一、清除原rules
iptables-F
iptables-X
二、添加新的INPUT/OUTPUTrules
注:开放http,ftp,samba,ssh的端口
(1)、INPUTrules
iptables-AINPUT-ptcp--dport80-mstate--stateNEW,ESTABLISHED,RELATED-jACCEPT
iptables-AINPUT-ptcp--dport21-mstate--stateNEW,ESTABLISHED,RELATED-jACCEPT
iptables-AINPUT-ptcp--dport20-mstate--stateNEW,ESTABLISHED,RELATED-jACCEPT
iptables-AINPUT-ptcp--dport445-mstate--stateNEW,ESTABLISHED,RELATED-jACCEPT
iptables-AINPUT-ptcp--dport22-mstate--stateNEW,ESTABLISHED,RELATED-jACCEPT
(2)、OUTPUTrules
iptables-AOUTPUT-ptcp--sport80-mstate--stateNEW,ESTABLISHED,RELATED-jACCEPT
iptables-AOUTPUT-ptcp--sport21-mstate--stateNEW,ESTABLISHED,RELATED-jACCEPT
iptables-AOUTPUT-ptcp--sport20-mstate--stateNEW,ESTABLISHED,RELATED-jACCEPT
iptables-AOUTPUT-ptcp--sport445-mstate--stateNEW,ESTABLISHED,RELATED-jACCEPT
iptables-AOUTPUT-pt