{"id":13382,"date":"2022-08-30T22:09:12","date_gmt":"2022-08-30T14:09:12","guid":{"rendered":"https:\/\/ailog.tw\/lifelog\/?p=13382"},"modified":"2022-08-30T22:09:12","modified_gmt":"2022-08-30T14:09:12","slug":"ol8-iptables","status":"publish","type":"post","link":"https:\/\/ailog.tw\/lifelog\/2022\/08\/30\/ol8-iptables\/","title":{"rendered":"CentOS 8\/Oracle Linux 8\u4f7f\u7528iptables\u9632\u706b\u7246"},"content":{"rendered":"<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\">\u5c0f\u7de8\u5728Linux\u7cfb\u7d71\u4f7f\u7528iptables\u5df2\u7d93\u5f88\u591a\u5e74\u4e86\uff0c\u4f46\u65b0\u7248\u7684Linux\u9810\u8a2d\u662f\u63a1\u7528firewalld\uff0c\u96e3\u514d\u9084\u662f\u6709\u4e9b\u4e0d\u7fd2\u6163\uff0c\u5982\u679c\u4f60\u8ddf\u5c0f\u7de8\u4e00\u6a23\u662f\u61f7\u820a\u7684\u4eba\uff0c\u90a3\u5c31\u4e0d\u53ef\u932f\u904e\u9019\u4e00\u7bc7\u5728\u65b0\u7248Linux\u555f\u7528iptables\u7684\u6587\u7ae0\u3002<!--more--><\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set01\u3001\u505c\u7528firewalld\u670d\u52d9<\/strong><\/span><br \/>\n<span style=\"font-family: verdana, geneva; font-size: 14pt;\">\u8a9e\u6cd5\uff1a<\/span><br \/>\n<span style=\"font-family: verdana, geneva; font-size: 14pt;\">systemctl stop firewalld<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13386 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-01.png\" alt=\"\" width=\"643\" height=\"95\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-01.png 643w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-01-300x44.png 300w\" sizes=\"auto, (max-width: 643px) 100vw, 643px\" \/><\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set02\u3001\u95dc\u9589firewalld\u670d\u52d9<\/strong><br \/>\n\u8a9e\u6cd5\uff1a<br \/>\nsystemctl mask firewalld<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13387 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-02.png\" alt=\"\" width=\"934\" height=\"126\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-02.png 934w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-02-300x40.png 300w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-02-768x104.png 768w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set03\u3001\u5b89\u88ddiptables\u5957\u4ef6<\/strong><br \/>\n\u8a9e\u6cd5\uff1a<br \/>\nyum install -y iptables<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13388 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-03.png\" alt=\"\" width=\"880\" height=\"103\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-03.png 880w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-03-300x35.png 300w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-03-768x90.png 768w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><br \/>\n<\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set04\u3001\u66f4\u65b0iptables\u5957\u4ef6<\/strong><br \/>\n\u8a9e\u6cd5\uff1a<br \/>\nyum update iptables<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13389 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-04.png\" alt=\"\" width=\"629\" height=\"160\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-04.png 629w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-04-300x76.png 300w\" sizes=\"auto, (max-width: 629px) 100vw, 629px\" \/><\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set05\u3001\u5b89\u88ddiptables\u670d\u52d9\u5957\u4ef6<\/strong><br \/>\n\u8a9e\u6cd5\uff1a<br \/>\nyum install -y iptables-services<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13391 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-05.png\" alt=\"\" width=\"813\" height=\"100\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-05.png 813w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-05-300x37.png 300w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-05-768x94.png 768w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set06\u3001\u8a2d\u5b9a\u958b\u6a5f\u555f\u52d5iptables\u670d\u52d9<\/strong><br \/>\n\u8a9e\u6cd5\uff1a<br \/>\nsystemctl enable iptables.service<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13393 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-06.png\" alt=\"\" width=\"776\" height=\"128\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-06.png 776w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-06-300x49.png 300w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-06-768x127.png 768w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set07\u3001\u6aa2\u67e5iptables\u72c0\u614b<\/strong><\/span><br \/>\n<span style=\"font-family: verdana, geneva; font-size: 14pt;\">\u8a9e\u6cd5\uff1a<br \/>\nservice iptables status<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13394 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-07.png\" alt=\"\" width=\"638\" height=\"200\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-07.png 638w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-07-300x94.png 300w\" sizes=\"auto, (max-width: 638px) 100vw, 638px\" \/><br \/>\n<\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set08\u3001\u8a2d\u5b9a\u9810\u8a2d\u898f\u5247<\/strong><\/span><br \/>\n<span style=\"font-family: verdana, geneva; font-size: 14pt;\">\u8a9e\u6cd5\uff1a<\/span><br \/>\n<span style=\"font-family: verdana, geneva; font-size: 14pt;\">iptables -p input accept<\/span><br \/>\n<span style=\"font-family: verdana, geneva; font-size: 14pt;\">iptables -p output accept<\/span><br \/>\n<span style=\"font-family: verdana, geneva; font-size: 14pt;\">iptables -p forward accept<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13400 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-08.png\" alt=\"\" width=\"772\" height=\"138\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-08.png 772w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-08-300x54.png 300w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-08-768x137.png 768w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><br \/>\n<span style=\"color: #ff0000;\">\u203b\u6ce8\u610f\u8a9e\u6cd5\u7684\u5927\u5c0f\u5beb<\/span><\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set09\u3001\u6e05\u9664\u9632\u706b\u7246\u76f8\u95dc\u898f\u5247<\/strong><\/span><br \/>\n<span style=\"font-family: verdana, geneva; font-size: 14pt;\">(1)\u3001\u6e05\u9664\u9632\u706b\u7246\u898f\u5247<br \/>\n\u8a9e\u6cd5\uff1a<\/span><br \/>\n<span style=\"font-family: verdana, geneva; font-size: 14pt;\">iptables -F<\/span><br \/>\n<span style=\"font-family: verdana, geneva; font-size: 14pt;\">iptables -X<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13401 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-09.png\" alt=\"\" width=\"552\" height=\"116\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-09.png 552w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-09-300x63.png 300w\" sizes=\"auto, (max-width: 552px) 100vw, 552px\" \/><\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\">(2)\u3001\u6e05\u9664mangle\u898f\u5247<br \/>\n\u8a9e\u6cd5\uff1a<br \/>\niptables -F -t mangle<br \/>\niptables -t mangle -X<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13402 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-10.png\" alt=\"\" width=\"687\" height=\"110\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-10.png 687w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-10-300x48.png 300w\" sizes=\"auto, (max-width: 687px) 100vw, 687px\" \/><\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\">(3)\u3001\u6e05\u9664NAT\u898f\u5247<br \/>\n\u8a9e\u6cd5\uff1a<br \/>\niptables -F -t nat<br \/>\niptables -t nat -X<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13403 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-11-e1661867066782.png\" alt=\"\" width=\"641\" height=\"96\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-11-e1661867066782.png 641w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-11-e1661867066782-300x45.png 300w\" sizes=\"auto, (max-width: 641px) 100vw, 641px\" \/><br \/>\n<\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set11\u3001\u67e5\u8a62iptables\u76ee\u524d\u898f\u5247<\/strong><br \/>\n\u8a9e\u6cd5\uff1a<br \/>\niptables -L -v -n | more<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13405 size-large\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-12-1024x290.png\" alt=\"\" width=\"525\" height=\"149\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-12-1024x290.png 1024w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-12-300x85.png 300w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-12-768x218.png 768w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-12.png 1114w\" sizes=\"auto, (max-width: 525px) 100vw, 525px\" \/><br \/>\n<\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set10\u3001\u8a2d\u5b9a\u5141\u8a31192.168.8.15\u900f\u904eTCP\u5354\u5b9a\u9023\u5165\u4e3b\u6a5f\uff0c\u5176\u4ed6\u4e3b\u6a5f\u7684TCP\u5354\u5b9a\u62d2\u7d55\u9023\u7dda<\/strong><br \/>\n\u8a9e\u6cd5\uff1a<br \/>\niptables -A INPUT -p tcp -s 192.168.8.15 -j ACCEPT<br \/>\niptables -A INPUT -p tcp -j DROP<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13407 size-full\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-13.png\" alt=\"\" width=\"1014\" height=\"120\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-13.png 1014w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-13-300x36.png 300w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-13-768x91.png 768w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/span><\/p>\n<p><span style=\"font-family: verdana, geneva; font-size: 14pt;\"><strong>Set10\u3001\u6307\u5b9a\u7db2\u8def\u5361\u8a2d\u5b9a\u9632\u706b\u7246\u898f\u5247<br \/>\n\u8a9e\u6cd5\uff1a<br \/>\n<\/strong><span style=\"font-size: 12pt;\">iptables -A INPUT -i ens224 -p tcp -s 192.168.5.69 -j ACCEPT<br \/>\niptables -L -v -n | more<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-13409 size-large\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-14-1024x334.png\" alt=\"\" width=\"525\" height=\"171\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-14-1024x334.png 1024w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-14-300x98.png 300w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-14-768x250.png 768w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2022\/08\/ol8-iptables-14.png 1148w\" sizes=\"auto, (max-width: 525px) 100vw, 525px\" \/><\/span><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5c0f\u7de8\u5728Linux\u7cfb\u7d71\u4f7f\u7528iptables\u5df2\u7d93\u5f88\u591a\u5e74\u4e86\uff0c\u4f46\u65b0\u7248\u7684Linux\u9810\u8a2d\u662f\u63a1\u7528firewalld\uff0c\u96e3\u514d\u9084\u662f &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/ailog.tw\/lifelog\/2022\/08\/30\/ol8-iptables\/\" class=\"more-link\">\u95b1\u8b80\u5168\u6587<span class=\"screen-reader-text\">\u3008CentOS 8\/Oracle Linux 8\u4f7f\u7528iptables\u9632\u706b\u7246\u3009<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":13399,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,381,385],"tags":[5286,5536,5535,5285,5537],"class_list":["post-13382","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-itinfo","category-firewall","category-security","tag-centos-8","tag-firewalld","tag-iptables","tag-oracle-linux-8","tag-5537"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/posts\/13382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/comments?post=13382"}],"version-history":[{"count":13,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/posts\/13382\/revisions"}],"predecessor-version":[{"id":13411,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/posts\/13382\/revisions\/13411"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/media\/13399"}],"wp:attachment":[{"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/media?parent=13382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/categories?post=13382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/tags?post=13382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}