首页 | 资讯动态 | linux基础 | 系统管理 | 网络管理 | 编程开发 | linux数据库 | 服务器技术 | linux相关 | linux认证 | 嵌入式 | 下载中心 | 专题 | linux招聘 | HR | 镜像
OKLinux中文技术站
·设为首页
·加入收藏
·联系我们
系统管理: 中文环境 系统管理 桌面应用 内核技术 | Linux基础: 基础入门 安装配置 常用命令 经验技巧 软件应用 | Linux数据库: Mysql Postgre Oracle DB2 Sybase other
网络管理: 网络安全 网络应用 Linux服务器 环境配置 黑客安全 | 编程开发: PHP CC++ Python Perl Shell 嵌入式开发 java jsp | PHP技术: PHP基础 PHP技巧 PHP应用 PHP文摘
搜索中心 Linux招聘 Linux专题 Apache | Linux相关: 硬件相关 Linux解决方案 Linux认证 企业应用 其它Unix | 相关下载: 资料下载 参考手册 开发工具 服务器类 软路由 其它
 技术搜索:
会员中心 注册会员 高级搜索  
  → 当前位置:首页>网络管理>网络安全>正文

SUSE Linux 默认的iptables防火墙配置

http://www.oklinux.cn  2008-04-22  linuxidc   会员收藏  游客收藏  【 】 
您查看的文章来源于http://www.oklinux.cn

SuSE Linux 默认的iptables防火墙配置,你看的懂吗?

Chain INPUT (policy DROP)
target   prot opt source        destination
ACCEPT   all -- anywhere       anywhere
ACCEPT   all -- anywhere       anywhere      state RELATED,ESTAB LISHED
input_ext all -- anywhere       anywhere
input_ext all -- anywhere       anywhere
LOG    all -- anywhere       anywhere      limit: avg 3/min bu rst 5 LOG level warning tcp-options ip-options prefix `SFW2-IN-ILL-TARGET '
DROP    all -- anywhere       anywhere
Chain FORWARD (policy DROP)
target   prot opt source        destination
LOG    all -- anywhere       anywhere      limit: avg 3/min bu rst 5 LOG level warning tcp-options ip-options prefix `SFW2-FWD-ILL-ROUTING '
Chain OUTPUT (policy ACCEPT)
target   prot opt source        destination
ACCEPT   all -- anywhere       anywhere
ACCEPT   all -- anywhere       anywhere      state NEW,RELATED,E STABLISHED
LOG    all -- anywhere       anywhere      limit: avg 3/min bu rst 5 LOG level warning tcp-options ip-options prefix `SFW2-OUT-ERROR '
Chain forward_ext (0 references)
target   prot opt source        destination
Chain input_ext (2 references)
target   prot opt source        destination
DROP    all -- anywhere       anywhere      PKTTYPE = broadcast
ACCEPT   icmp -- anywhere       anywhere      icmp source-quench
ACCEPT   icmp -- anywhere       anywhere      icmp echo-request
ACCEPT   icmp -- anywhere       anywhere      state RELATED,ESTAB LISHED icmp echo-reply
ACCEPT   icmp -- anywhere       anywhere      state RELATED,ESTAB LISHED icmp destination-unreachable
ACCEPT   icmp -- anywhere       anywhere      state RELATED,ESTAB LISHED icmp time-exceeded
ACCEPT   icmp -- anywhere       anywhere      state RELATED,ESTAB LISHED icmp parameter-problem
ACCEPT   icmp -- anywhere       anywhere      state RELATED,ESTAB LISHED icmp timestamp-reply
ACCEPT   icmp -- anywhere       anywhere      state RELATED,ESTAB LISHED icmp address-mask-reply
ACCEPT   icmp -- anywhere       anywhere      state RELATED,ESTAB LISHED icmp protocol-unreachable
ACCEPT   icmp -- anywhere       anywhere      state RELATED,ESTAB LISHED icmp redirect
LOG    tcp -- anywhere       anywhere      limit: avg 3/min bu rst 5 tcp dpt:5801 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-op tions prefix `SFW2-INext-ACC-TCP '
ACCEPT   tcp -- anywhere       anywhere      tcp dpt:5801
LOG    tcp -- anywhere       anywhere      limit: avg 3/min bu rst 5 tcp dpt:5901 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-op tions prefix `SFW2-INext-ACC-TCP '
ACCEPT   tcp -- anywhere       anywhere      tcp dpt:5901
LOG    tcp -- anywhere       anywhere      limit: avg 3/min bu rst 5 tcp dpt:ssh flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-opt ions prefix `SFW2-INext-ACC-TCP '
ACCEPT   tcp -- anywhere       anywhere      tcp dpt:ssh
reject_func tcp -- anywhere       anywhere      tcp dpt:ident sta te NEW
LOG    all -- anywhere       anywhere      limit: avg 3/min bu rst 5 PKTTYPE = multicast LOG level warning tcp-options ip-options prefix `SFW2- INext-DROP-DEFLT '
DROP    all -- anywhere       anywhere      PKTTYPE = multicast
LOG    tcp -- anywhere       anywhere      limit: avg 3/min bu rst 5 tcp flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options pre fix `SFW2-INext-DROP-DEFLT '
LOG    icmp -- anywhere       anywhere      limit: avg 3/min bu rst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT '
LOG    udp -- anywhere       anywhere      limit: avg 3/min bu rst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT '
LOG    all -- anywhere       anywhere      limit: avg 3/min bu rst 5 state INVALID LOG level warning tcp-options ip-options prefix `SFW2-INext- DROP-DEFLT-INV '
DROP    all -- anywhere       anywhere
Chain reject_func (1 references)
target   prot opt source        destination
REJECT   tcp -- anywhere       anywhere      reject-with tcp-res et
REJECT   udp -- anywhere       anywhere      reject-with icmp-po rt-unreachable
REJECT   all -- anywhere       anywhere      reject-with icmp-pr oto-unreachable
hugang:~ # iptables -L
Chain INPUT (policy DROP)
target   prot opt source        destination
ACCEPT   all -- anywhere       anywhere
ACCEPT   all -- anywhere       anywhere      state RELATED,ESTABLISHED

共2页: 上一页 1 [2] 下一页

上一篇:分享一个Linux防火墙脚本   下一篇:利用HP磁带库轻松保护Sybase数据库安全

收藏于收藏夹】 【评论】 【推荐】 【打印】 【关闭
相关文档
·分享一个Linux防火墙脚本
·Linux系统防火墙进程查看的方法简介
·SUSE Linux推出支持VPN的防火墙软件
·CentOS Linux关闭防火墙
·Linux系统Iptables防火墙使用手册
·SUSE 10.2防火墙配置实验
·Ubuntu下设置shorewall防火墙
·SUSE Linux防火墙的设置笔记
·Linux安全学习 阻止SSH口令尝试工具软件
·Ubuntu8.04初学之系统安全篇
·Linux环境下四大IDS入侵检测工具的认识
·Ubuntu初始化iptables的实现
·我的SUSE Linux防火墙配置笔记
·不安全的reboot启动
·SUSE防火墙手动永久关闭方法
·Ubuntu里安装配置防火墙
发表评论
密码: 匿名评论
评论内容:

(不超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规)
 
  最新文档
·FreeBSD ZIL机制不安全文件权限漏洞
·Novell eDirectory Post Auth头远程溢
·Linux Kernel Ext4子系统ioctl本地权限
·Linux Kernel ext4_fill_flex_info函数
·Linux Kernel ext4_decode_error函数空
·奥巴马任命网络安全专家担任“网络沙皇
·FreePBX多个跨站脚本和HTML注入漏洞
·DeluxeBB多个远程安全漏洞
·系统安全:Windows与Linux平台
·PostgreSQL爆漏洞 Oracle家Sun忙修补
·分析称谷歌Chrome OS 将成黑客主要攻击
·phpGroupWare多个输入验证漏洞
  阅读排行
·Ubuntu中UFW防火墙的安装及使用
·Ubuntu里安装配置防火墙
·Linux下Sniffer工具Tcpdump的安装和使
·Ubuntu下轻松安装小红伞杀毒软件
·Ubuntu防火墙 UFW 设置简介
·Linux下破解路由器WEP加密
·Linux系统中的Passwd文件详细解析
·CentOS Linux关闭防火墙
·Linux下安装配置NTOP监视网络使用情况[
·Linux下配置ssh无密码登录
·Linux安全之网上惊现傻瓜型病毒制作工
·配置Linux 内核并利用iptables 做端口
·Linux 安全模块(LSM)简介
·我的SUSE Linux防火墙配置笔记
·Ubuntu 9.04 下无线破解
网摘收藏: