内网ip:任意通讯
外网ip :内部发起任意通讯,外部发起只允许80,443端口通讯
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -F
iptables -X
iptables -A INPUT -i lo -p all -j ACCEPT
iptables -A INPUT -i eth0 -p all -j ACCEPT
iptables -A OUTPUT -o lo -p all -j ACCEPT
iptables -A OUTPUT -o eth0 -p all -j ACCEPT
iptables -A INPUT -i eth1 -p tcp --dport 80-j ACCEPT
iptables -A OUTPUT -o eth1 -p tcp --sport80 -j ACCEPT
iptables -A INPUT -i eth1 -p tcp --dport 443-j ACCEPT
iptables -A OUTPUT -o eth1 -p tcp --sport 443-j ACCEPT
iptables -A INPUT -i eth1 -m state --stateESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -i eth1 -m state --stateNEW,INVALID -j DROP
iptables -A OUTPUT -o eth1 -p all -j ACCEPT
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP
/etc/init.d/iptables save
service iptables restart