Skip to content

Instantly share code, notes, and snippets.

@nakamura-akifumi
Last active August 29, 2015 14:14
Show Gist options
  • Save nakamura-akifumi/c0a0e749e73483fe7574 to your computer and use it in GitHub Desktop.
Save nakamura-akifumi/c0a0e749e73483fe7574 to your computer and use it in GitHub Desktop.
iptablesの設定
iptables -A INPUT -p tcp --tcp-flags ALL NONE -j DROP
iptables -A INPUT -p tcp ! --syn -m state --state NEW -j DROP
iptables -A INPUT -p tcp --tcp-flags ALL ALL -j DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -p icmp -j ACCEPT
iptables -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
# iptables -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
iptables -A INPUT -p tcp -m tcp --dport 10037 -j ACCEPT
iptables -A INPUT -p tcp -m tcp --dport 10083 -j ACCEPT
iptables -I INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
# service iptables save
/sbin/iptables-save > /etc/sysconfig/iptables
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment