Portál AbcLinuxu, 12. května 2025 18:28
#omezená IP IPBLOK1=192.168.4.53 iptables -N whitelist iptables -A whitelist -s IPBLOK1 -j ACCEPT iptables -A INPUT -j whitelist iptables -A OUTPUT -j whitelist iptables -A FORWARD -j whitelist
iptables -A FORWARD -s IP -d 77.75.77.138 -p tcp --destination-port 80 -j ACCEPT iptables -A FORWARD -s IP -d 194.213.41.145 -p tcp --destination-port 80 -j ACCEPT
cat firewall.sh #!/bin/bash modprobe ip_conntrack whitelist=/etc/init.d/whitelist IP=192.168.4.73 iptables -P INPUT DROP iptables -P OUTPUT DROP iptables -N whitelist iptables -A whitelist -s $IP -j ACCEPT iptables -A whitelist -j RETURN iptables -A INPUT -j whitelist iptables -A OUTPUT -j whitelist
#www.mapy.cz 77.75.77.138 #www.justice.cz 194.213.41.145
iptables -L -v -n Chain INPUT (policy DROP 24 packets, 1632 bytes) pkts bytes target prot opt in out source destination 24 1632 whitelist all -- * * 0.0.0.0/0 0.0.0.0/0 Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain OUTPUT (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 whitelist all -- * * 0.0.0.0/0 0.0.0.0/0 Chain allowed_ips (0 references) pkts bytes target prot opt in out source destination Chain blacklist (0 references) pkts bytes target prot opt in out source destination Chain whitelist (2 references) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * * 192.168.4.73 0.0.0.0/0 24 1632 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0Ale nedostanu se nikam ani na ty dvě IP co jsou v whitelistu :) ..
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.