赞
踩
- *filter
- :FORWARD ACCEPT [0:0]
- :INPUT ACCEPT [0:0]
- :RH-Firewall-1-INPUT - [0:0]
- :OUTPUT ACCEPT [0:0]
- -A FORWARD -j RH-Firewall-1-INPUT
- -A INPUT -j RH-Firewall-1-INPUT
- -A RH-Firewall-1-INPUT -i lo -j ACCEPT
- -A RH-Firewall-1-INPUT -p icmp -m icmp --icmp-type any -j ACCEPT
- -A RH-Firewall-1-INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A RH-Firewall-1-INPUT -p tcp -m state -m tcp --dport 80 --state NEW -j ACCEPT
- -A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited COMMIT
|
- # Don't do connection tracking on port 80 and 8000 because sometimes it
- # results in dropped connections due to ICMP_HOST_UNREACHABLE messages
- #-A RH-Firewall-1-INPUT -p tcp -m state -m tcp --dport 80 --state NEW -j ACCEPT
- #-A RH-Firewall-1-INPUT -p tcp -m state -m tcp --dport 8000 --state NEW -j ACCEPT
- -A RH-Firewall-1-INPUT -p tcp --dport 80 -j ACCEPT
- -A RH-Firewall-1-INPUT -p tcp --dport 8000 -j ACCEPT
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。