vim iptables.sh
#!/bin/bash
iptables -F
iptables -X
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
#内部端口通信允许
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
#允许ping 外部
iptables -A INPUT -p icmp --icmp-type echo-reply -j ACCEPT
iptables -A OUTPUT -p icmp --icmp-type echo-request -j ACCEPT
#允许ping 内部
iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
iptables -A OUTPUT -p icmp --icmp-type echo-reply -j ACCEPT
#允许访问内部端口
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -p tcp --dport 465 -j ACCEPT
iptables -t filter -A INPUT -s 192.168.1.97 -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
iptables -t filter -A INPUT -s 192.168.1.97 -p tcp -m state --state NEW -m tcp --dport 12345 -j ACCEPT
iptables -t filter -A INPUT -s 192.168.1.97 -p tcp -m state --state NEW -m tcp --dport 12380 -j ACCEPT
iptables -A INPUT -p tcp --dport 7010 -j ACCEPT
iptables -A INPUT -p tcp --dport 7000 -j ACCEPT
iptables -A INPUT -p tcp --dport 993 -j ACCEPT
iptables -A INPUT -p tcp --dport 25 -j ACCEPT
iptables -A INPUT -p tcp --dport 8050 -j ACCEPT
iptables-save >/etc/iptables-script
加开机启动