资源描述:
《suse默认的iptables》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、suse默认的iptables~教育资源库ChainINPUT(policyDROP)target protoptsource destinationACCEPT all -- anyit:avg3/minburst5LOGlevelit:avg3/minburst5LOGlevelit:avg3/minburst5LOGlevelp-- anypsource-quenchACCEPT icmp-- anypecho-requestACCEPT icmp-- anypecho-
2、replyACCEPT icmp-- anypdestination-unreachableACCEPT icmp-- anyptime-exceededACCEPT icmp-- anypparameter-problemACCEPT icmp-- anyptimestamp-replyACCEPT icmp-- anypaddress-mask-replyACCEPT icmp-- anypprotocol-unreachableACCEPT icmp-- anypredirec
3、tLOG tcp -- anyit:avg3/minburst5tcpdpt:5801flags:FIN,SYN,RST,ACK/SYNLOGlevelit:avg3/minburst5tcpdpt:5901flags:FIN,SYN,RST,ACK/SYNLOGlevelit:avg3/minburst5tcpdpt:sshflags:FIN,SYN,RST,ACK/SYNLOGlevelwarningtcp-optionsip-optionsprefix`SFW2-INext-ACC-T
4、CP'ACCEPT tcp -- anywhere anywhere123下一页友情提醒:,特别!tcpdpt:sshreject_func tcp -- anyit:avg3/minburst5PKTTYPE=multicastLOGlevelulticastLOG tcp -- anyit:avg3/minburst5tcpflags:FIN,SYN,RST,ACK/SYNLOGlevelp-- anyit:avg3/minburst5LOGlevelit:avg3/
5、minburst5LOGlevelit:avg3/minburst5stateINVALIDLOGlevelp-port-unreachableREJECT all -- anyp-proto-unreachablehugang:~#iptables-LChainINPUT(policyDROP)target protoptsource destinationACCEPT all -- anyit:avg3/minburst5LOGlevelit:avg3/minburst5LO
6、Glevelit:avg3/minburst5LOGlevelp-- anypsource-quenchACCEPT icmp-- anypecho-requestACCEPT icmp-- anypecho-replyACCEPT icmp-- anywhere anywhere stateRELATED,E上一页123下一页友情提醒:,特别!STABLISHEDicmpdestination-unreachableACCEPT icmp-- anyptime-exc
7、eededACCEPT icmp-- anypparameter-problemACCEPT icmp-- anyptimestamp-replyACCEPT icmp-- anypaddress-mask-replyACCEPT icmp-- anypprotocol-unreachableACCEPT icmp-- anypredirectLOG tcp -- anyit:avg3/minburst5tcpdpt:5801flags:FIN,SYN,RST,ACK/SYNLOG
8、levelit:avg3/minburst5tcpdpt:5901flags:FIN,SYN,RST,ACK/SYNLOGlevelit:avg3/minburst5tcpdpt:sshflags:FIN,SYN,RST,ACK/SYNLOGlevelit:avg3/minburst5PKTTYPE=multicastLOGlevelulticastLOG tcp -- anyit:avg3/minburst5tcpflags:FIN,SYN,RST,ACK/SYNLOGle