温馨提示×

centos iptables怎样兼容

小樊
32
2026-10-05 15:51:15
栏目: 智能运维

你的问题有点简略,我分几种常见场景给你说明 CentOS 下 iptables 如何“兼容”,你可以对号入座:


一、CentOS 7/8 中 iptables 与 firewalld 兼容

现象

CentOS 7 开始默认使用 firewalld,但你习惯用 iptables 命令。

解决方式(二选一)

✅ 方式 1:停用 firewalld,使用 iptables(最常用)

systemctl stop firewalld
systemctl disable firewalld

yum install -y iptables-services
systemctl enable iptables
systemctl start iptables

之后就可以正常使用:

iptables -L -n
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
service iptables save

✅ 方式 2:firewalld + iptables 共存(不推荐新手)

firewalld 本质也是调用 iptables,但规则由它管理,不建议手动改 iptables。


二、CentOS 8 使用 nftables,iptables 如何兼容

CentOS 8 默认是 nftables,但提供了 iptables 兼容层

yum install -y iptables iptables-services

查看是否使用 nft 后端:

iptables -V
# 显示 xtables-multi 或 nf_tables

如果你想完全用传统 iptables:

systemctl disable firewalld
systemctl stop firewalld

systemctl enable iptables
systemctl start iptables

三、Docker 与 iptables 兼容问题

现象

Docker 自动改 iptables,你手动加的规则失效

解决

  1. 不要把规则写在 DOCKER 链
  2. 使用 DOCKER-USER 链(推荐):
iptables -I DOCKER-USER -p tcp --dport 3306 -j DROP

四、规则重启失效(兼容性重点)

CentOS 7/8 必须保存:

service iptables save
# 或
iptables-save > /etc/sysconfig/iptables

五、快速判断你现在的状态

systemctl status firewalld
iptables -L -n

如果你能补充一句:

  • CentOS 几?
  • 是“命令不存在”“规则不生效”还是“和 Docker / firewalld 冲突”?

我可以给你精确到命令级别的方案。

0 踩