//添加开放的端口和固定ip

vi  /etc/sysconfig/iptables

SRE实战 互联网时代守护先锋,助力企业售后服务体系运筹帷幄!一键直达领取阿里云限量特价优惠。

 

[root@root220156 /]# echo "unset MAILCHECK">> /etc/profile 禁止弹出发邮件

开启固定ip和端口访问配置:

-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

-A INPUT -p icmp -j ACCEPT

-A INPUT -i lo -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.137.5 -m multiport --dports 10102,80 -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.137.21 -m multiport --dports 10102,80 -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.137.1 -m multiport --dports 10102,80 -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.17.157 -m multiport --dports 10102,80 -j ACCEPT

 

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.115.23  --dport 80 -j ACCEPT

-A INPUT -m state --state NEW -m tcp -p tcp -s 192.168.107.233  --dport 80 -j ACCEPT

-A INPUT -j REJECT --reject-with icmp-host-prohibited

-A FORWARD -j REJECT --reject-with icmp-host-prohibited

COMMIT

service iptables restart  重启防火墙

扫码关注我们
微信号:SRE实战
拒绝背锅 运筹帷幄