×÷ΪLinuxϵͳÖÐÖÁ¹ØÖØÒªµÄ·À»ðǽ×é¼þ£¬iptablesÒÔÆäÇ¿´óµÄ¹¦ÄܺÍÁé»îÐÔ£¬³ÉΪ±£»¤ÏµÍ³ÃâÊÜÍøÂç¹¥»÷µÄÖØÒª¹¤¾ß
±¾ÎĽ«ÉîÈë̽ÌÖiptablesµÄ¹¤×÷ÔÀí¡¢»ù±¾Óï·¨¡¢ÅäÖ÷½·¨ÒÔ¼°ÆäÔÚÍøÂ簲ȫÖеÄʵ¼ÊÓ¦Óã¬Ö¼ÔÚ°ïÖú¶ÁÕßÈ«ÃæÀí½â²¢ÓÐЧÀûÓÃÕâһǿ´óµÄ°²È«¹¤¾ß
iptables¸ÅÊö iptablesÊÇLinuxϵͳÖÐÓÃÓÚÅäÖÃÄÚºËIP°ü¹ýÂ˹æÔòµÄÈí¼þ
Ëü»ùÓÚÄÚºËÖеÄnetfilter¿ò¼Ü¹¤×÷£¬¸Ã¿ò¼ÜÔÚLinux 2.4.x°æ±¾ºóÒýÈ룬ÊÇÐÂÒ»´úLinux·À»ðǽ»úÖÆµÄºËÐÄ×é¼þ
iptablesͨ¹ýÔÊÐí¡¢¾Ü¾ø¡¢×ª·¢¡¢Öض¨ÏòµÈ²Ù×÷£¬¶Ô½ø³ö·þÎñÆ÷µÄÍøÂçÁ÷Á¿½øÐо«Ï¸¿ØÖÆ£¬´Ó¶øÓÐЧÔöǿϵͳµÄ°²È«ÐÔ
iptables²ÉÓñíºÍÁ´µÄ·Ö²ã½á¹¹À´×éÖ¯ºÍ¹ÜÀí·À»ðǽ¹æÔò
±íÊǹæÔòµÄÈÝÆ÷£¬¸ù¾Ý¹æÔò¼¯µÄ²»Í¬ÓÃ;£¬iptablesÄÚÖÃÁËËĸö±í£ºfilter¡¢nat¡¢mangleºÍraw
ÿ¸ö±íÄÚÓÖ°üº¬²»Í¬µÄ¹æÔòÁ´£¬ÕâЩÁ´¸ù¾Ý´¦ÀíÊý¾Ý°üµÄ²»Í¬Ê±»ú½øÐл®·Ö£¬°üÀ¨INPUT¡¢OUTPUT¡¢FORWARD¡¢PREROUTINGºÍPOSTROUTINGÎåÖÖ
- filter±í£ºÓÃÓÚ¿ØÖÆÊý¾Ý°üÊÇ·ñ±»½ÓÊÜ¡¢×ª·¢»ò¶ªÆú£¬°üº¬INPUT¡¢OUTPUTºÍFORWARDÁ´
- nat±í£ºÓÃÓÚÍøÂçµØÖ·×ª»»£¬¿ÉÒÔÐÞ¸ÄÊý¾Ý°üµÄÔ´¡¢Ä¿±êIPµØÖ·ºÍ¶Ë¿ÚºÅ£¬°üº¬OUTPUT¡¢PREROUTINGºÍPOSTROUTINGÁ´
- mangle±í£ºÓÃÓÚÐÞ¸ÄÊý¾Ý°üµÄÄÚÈÝ£¬Èç·þÎñÀàÐÍ¡¢ÉúÃüÖÜÆÚµÈ£¬°üº¬INPUT¡¢OUTPUT¡¢FORWARD¡¢PREROUTINGºÍPOSTROUTINGÁ´
- raw±í£ºÓÃÓÚ¾ö¶¨Êý¾Ý°üÊÇ·ñ½øÐÐ״̬¸ú×Ù£¬°üº¬OUTPUTºÍPREROUTINGÁ´
iptablesµÄ»ù±¾Óï·¨ÓëÅäÖ÷½·¨ iptablesµÄÃüÁî¸ñʽÈçÏ£º`iptables¡¾-t table¡¿command¡¾match¡¿¡¾target/jump¡¿`
ÆäÖУ¬`-ttable`Ö¸¶¨Òª²Ù×÷µÄ±í£¬Ä¬ÈÏΪfilter±í£»`command`ÊÇiptablesµÄ²Ù×÷ÃüÁÈç-A£¨×·¼Ó¹æÔò£©¡¢-I£¨²åÈë¹æÔò£©¡¢-D£¨É¾³ý¹æÔò£©µÈ£»`match`ÓÃÓÚÖ¸¶¨Æ¥ÅäÌõ¼þ£¬ÈçÔ´IP¡¢Ä¿µÄIP¡¢¶Ë¿ÚºÅ¡¢ÐÒéÀàÐ͵ȣ»`target/jump`Ö¸¶¨µ±Êý¾Ý°üÆ¥Å乿ÔòºóµÄÄ¿±ê¶¯×÷£¬ÈçACCEPT£¨½ÓÊÜ£©¡¢DROP£¨¶ªÆú£©¡¢REJECT£¨¾Ü¾ø²¢·µ»Ø´íÎóÐÅÏ¢£©µÈ
Ìí¼Ó¹æÔò ʹÓÃ-AÑ¡Ïî¿ÉÒÔÔÚÖ¸¶¨Á´µÄĩβÌí¼ÓÒ»Ìõ¹æÔò
ÀýÈ磬ҪÔÊÐíÀ´×ÔÌØ¶¨IPµØÖ·µÄSSHÁ¬½Ó£¬¿ÉÒÔÔÚINPUTÁ´Ìí¼Ó¹æÔò£º`iptables -AINPUT-ptcp--dport22-s192.168.1.100-j ACCEPT`
²åÈë¹æÔò ʹÓÃ-IÑ¡Ïî¿ÉÒÔÔÚÖ¸¶¨Á´µÄÖ¸¶¨Î»ÖòåÈëÒ»Ìõ¹æÔò
Èç¹ûδָ¶¨Î»Öã¬Ôò²åÈëµ½Á´µÄÍ·²¿
ÀýÈ磬ҪÔÚINPUTÁ´µÄ¿ªÍ·²åÈëÒ»Ìõ¹æÔòÒÔÔÊÐíËùÓÐICMPÊý¾Ý°ü£º`iptables -IINPUT-picmp-jACCEPT`
ɾ³ý¹æÔò ʹÓÃ-DÑ¡Ïî¿ÉÒÔɾ³ýÖ¸¶¨Á´ÖеÄÖ¸¶¨¹æÔò
ÐèÒªÖ¸¶¨¹æÔòµÄ±àºÅ»òÍêȫƥÅäµÄ¹æÔòÄÚÈÝ
ÀýÈ磬Ҫɾ³ýINPUTÁ´ÖбàºÅΪ1µÄ¹æÔò£º`iptables -DINPUT1`
Áгö¹æÔò ʹÓÃ-LÑ¡Ïî¿ÉÒÔÁгöÖ¸¶¨Á´ÖеÄËù