在 Linux 中,防火墙规则取决于你使用的防火墙工具。常见有以下几种:
iptables(传统方式)iptables -L -n -v
允许 SSH(22端口)
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
允许某个 IP 访问所有端口
iptables -A INPUT -s 192.168.1.100 -j ACCEPT
禁止某个 IP
iptables -A INPUT -s 10.0.0.5 -j DROP
允许已建立连接
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
# CentOS / RHEL
service iptables save
# Ubuntu(需安装)
iptables-save > /etc/iptables.rules
firewalld(CentOS 7+ / RHEL / Fedora)systemctl status firewalld
firewall-cmd --zone=public --add-port=8080/tcp --permanent
firewall-cmd --reload
firewall-cmd --add-service=http --permanent
firewall-cmd --reload
firewall-cmd --permanent --add-source=192.168.1.0/24
firewall-cmd --reload
ufw(Ubuntu 常用)ufw enable
ufw allow 22/tcp
ufw allow 80
ufw deny 3306
ufw allow from 192.168.1.100
ufw status
| 系统 | 推荐 |
|---|---|
| CentOS 7+ | firewalld |
| Ubuntu | ufw |
| 老系统 / 精细控制 | iptables |
如果你能告诉我:
我可以给你精确命令。