1. vim /etc/sysconfig/iptables # Generated by iptables-save v1.2.11 on Wed Oct 14 15:41:59 2009 # Firewall configuration written by system-config-securitylevel # Manual customization of this file is not recommended. *filter :INPUT ACCEPT [0:0] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] :RH-Firewall-1-INPUT - [0:0] -A INPUT -j RH-Firewall-1-INPUT -A FORWARD -j RH-Firewall-1-INPUT -A RH-Firewall-1-INPUT -i lo -j ACCEPT -A RH-Firewall-1-INPUT -i eth1 -p icmp --icmp-type any -j ACCEPT -A RH-Firewall-1-INPUT -p 50 -j ACCEPT -A RH-Firewall-1-INPUT -p 51 -j ACCEPT -A RH-Firewall-1-INPUT -p udp --dport 5353 -d 224.0.0.251 -j ACCEPT -A RH-Firewall-1-INPUT -i eth1 -p udp --dport 123 -j ACCEPT # Commented by shingo 08-12-02 For forbidden IPP Service #-A RH-Firewall-1-INPUT -p udp -m udp --dport 631 -j ACCEPT -A RH-Firewall-1-INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT # Added by luiss 09-12-11 For accept ssh from a safe IPAddress -A RH-Firewall-1-INPUT -i eth0 -m state --state NEW -m tcp -p tcp -s 123.123.123.123 --dport 22 -j ACCEPT # Added by luiss 09-12-11 For accept oracle from a safe IPAddress -A RH-Firewall-1-INPUT -i eth0 -m state --state NEW -m tcp -p tcp -s 123.123.123.123 --dport 1521 -j ACCEPT # Added by luiss 08-12-02 For httpd -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT # Added by luiss 09-02-11 For PING from a safe IPAddress -A RH-Firewall-1-INPUT -s 123.123.123.123 -p icmp --icmp-type 8 -j ACCEPT # Added by luiss 08-12-02 For forbidden FTP #-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 21 -j ACCEPT -A RH-Firewall-1-INPUT -i eth0 -j REJECT --reject-with icmp-host-prohibited COMMIT 2. service iptables restart