iptables問題一問 - Linux
By Cara
at 2010-03-02T10:31
at 2010-03-02T10:31
Table of Contents
Dear 鄉民~
看完了遊戲王出場的燈會~還有大大的月亮 是不是覺得夏天就要到了
(結果今天好冷).....咦~離題了
這是我目前server的架構
OS CENTOS 5.4
web server : httpd-2.2.3-31.el5.centos.2
IP addr 10.1.1.1
裡面同時還有dns, sendmail, ftp, mysql 在執行
這是iptables的規則
INPUT Chain
-A INPUT -s 10.1.1.1 -i lo -p tcp -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 8 -m limit --limit 5/sec --limit-burst 10 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 8 -j DROP
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 25 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 110 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 21 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 20 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 443 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -d 127.0.0.1 -i lo -j ACCEPT
-A INPUT -j DROP
OUTPUT Chain
-A OUTPUT -o eth0 -j ACCEPT
-A OUTPUT -d 127.0.0.1 -o lo -j ACC
自己看了看是沒有甚麼問題~也想了一下
然後..../etc/init.d/iptables給他start下去
花現一個殘忍的事實.....網頁變的超級慢......
有點卡關~~~
囧 是不是有哪裡沒有想到呢?? 還請指點囉~
--
--
看完了遊戲王出場的燈會~還有大大的月亮 是不是覺得夏天就要到了
(結果今天好冷).....咦~離題了
這是我目前server的架構
OS CENTOS 5.4
web server : httpd-2.2.3-31.el5.centos.2
IP addr 10.1.1.1
裡面同時還有dns, sendmail, ftp, mysql 在執行
這是iptables的規則
INPUT Chain
-A INPUT -s 10.1.1.1 -i lo -p tcp -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 8 -m limit --limit 5/sec --limit-burst 10 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 8 -j DROP
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 25 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 110 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 21 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 20 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 443 -j ACCEPT
-A INPUT -d 10.1.1.1 -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -d 127.0.0.1 -i lo -j ACCEPT
-A INPUT -j DROP
OUTPUT Chain
-A OUTPUT -o eth0 -j ACCEPT
-A OUTPUT -d 127.0.0.1 -o lo -j ACC
自己看了看是沒有甚麼問題~也想了一下
然後..../etc/init.d/iptables給他start下去
花現一個殘忍的事實.....網頁變的超級慢......
有點卡關~~~
囧 是不是有哪裡沒有想到呢?? 還請指點囉~
--
--
Tags:
Linux
All Comments
By Michael
at 2010-03-05T09:05
at 2010-03-05T09:05
By Catherine
at 2010-03-08T00:13
at 2010-03-08T00:13
By Genevieve
at 2010-03-11T09:49
at 2010-03-11T09:49
By Andrew
at 2010-03-13T10:11
at 2010-03-13T10:11
By Joseph
at 2010-03-17T12:04
at 2010-03-17T12:04
By Wallis
at 2010-03-17T15:24
at 2010-03-17T15:24
By George
at 2010-03-19T19:08
at 2010-03-19T19:08
By Charlie
at 2010-03-24T16:16
at 2010-03-24T16:16
By Ina
at 2010-03-26T14:29
at 2010-03-26T14:29
By Harry
at 2010-03-31T11:41
at 2010-03-31T11:41
By Erin
at 2010-04-04T08:55
at 2010-04-04T08:55
By Emma
at 2010-04-07T13:06
at 2010-04-07T13:06
By Caitlin
at 2010-04-10T03:42
at 2010-04-10T03:42
By Carol
at 2010-04-14T20:28
at 2010-04-14T20:28
By Hardy
at 2010-04-16T18:00
at 2010-04-16T18:00
By Lucy
at 2010-04-18T18:57
at 2010-04-18T18:57
By Joseph
at 2010-04-21T14:29
at 2010-04-21T14:29
By Lauren
at 2010-04-25T00:43
at 2010-04-25T00:43
Related Posts
Rainlendar 的事件Alarm
By Odelette
at 2010-03-01T23:58
at 2010-03-01T23:58
gcin中嘸蝦米的逗點
By Harry
at 2010-03-01T23:48
at 2010-03-01T23:48
燒錄centOS 5.4 義大載的
By Skylar DavisLinda
at 2010-03-01T20:04
at 2010-03-01T20:04
灌好雙系統後進不了xp
By Kelly
at 2010-03-01T18:31
at 2010-03-01T18:31
灌好雙系統後進不了xp
By Mary
at 2010-03-01T17:17
at 2010-03-01T17:17