|
|
@ -43,7 +43,11 @@ if [ -f /usr/sbin/iptables ];then |
|
|
|
iptables_status=`systemctl status iptables | grep 'inactive'` |
|
|
|
iptables_status=`systemctl status iptables | grep 'inactive'` |
|
|
|
if [ "${iptables_status}" != '' ];then |
|
|
|
if [ "${iptables_status}" != '' ];then |
|
|
|
service iptables restart |
|
|
|
service iptables restart |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# iptables -P FORWARD DROP |
|
|
|
|
|
|
|
iptables -P INPUT DROP |
|
|
|
|
|
|
|
iptables -P OUTPUT ACCEPT |
|
|
|
|
|
|
|
|
|
|
|
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT |
|
|
|
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT |
|
|
|
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT |
|
|
|
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT |
|
|
|
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT |
|
|
|
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT |
|
|
|