今天我們要來(lái)說(shuō)說(shuō)centos系統(tǒng)防火墻隐绵,我選擇使用的
iptables
威恼,那么接下來(lái)我們就開(kāi)始安裝慌核、配置厚脉、使用
- 關(guān)閉
firewalld
防火墻[root@jjckj cblog]# systemctl status firewalld.service ● firewalld.service - firewalld - dynamic firewall daemon Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled) Active: inactive (dead) Docs: man:firewalld(1)
- 安裝
iptables
防火墻yum install -y iptables-services
- 啟動(dòng)
iptables
[root@jjckj cblog]# systemctl status iptables.service ● iptables.service - IPv4 firewall with iptables Loaded: loaded (/usr/lib/systemd/system/iptables.service; enabled; vendor preset: disabled) Active: active (exited) since 五 2019-09-06 15:40:17 CST; 47min ago Process: 105020 ExecStop=/usr/libexec/iptables/iptables.init stop (code=exited, status=0/SUCCESS) Process: 105086 ExecStart=/usr/libexec/iptables/iptables.init start (code=exited, status=0/SUCCESS) Main PID: 105086 (code=exited, status=0/SUCCESS) Tasks: 0 Memory: 0B CGroup: /system.slice/iptables.service 9月 06 15:40:16 jjckj.com systemd[1]: Starting IPv4 firewall with iptables... 9月 06 15:40:17 jjckj.com iptables.init[105086]: iptables: Applying firewall rules: [ 確定 ] 9月 06 15:40:17 jjckj.com systemd[1]: Started IPv4 firewall with iptables.
- 設(shè)置開(kāi)機(jī)自啟動(dòng)
systemctl enable iptables.service
- 配置端口開(kāi)放
# sample configuration for iptables service # you can edit this manually or use system-config-firewall # please do not ask us to add additional ports/services to this default configuration *filter :INPUT ACCEPT [0:0] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 2122 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 8080:9999 -j ACCEPT -A INPUT -s 192.168.31.1/24 -p tcp -m state --state NEW -m multiport --dport 7979,80,3389 -j ACCEPT -A INPUT -j REJECT --reject-with icmp-host-prohibited -A FORWARD -j REJECT --reject-with icmp-host-prohibited COMMIT
- 22和2212是單獨(dú)配置的外網(wǎng)可以訪問(wèn),
- 8080:9999配置的是外網(wǎng)可以訪問(wèn)8080與9999中間段的所有端口服務(wù)步藕,
- 7979,80,3389 配置的是局域網(wǎng)才能訪問(wèn)的端口服務(wù)(注意配置多個(gè)不連續(xù)的端口要加
multiport
)
- 配置好保存之后重啟
iptables
服務(wù)systemctl restart iptables.service
現(xiàn)在就可以測(cè)試你的外網(wǎng)是否可以訪問(wèn)及內(nèi)網(wǎng)訪問(wèn)情況
如果安裝了
iptables
同時(shí)也安裝了docker
在啟動(dòng)服務(wù)時(shí)報(bào)下面這種錯(cuò)
在這里插入圖片描述
可以重啟一下docker
systemctl restart docker.service
然后
docker
服務(wù)就可以運(yùn)行了(我也不知道為什么)