linux通过iptables只允许某ip可以ping

// 禁止全部ping操作
iptables -I INPUT 1 -p icmp --icmp-type echo-request -j DROP
// 只允许某ip可以ping操作
iptables -I INPUT -p icmp --icmp-type echo-request -s 8.8.8.8 -j ACCEPT

禁止入向ping包:
iptables -I INPUT 1 -p icmp --icmp-type echo-request -j DROP
ip6tables -I INPUT 1 -p icmpv6 --icmpv6-type echo-request -j DROP

取消禁止:
iptables -D INPUT -p icmp --icmp-type echo-request -j DROP
ip6tables -D INPUT -p icmpv6 --icmpv6-type echo-request -j DROP

禁止应答入向ping包:
iptables -I OUTPUT 1 -p icmp --icmp-type echo-reply -j DROP
ip6tables -I OUTPUT 1 -p icmpv6 --icmpv6-type echo-reply -j DROP

禁止出向ping包:
iptables -I OUTPUT 1 -p icmp --icmp-type echo-request -j DROP
ip6tables -I OUTPUT 1 -p icmpv6 --icmpv6-type echo-request -j DROP

猜你喜欢

转载自blog.csdn.net/ouchangjian/article/details/122926544
今日推荐