centos防火墙添加端口8080 版本2.6.32-279.el6.x86_64

centos防火墙添加端口:

执行 vi /etc/sysconfig/iptables 如下

# Generated by iptables-save v1.4.7 on Thu Jan 29 00:55:17 2015
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [33:3044]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 8080 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
# Completed on Thu Jan 29 00:55:17 2015

添加如下:-A INPUT -p tcp -m state --state NEW -m tcp --dport 8080 -j ACCEPT 

注意,一定要添加到REJECT  语句之上,我添加到下面的时候端口依然不能访问,添加到上面就可以了。

添加后执行 /etc/rc.d/init.d/iptables restart

查看  /etc/rc.d/init.d/iptables status 如下:
1    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED 
2    ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0           
3    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           
4    ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           state NEW tcp dpt:22 
5    ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           state NEW tcp dpt:8080 
6    REJECT     all  --  0.0.0.0/0            0.0.0.0/0           reject-with icmp-host-prohibited 


Chain FORWARD (policy ACCEPT)
num  target     prot opt source               destination         
1    REJECT     all  --  0.0.0.0/0            0.0.0.0/0           reject-with icmp-host-prohibited 


Chain OUTPUT (policy ACCEPT)
num  target     prot opt source               destination         

如果有第5条信息,访问浏览器试试.

猜你喜欢

转载自blog.csdn.net/ysyanshen/article/details/43273645
今日推荐