{"id":1691,"date":"2010-01-21T14:46:44","date_gmt":"2010-01-21T14:46:44","guid":{"rendered":"http:\/\/www.icocean.com\/blog\/?p=1691"},"modified":"2010-01-21T14:58:54","modified_gmt":"2010-01-21T14:58:54","slug":"lamp%E6%9C%8D%E5%8A%A1%E5%99%A8iptables%E8%A7%84%E5%88%99","status":"publish","type":"post","link":"https:\/\/www.icocean.com\/blog\/?p=1691","title":{"rendered":"LAMP\u670d\u52a1\u5668iptables\u89c4\u5219"},"content":{"rendered":"<p>WEB\u91cc\u5c31\u88c5\u4e86\u4e2aLAMP,\u8981\u6c42\u670d\u52a1\u5668\u53ea\u5f00\u653e80\uff0c21\uff0c22\u7aef\u53e3\u5916\u7f51\u8bbf\u95ee\uff0c\u670d\u52a1\u5668\u51fa\u53bb\u7684\u7aef\u53e3\u90fd\u5f00\u653e<\/p>\n<p>#!\/bin\/bash<br \/>\/sbin\/modprobe ip_conntrac<br \/>\/sbin\/modprobe ip_conntrack_ftp<\/p>\n<p>\/sbin\/iptables -F<br \/>\/sbin\/iptables -X<br \/>\/sbin\/iptables -P INPUT DROP<br \/>\/sbin\/iptables -P FORWARD ACCEPT<br \/>\/sbin\/iptables -P OUTPUT ACCEPT<br \/>\/sbin\/iptables -A INPUT -i lo -j ACCEPT<br \/>\/sbin\/iptables -A INPUT -p tcp &#8211;sport 21 -j ACCEPT<br \/>\/sbin\/iptables -A INPUT -p tcp &#8211;dport 22 -j ACCEPT<br \/>\/sbin\/iptables -A INPUT -p udp &#8211;dport 53 -j ACCEPT<br \/>\/sbin\/iptables -A INPUT -p tcp &#8211;dport 80 -j ACCEPT<br \/>\/sbin\/iptables -A INPUT -m state &#8211;state RELATED,ESTABLISHED -j ACCEPT<!--more--><\/p>\n<p>http:\/\/linux.chinaunix.net\/bbs\/thread-1140391-1-6.html<\/p>\n","protected":false},"excerpt":{"rendered":"<p>WEB\u91cc\u5c31\u88c5\u4e86\u4e2aLAMP,\u8981\u6c42\u670d\u52a1\u5668\u53ea\u5f00\u653e80\uff0c21\uff0c22\u7aef\u53e3\u5916\u7f51\u8bbf\u95ee\uff0c\u670d\u52a1\u5668\u51fa\u53bb\u7684\u7aef\u53e3\u90fd\u5f00\u653e #!\/bin\/ <a href='https:\/\/www.icocean.com\/blog\/?p=1691' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[2525,2574],"class_list":["post-1691","post","type-post","status-publish","format-standard","hentry","category-linuxunix","tag-firewall","tag-iptables","category-16-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1691","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1691"}],"version-history":[{"count":0,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1691\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1691"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1691"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1691"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}