最終更新: triplexsys 2014年01月11日(土) 17:56:29履歴
- 以下の内容を/etc/sysconfig/iptablesに記入
*filter
:INPUT DROP [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state NEW -p tcp --dport 80 -j ACCEPT
-A INPUT -m state --state NEW -p tcp --dport 443 -j ACCEPT
-A INPUT -m state --state NEW -p tcp --dport 22222 \
-m hashlimit --hashlimit-burst 5 --hashlimit 1/m --hashlimit-mode srcip \
--hashlimit-htable-expire 120000 --hashlimit-name ssh-limit -j ACCEPT
-A INPUT -p udp --dport 5353 -d 224.0.0.251 -j ACCEPT
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -j LOG --log-prefix "iptables:" --log-level=error
COMMIT
- カテゴリ:
- インターネット
- Webプログラミング
このページへのコメント
YEOVk2 Fantastic article.Really thank you! Great.
UCppYt Very neat blog post.Much thanks again. Much obliged.
pTXcqh I think this is a real great blog article. Will read on...
KRK3lg Thanks-a-mundo for the article.Really thank you! Fantastic.
TVCXZk <a href="http://vzuynzqflyzg.com/">vzuynzqflyzg</a>, [url=http://epgwkkeggpdb.com/]epgwkkeggpdb[/url], [link=http://dpymipjshmiw.com/]dpymipjshmiw[/link], http://nfkzznfcihwl.com/