iptables 四表五链
iptables(nat,filter,mangle,raw)(INPUT,FORWARD,OUTPUT,PREROUTING,POSTROUTING)
filter: INPUT, OUTPUT, FORWARD
nat: PREROUTING, POSTROUTING, OUTPUT
mangle: PREROUTING, INPUT, FORWARD, OUTPUT, POSTROUTING
规则管理类:
-A 添加规则
-I 插入规则
-D 删除规则
-R Replace rule
链接管理类:
-F, flush, 清空链
-N, new, 新建链
-X, delete, 删除自定义的空链
-E, rename
默认策略:
-P, policy Change policy on chain to target
清空计数器:
-Z, zero
每条规则(包括默认策略)都有两个计数器:
被此规则匹配到的所有数据包的个数;
被此规则匹配到的所有数据包的大小之和;
查看类:
-L, List the rules in a chain or all chains
-S, Print the rules in a chain or all chains
-n, numeric
-v, verbose
-vv
-vvv
-x, exactly
--line-numbers
基本匹配:
-s SOURCE:IP, NETWORK
-d DESTINATION:IP, NETWORK
-p {tcp|udp|icmp}
-i INTERFACE
-o INTERFACE
扩