查看iptables
sudo iptables -L -n
保存策略
sudo iptables-save > /etc/iptables.rules
新增条目
sudo iptables -A INPUT -s 125.46.41.219 -j DROP
# Generated by iptables-save v1.6.1 on Sun Jul 1 16:53:12 2018
*filter
:INPUT ACCEPT [313:248784]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [341:38140]
-A INPUT -s 222.186.61.240/32 -j DROP
-A INPUT -s 121.51.23.142/32 -j DROP
-A INPUT -s 199.127.0.0/16 -j DROP
-A INPUT -s 34.250.0.0/16 -j DROP
-A INPUT -s 74.125.0.0/16 -j DROP
-A INPUT -s 64.233.0.0/16 -j DROP
-A INPUT -s 172.217.0.0/16 -j DROP
-A INPUT -p tcp -m tcp --dport 445 -j DROP
-A INPUT -s 125.46.41.219/32 -j DROP
-A INPUT -s 117.25.129.73/32 -j DROP
-A OUTPUT -p tcp -m tcp --dport 445 -j DROP
-A OUTPUT -d 199.127.0.0/16 -j DROP
-A OUTPUT -d 172.217.0.0/16 -j DROP
-A OUTPUT -d 64.233.0.0/16 -j DROP
-A OUTPUT -d 34.250.0.0/16 -j DROP
-A OUTPUT -d 74.125.0.0/16 -j DROP
COMMIT
# Completed on Sun Jul 1 16:53:12 2018