centos6.5虛擬機器安裝後,沒有iptables配置檔案

散盡浮華發表於2016-08-31

 

openstack環境裡安裝centos6.5系統的虛擬機器,安裝好後,發現沒有/etc/syscofig/iptables防火牆配置檔案。

解決辦法如下:

[root@kvm-server005 ~]# iptables -P OUTPUT ACCEPT
[root@kvm-server005 ~]# /etc/init.d/iptables save
iptables: Saving firewall rules to /etc/sysconfig/iptables:[ OK ]

這樣,/etc/sysconfig/iptables配置檔案就有了
[root@kvm-server005 ~]# cat /etc/sysconfig/iptables
# Generated by iptables-save v1.4.7 on Wed Aug 31 01:14:57 2016
*filter
:INPUT ACCEPT [43:3196]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [23:2380]
COMMIT
# Completed on Wed Aug 31 01:14:57 2016


再補充點其他內容配置:
[root@kvm-server005 ~]# cat /etc/sysconfig/iptables
# Generated by iptables-save v1.4.7 on Wed Aug 31 01:14:57 2016
*filter
:INPUT ACCEPT [43:3196]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [23:2380]
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -s 192.168.1.0/24 -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
# Completed on Wed Aug 31 01:14:57 2016
[root@kvm-server005 ~]# /etc/init.d/iptables restart
iptables: Setting chains to policy ACCEPT: filter [ OK ]
iptables: Flushing firewall rules: [ OK ]
iptables: Unloading modules: [ OK ]
iptables: Applying firewall rules: [ OK ]
[root@kvm-server005 ~]#

===========================================================
對/etc/sysconfig/iptables檔案的幾條配置的簡單解釋:
:INPUT ACCEPT [0:0]
# 該規則表示INPUT表預設策略是ACCEPT

:FORWARD ACCEPT [0:0]
# 該規則表示FORWARD表預設策略是ACCEPT

:OUTPUT ACCEPT [0:0]
# 該規則表示OUTPUT表預設策略是ACCEPT

-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
# 意思是允許進入的資料包只能是剛剛我發出去的資料包的迴應,ESTABLISHED:已建立的連結狀態。RELATED:該資料包與本機發出的資料包有關。

-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
# 這兩條的意思是在INPUT表和FORWARD表中拒絕所有其他不符合上述任何一條規則的資料包。並且傳送一條host prohibited的訊息給被拒絕的主機。
注意,在做單純的來源IP的白名單限制時,下面這兩條策略不能註釋!否則設定的白名單將無效!

相關文章