首页 新闻 会员 周边 捐助

关于centos6.X 系统的iptables策略

0
悬赏园豆:5 [已关闭问题] 关闭于 2019-05-29 07:41

iptables策略一:

Firewall configuration written by system-config-firewall

Manual customization of this file is not recommended.

*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p tcp --dport 22 -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT

iptables策略二:

Firewall configuration written by system-config-firewall

Manual customization of this file is not recommended.

*filter
:INPUT DROP [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p tcp --dport 22 -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT

两套策略仅将:INPUT默认策略分别为ACCEPT和DROP,这两套测略下对入站的数据包处理过程中有什么不同?

叼着辣条的猫的主页 叼着辣条的猫 | 菜鸟二级 | 园豆:202
提问于:2019-05-28 23:52
< >
分享
清除回答草稿
   您需要登录以后才能回答,未注册用户请先注册