iptables安装使用 (为Redis开放特定IP)

本文详细介绍如何在CentOS 7系统中,通过停用firewall并安装及配置iptables,实现为Redis服务开放特定IP和端口的过程。步骤包括关闭firewall、安装iptables、编辑iptables配置文件以添加IP白名单和开放特定端口,最后启动并设置iptables开机启动。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

iptables安装使用 (为Redis开放特定IP)

停用firewall

由于centos7默认是使用firewall作为防火墙,先关闭firewall。

#停止firewall 
systemctl stop firewalld.service
#禁止firewall开机启动 
systemctl disable firewalld.service
#查看firewall status
# systemctl status firewalld.service
● firewalld.service - firewalld - dynamic firewall daemon
   Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled)
   Active: inactive (dead)
     Docs: man:firewalld(1)

iptables安装

查看iptables-services

#yum list iptables-services
Loaded plugins: fastestmirror
Determining fastest mirrors
Available Packages
iptables-services.x86_64                                                                              1.4.21-24.1.el7_5                                                                              updates

安装iptables

yum install iptables-services -y

iptables配置

编辑配置

vim /etc/sysconfig/iptables

默认配置如下:

# sample configuration for iptables service
# you can edit this manually or use system-config-firewall
# please do not ask us to add additional ports/services to this default configuration
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT

修改配置如下:

*filter
#拒绝全部INPUT
:INPUT DROP [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
#INPUT增加IP白名单(对该IP所有端口开放)
-A INPUT -s 18.28.238.59 -j ACCEPT
-A INPUT -s 18.88.178.14 -j ACCEPT
#开放80端口
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT

#开放特定IP的特定端口端口
-A INPUT -s 18.88.178.14 -p tcp -m tcp --dport 6379 -j ACCEPT
#ping使用的端口
-A INPUT -p icmp -j ACCEPT
#开放localhost
-A INPUT -i lo -j ACCEPT
#开放RELATED,ESTABLISHED状态
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
#拒绝其他端口的操作
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT

启动iptables

service iptables start

关闭与状态

service iptables  start     #启动服务
service iptables  stop     #停止服务
service iptables  restart  #重启服务

查看iptables

# systemctl status iptables.service
● iptables.service - IPv4 firewall with iptables
   Loaded: loaded (/usr/lib/systemd/system/iptables.service; disabled; vendor preset: disabled)
   Active: active (exited) since Tue 2018-11-06 11:26:57 CST; 4s ago
  Process: 25961 ExecStart=/usr/libexec/iptables/iptables.init start (code=exited, status=0/SUCCESS)
 Main PID: 25961 (code=exited, status=0/SUCCESS)

Nov 06 11:26:57 haocailai-001 systemd[1]: Starting IPv4 firewall with iptables...
Nov 06 11:26:57 haocailai-001 iptables.init[25961]: iptables: Applying firewall rules: [  OK  ]
Nov 06 11:26:57 haocailai-001 systemd[1]: Started IPv4 firewall with iptables.

设置开机启动

# systemctl enable iptables.service
Created symlink from /etc/systemd/system/basic.target.wants/iptables.service to /usr/lib/systemd/system/iptables.service.
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值