：<br />
yum update iptables<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13389 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-04.png" alt="" width="629" height="160" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-04.png 629w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-04-300x76.png 300w" sizes="auto, (max-width: 629px) 100vw, 629px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set05、安裝iptables服務套件</strong><br />
語法：<br />
yum install -y iptables-services<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13391 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-05.png" alt="" width="813" height="100" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-05.png 813w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-05-300x37.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-05-768x94.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set06、設定開機啟動iptables服務</strong><br />
語法：<br />
systemctl enable iptables.service<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13393 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-06.png" alt="" width="776" height="128" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-06.png 776w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-06-300x49.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-06-768x127.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set07、檢查iptables狀態</strong></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">語法：<br />
service iptables status<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13394 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-07.png" alt="" width="638" height="200" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-07.png 638w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-07-300x94.png 300w" sizes="auto, (max-width: 638px) 100vw, 638px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set08、設定預設規則</strong></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">語法：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">iptables -p input accept</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">iptables -p output accept</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">iptables -p forward accept<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13400 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-08.png" alt="" width="772" height="138" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-08.png 772w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-08-300x54.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-08-768x137.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
<span style="color: #ff0000;">※注意語法的大小寫</span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set09、清除防火牆相關規則</strong></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">(1)、清除防火牆規則<br />
語法：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">iptables -F</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">iptables -X<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13401 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-09.png" alt="" width="552" height="116" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-09.png 552w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-09-300x63.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(2)、清除mangle規則<br />
語法：<br />
iptables -F -t mangle<br />
iptables -t mangle -X<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13402 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-10.png" alt="" width="687" height="110" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-10.png 687w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-10-300x48.png 300w" sizes="auto, (max-width: 687px) 100vw, 687px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(3)、清除NAT規則<br />
語法：<br />
iptables -F -t nat<br />
iptables -t nat -X<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13403 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-11-e1661867066782.png" alt="" width="641" height="96" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-11-e1661867066782.png 641w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-11-e1661867066782-300x45.png 300w" sizes="auto, (max-width: 641px) 100vw, 641px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set11、查詢iptables目前規則</strong><br />
語法：<br />
iptables -L -v -n | more<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13405 size-large" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-12-1024x290.png" alt="" width="525" height="149" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-12-1024x290.png 1024w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-12-300x85.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-12-768x218.png 768w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-12.png 1114w" sizes="auto, (max-width: 525px) 100vw, 525px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set10、設定允許192.168.8.15透過TCP協定連入主機，其他主機的TCP協定拒絕連線</strong><br />
語法：<br />
iptables -A INPUT -p tcp -s 192.168.8.15 -j ACCEPT<br />
iptables -A INPUT -p tcp -j DROP<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13407 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-13.png" alt="" width="1014" height="120" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-13.png 1014w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-13-300x36.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-13-768x91.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set10、指定網路卡設定防火牆規則<br />
語法：<br />
</strong><span style="font-size: 12pt;">iptables -A INPUT -i ens224 -p tcp -s 192.168.5.69 -j ACCEPT<br />
iptables -L -v -n | more<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13409 size-large" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-14-1024x334.png" alt="" width="525" height="171" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-14-1024x334.png 1024w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-14-300x98.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-14-768x250.png 768w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-14.png 1148w" sizes="auto, (max-width: 525px) 100vw, 525px" /></span></span></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
