My understand of "iptables"

来源:互联网 发布:知彼网络 编辑:程序博客网 时间:2024/06/04 19:23
I learn the iptables when I want to set the firewall in ubuntu.
First :
    The iptables is one tool which is used to set the "netfilter" by user or system.

    like the image below:
    
Second:
    the rules constitute chains, and chains constitute tables. The iptables is used to set/maintain/inspect tables.
Each chain is a list of rules which can match a set of packets.  Each rule specifies what to do with a packet that matches. 

Third:parameters
    -A, --append chain rule-specification
              Append  one  or more rules to the end of the selected chain.
#******************#
    -j, --jump target
              This specifies the target of the rule; i.e., what to do if the packet matches it.

#******************#
    -p   (small)--protocol protocol
              The protocol of the rule or of the packet to check.
    -P   (big)--policy chain target
              Set  the  policy  for  the chain to the given target.  See the section TARGETS for the legal targets. 
#******************#
    -t, --table table
              This  option  specifies  the  packet matching table which the command should operate on.
                The tables are as follows:filter/ nat/ mangle/ raw/ security
#******************#
    -x    (small)--exact
              Expand  numbers. 
    -X    (big)--delete-chain [chain]
              Delete  the  optional  user-defined chain specified.
#******************#
    -m    --match match
              Specifies  a  match  to  use,  that is, an extension module that
              tests for a specific property.
#******************#
    --sport    source port
    --dport    destination port
        For example:
            /sbin/iptables -A INPUT -p tcp --dport 80 -j ACCEPT 
                That is to say allow external visit local by local 80 port
            /sbin/iptables -A INPUT -p tcp --sport 80 -j ACCEPT 
                That is to say allow external visit local from external 80 port




    
<script>window._bd_share_config={"common":{"bdSnsKey":{},"bdText":"","bdMini":"2","bdMiniList":false,"bdPic":"","bdStyle":"0","bdSize":"16"},"share":{}};with(document)0[(getElementsByTagName('head')[0]||body).appendChild(createElement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new Date()/36e5)];</script>
阅读(11) | 评论(0) | 转发(0) |
0

上一篇:build makefile for my coding!!

下一篇:shell 编程语法总结(I/O 逻辑控制结构)

相关热门文章
  • 欢迎zmyxi在ChinaUnix博客安家...
  • mysqldump备份所有数据库,恢...
  • 欢迎smy02在ChinaUnix博客安家...
  • 欢迎nonmygod在ChinaUnix博客...
  • 欢迎kamycc在ChinaUnix博客安...
  • linux 常见服务端口
  • xmanager 2.0 for linux配置
  • 【ROOTFS搭建】busybox的httpd...
  • openwrt中luci学习笔记
  • 什么是shell
  • linux dhcp peizhi roc
  • 关于Unix文件的软链接
  • 求教这个命令什么意思,我是新...
  • sed -e "/grep/d" 是什么意思...
  • 谁能够帮我解决LINUX 2.6 10...
给主人留下些什么吧!~~
原创粉丝点击