温馨提示×

如何替换debian防火墙

小樊
42
2026-09-23 05:57:17
栏目: 智能运维

在 Debian 系统中,“防火墙”通常指 iptables / nftables 以及用户层管理工具(如 ufw、firewalld)。所谓“替换防火墙”,一般有以下几种常见场景:


一、用 ufw 替换 iptables 手动规则(推荐新手)

1. 安装 ufw

sudo apt update
sudo apt install ufw

2. 禁用原有 iptables 规则(如有)

sudo iptables -F
sudo iptables -X

3. 配置并启用 ufw

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow ssh
sudo ufw enable

4. 检查状态

sudo ufw status

✅ 此时 ufw 已“替换”你原来的 iptables 管理方式。


二、用 nftables 替换 iptables(Debian 10+ 推荐)

Debian 默认已逐步转向 nftables。

1. 安装 nftables

sudo apt install nftables

2. 禁用 iptables 服务

sudo systemctl stop iptables
sudo systemctl disable iptables

(如未安装 iptables 服务可忽略)

3. 启用 nftables

sudo systemctl enable nftables
sudo systemctl start nftables

4. 编写规则示例

sudo nft add table inet filter
sudo nft add chain inet filter input { type filter hook input priority 0 \; }
sudo nft add rule inet filter input ct state established,related accept
sudo nft add rule inet filter input tcp dport 22 accept
sudo nft add rule inet filter input drop

三、用 firewalld 替换 ufw / iptables

1. 安装 firewalld

sudo apt install firewalld

2. 禁用 ufw

sudo ufw disable

3. 启动 firewalld

sudo systemctl enable firewalld
sudo systemctl start firewalld

4. 常用命令

sudo firewall-cmd --add-service=ssh --permanent
sudo firewall-cmd --reload

四、彻底“替换”原防火墙的核心思路

  1. 停止旧防火墙
    • ufw disable
    • systemctl stop iptables
  2. 启用新防火墙
    • nftables / firewalld / ufw
  3. 确保开机不冲突
    • 只保留一个防火墙服务

五、推荐组合(按场景)

场景 推荐
个人 / VPS ufw
服务器 / 新系统 nftables
企业 / 多区域 firewalld

如果你能说明:

  • 当前用的是 iptables / ufw / firewalld
  • 想换成 哪一个
  • Debian 版本

我可以给你精确到命令的替换方案。

0 踩