CentOS7安装iptables防火墙
来源:互联网 发布:安卓手机编程软件 编辑:程序博客网 时间:2024/06/04 19:33
由于centos7默认是使用firewall作为防火墙,而不是iptables,下面介绍如何将系统的防火墙设置为iptables。
1.关闭和禁用firewalld
1)查看firewalld状态:[root@localhost sysconfig]# systemctl status firewalld.service ● firewalld.service - firewalld - dynamic firewall daemon Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled) Active: active (running) since 五 2017-12-22 03:39:35 CST; 2s ago Docs: man:firewalld(1) Main PID: 3861 (firewalld) CGroup: /system.slice/firewalld.service └─3861 /usr/bin/python -Es /usr/sbin/firewalld --nofork --nopid上面信息Active: active (running)表示firewalld没有关闭2)关闭firewalld[root@localhost sysconfig]# systemctl stop firewalld.service ● firewalld.service - firewalld - dynamic firewall daemon Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled; vendor preset: enabled) Active: inactive (dead) since 五 2017-12-22 03:26:08 CST; 8min ago Docs: man:firewalld(1) Main PID: 829 (code=exited, status=0/SUCCESS) 上面信息Active: inactive (dead)表示firewalld没有关闭 3)禁止firewall开机启动 [root@localhost sysconfig]# systemctl disable firewalld.service
2.安装防火墙iptables和iptables-services
1)查看是否安装iptables[root@localhost sysconfig]# systemctl status iptables.service2)若没有安装,进行安装[root@localhost ~]# yum install -y iptables[root@localhost ~]# yum install iptables-services3)配置允许访问的端口[root@localhost ~]# vim /etc/sysconfig/iptables ..............-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT-A INPUT -p tcp -m state --state NEW -m tcp --dport 8080 -j ACCEPT-A INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT-A INPUT -p tcp -m state --state NEW -m tcp --dport 1521 -j ACCEPT..............................:wq保存4)重启防火墙使配置文件生效 [root@localhost ~]# systemctl restart iptables.service5)设置开机自启动iptables防火墙[root@localhost ~]# systemctl enable iptables.service6)查看iptables状态[root@localhost ~]# systemctl status iptables.service● iptables.service - IPv4 firewall with iptables Loaded: loaded (/usr/lib/systemd/system/iptables.service; enabled; vendor preset: disabled) Active: active (exited) since 五 2017-12-22 03:53:05 CST; 1s ago Process: 4460 ExecStop=/usr/libexec/iptables/iptables.init stop (code=exited, status=0/SUCCESS) Process: 4534 ExecStart=/usr/libexec/iptables/iptables.init start (code=exited, status=0/SUCCESS) Main PID: 4534 (code=exited, status=0/SUCCESS)7)启动iptables防火墙[root@localhost ~]# systemctl start iptables.service8)关闭iptables防火墙[root@localhost ~]# systemctl stop iptables.service
阅读全文
0 0
- centos7 安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- CentOS7安装iptables防火墙
- Centos7 安装iptables防火墙
- CentOS7安装iptables防火墙
- 九、CentOS7 安装iptables防火墙
- [CentOs7]iptables防火墙安装与设置
- Linux——CentOS7安装iptables防火墙
- oauth2
- Attention
- Maven的环境隔离
- c# post-get
- Leetcode203. Remove Linked List Elements
- CentOS7安装iptables防火墙
- 494. Target Sum
- user account control用户帐户控制
- clipboard.js 复制到剪贴板
- 跨域的问题
- Listview下啦刷新
- angularjs作用域及其生命周期
- 算法实验1《分治算法实验》
- JAVA-Swing图形化界面之事件监听1