直接iptables 命令搞的设置是一次性的,下次开启防火墙就没有了,
永久的要rules文件,我的在,
/etc/iptables/iptables.rules
这个目录下有个simple_firewall.rules,可以直接拿来用,
[0aoeiuv@AoEiuV-PC:~]1$cat /etc/iptables/simple_firewall.rules
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -p icmp -j ACCEPT
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -j REJECT --reject-with tcp-reset
-A INPUT -p udp -j REJECT --reject-with icmp-port-unreachable
-A INPUT -j REJECT --reject-with icmp-proto-unreachable
COMMIT