Back

表 1. iptablesの設定例

*filter
:INPUT DROP [0:0]							(1)
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:RH-Lokkit-0-50-INPUT - [0:0]
-A INPUT -j RH-Lokkit-0-50-INPUT
-A FORWARD -j RH-Lokkit-0-50-INPUT
-A RH-Lokkit-0-50-INPUT -i lo -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p icmp -j ACCEPT				(2)
-A RH-Lokkit-0-50-INPUT -p tcp --sport 53 -s 130.87.56.2 -j ACCEPT	(3)
-A RH-Lokkit-0-50-INPUT -p tcp --sport 42 -s 130.87.56.2 -j ACCEPT	(4)
-A RH-Lokkit-0-50-INPUT -p udp --sport 53 -s 130.87.56.2 -j ACCEPT	(5)
-A RH-Lokkit-0-50-INPUT -p udp --sport 42 -s 130.87.56.2 -j ACCEPT	(6)
-A RH-Lokkit-0-50-INPUT -s 172.30.32.102 -p udp -m udp --sport 123 --dport 123 -j ACCEPT (7)
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp -- dport 22 -j ACCEPT		(8)
-A RH-Lokkit-0-50-INPUT -s 130.87.0.0/255.255.0.0 -p tcp -m tcp --dport 22 -j ACCEPT     (9)
-A RH-Lokkit-0-50-INPUT -p tcp --dport 25 -j ACCEPT			(10)
-A RH-Lokkit-0-50-INPUT -p tcp --sport 25 -j ACCEPT			(11)
-A RH-Lokkit-0-50-INPUT -p tcp --dport 113 -j ACCEPT			(12)
-A RH-Lokkit-0-50-INPUT -p tcp -s 130.87.32.65 --sport 515 -j ACCEPT	(13)
-A RH-Lokkit-0-50-INPUT -p tcp --dport 80 -j ACCEPT			(14)
-A RH-Lokkit-0-50-INPUT -p tcp --dport 137:139 -s 130.87.57.44 -j ACCEPT (15)
-A RH-Lokkit-0-50-INPUT -p udp --dport 137:139 -s 130.87.57.44 -j ACCEPT (16)
-A RH-Lokkit-0-50-INPUT -p udp --dport 111 -s 130.87.57.44 -j ACCEPT	(17)
-A RH-Lokkit-0-50-INPUT -p tcp --dport 111 -s 130.87.57.44 -j ACCEPT	(18)
-A RH-Lokkit-0-50-INPUT -p udp --dport 1024 -s 130.87.57.44 -j ACCEPT	(19)
-A RH-Lokkit-0-50-INPUT -p udp --dport 2049 -s 130.87.57.44 -j ACCEPT	(19)


Back