centos防火牆新增埠8080 版本2.6.32-279.el6.x86_64
阿新 • • 發佈:2019-01-04
centos防火牆新增埠:
執行 vi /etc/sysconfig/iptables 如下
# Generated by iptables-save v1.4.7 on Thu Jan 29 00:55:17 2015
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [33:3044]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 8080 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
# Completed on Thu Jan 29 00:55:17 2015
新增如下:-A INPUT -p tcp -m state --state NEW -m tcp --dport 8080 -j ACCEPT
注意,一定要新增到REJECT 語句之上,我新增到下面的時候埠依然不能訪問,新增到上面就可以了。新增後執行 /etc/rc.d/init.d/iptables restart
檢視 /etc/rc.d/init.d/iptables status 如下: 1 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
2 ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
3 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
4 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:22
5 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:8080
6 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
Chain FORWARD (policy ACCEPT)
num target prot opt source destination
1 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
Chain OUTPUT (policy ACCEPT)
num target prot opt source destination
如果有第5條資訊,訪問瀏覽器試試.