温馨提示×

debian防火墙怎么封某个端口

小樊
53
2026-09-29 11:38:39
栏目: 智能运维

在 Debian 里“防火墙”通常分几种情况,下面按最常见、最推荐到底层给你说明。


一、使用 UFW(最简单,推荐)

Debian 默认不一定装,但 UFW 是管理 iptables 的最简单方式。

1. 安装 UFW

sudo apt update
sudo apt install ufw

2. 禁止某个端口(例如 8080)

sudo ufw deny 8080

或指定协议:

sudo ufw deny 8080/tcp

3. 允许其他端口(可选)

sudo ufw allow 22/tcp

4. 启用防火墙

sudo ufw enable

5. 查看状态

sudo ufw status

二、使用 iptables(底层方式)

封掉 8080 端口(TCP)

sudo iptables -A INPUT -p tcp --dport 8080 -j DROP

封 UDP

sudo iptables -A INPUT -p udp --dport 8080 -j DROP

查看规则

sudo iptables -L -n

⚠️ 注意:
iptables 规则重启后会丢失,需要安装:

sudo apt install iptables-persistent
sudo netfilter-persistent save

三、使用 nftables(Debian 新版本推荐)

1. 编辑规则

sudo nft add table inet filter
sudo nft add chain inet filter input { type filter hook input priority 0 \; }
sudo nft add rule inet filter input tcp dport 8080 drop

2. 保存

sudo nft list ruleset > /etc/nftables.conf

四、只限制某个 IP 访问端口(示例)

UFW:

sudo ufw deny from 192.168.1.100 to any port 8080

iptables:

sudo iptables -A INPUT -p tcp -s 192.168.1.100 --dport 8080 -j DROP

总结建议

  • 新手 / 服务器:用 UFW
  • 高级用户:用 nftables
  • 临时测试:用 iptables

如果你告诉我:

  • Debian 版本
  • 要封的端口
  • 是否只针对某个 IP

我可以给你精确命令。

0 踩