Linux iptables setup port 80/9080/9443
来源:互联网 发布:淘宝签署图片空间协议 编辑:程序博客网 时间:2024/06/04 18:22
1. Problem - Found on website, using the following command to add a rule
iptables -A INPUT -m state --state NEW -m tcp -p tcp --dport 9080 -j ACCEPT
iptables -A INPUT -m state --state NEW -m tcp -p tcp --dport 9443 -j ACCEPT
The setting didn't work, and the 9080/9443 not accessible.
Because the rules were added after
-A INPUT -j DROP
2. Solution, using the following
iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport 9080 -j ACCEPT
iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport 9443 -j ACCEPT
service iptables save
The rules were added to very beginning of the /etc/sysconfig/iptables. Then it worked.
3. Update the /etc/sysconfig/iptables-config, or the rules lost after issuing service iptables restart to make it take effect.
# Save current firewall rules on stop.
# Value: yes|no, default: no
# Saves all firewall rules to /etc/sysconfig/iptables if firewall gets stopped
# (e.g. on system shutdown).
IPTABLES_SAVE_ON_STOP="yes"
# Save current firewall rules on restart.
# Value: yes|no, default: no
# Saves all firewall rules to /etc/sysconfig/iptables if firewall gets
# restarted.
IPTABLES_SAVE_ON_RESTART="yes"
4. Sometimes 80 cannot added to iptables file (try many times)
失败了很多次,80端口总是设置不成功,被覆盖掉。估计是参数不对。
后来用命令: # system-config-firewall 在GUI里配置,会自动修改/etc/sysconfig/iptables文件
或者: # system-config-firewall-tui
参考: http://www.cyberciti.biz/faq/linux-web-server-firewall-tutorial/
- Linux iptables setup port 80/9080/9443
- ARM11 Peripheral port setup
- How to Setup a Linux Firewall with PPPoE/NAT/iptables
- iptables remote port forwarding
- iptables - port spoof / local port forward
- Linux Iptables Block Outgoing Access To Selected or Specific IP Address / Port
- Linux iptables开启80端口
- linux iptables
- Linux [ iptables ]
- linux iptables
- Linux Iptables
- linux iptables
- linux iptables
- linux iptables
- linux iptables
- linux iptables
- Linux iptables
- linux iptables
- android四种启动模式
- 学习android编程之路(7)- gallery+baseAdapter+ImageSwitcher数据从assets中获取
- hdu3038,3047(带权并查集)
- Shell脚本编程-脚本格式
- Hnoi2010弹飞绵羊题解LCT
- Linux iptables setup port 80/9080/9443
- 155Min Stack
- 1.excle学习之一:工作环境设置
- C/C++获取当前系统时间
- jquery each报 Uncaught TypeError: Cannot use 'in' operator to search for错误
- 带权最短路 Dijkstra, SPFA, Bellman-Ford, ASP, Floyd-Warshall 算法分析
- Android下拉刷新组件
- 懒得笔记3 spring bean 的生存范围 生命周期
- Eddy's research I