防火墙相关操作:
Redhat5和6:
service iptables stop
service iptables off
Redhat7:
systemctl stop firewalld.service
systemctl disable firewalld.service
防火墙策略:
添加一条策略:
-
禁用22端口
iptables -A INPUT -p tcp --dport 22 -j DROP
service iptables save
-
删掉某一个策略
示例:
[root@single1 ~]# service iptables status
Table: filter
Chain INPUT (policy ACCEPT)
num target prot opt source destination
1 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
2 ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
3 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
4 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:22
5 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
6 DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:1521
Chain FORWARD (policy ACCEPT)
num target prot opt source destination
1 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
Chain OUTPUT (policy ACCEPT)
num target prot opt source destination
删掉2 ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
则执行: iptables -D INPUT 2