mirror of
https://github.com/cheat/cheat.git
synced 2024-12-18 18:55:06 +01:00
[IPTABLES] Add some cheats for iptables
This commit is contained in:
parent
a858032d60
commit
c5f1d5c1ac
@ -16,3 +16,25 @@ iptables -A INPUT -i eth0 -p tcp --dport 902 -j REJECT --reject-with icmp-port-u
|
||||
# icmp-host-prohibited or
|
||||
# icmp-admin-prohibited
|
||||
# tcp-reset
|
||||
|
||||
# Add a comment to a rule:
|
||||
iptables ... -m comment --comment "This rule is here for this reason"
|
||||
|
||||
|
||||
# To remove or insert a rule:
|
||||
# 1) Show all rules
|
||||
iptables -L INPUT --line-numbers
|
||||
# OR iptables -nL --line-numbers
|
||||
|
||||
# Chain INPUT (policy ACCEPT)
|
||||
# num target prot opt source destination
|
||||
# 1 ACCEPT udp -- anywhere anywhere udp dpt:domain
|
||||
# 2 ACCEPT tcp -- anywhere anywhere tcp dpt:domain
|
||||
# 3 ACCEPT udp -- anywhere anywhere udp dpt:bootps
|
||||
# 4 ACCEPT tcp -- anywhere anywhere tcp dpt:bootps
|
||||
|
||||
# 2.a) REMOVE (-D) a rule. (here an INPUT rule)
|
||||
iptables -D INPUT 2
|
||||
|
||||
# 2.b) OR INSERT a rule.
|
||||
iptables -I INPUT {LINE_NUMBER} -i eth1 -p tcp --dport 21 -s 123.123.123.123 -j ACCEPT -m comment --comment "This rule is here for this reason"
|
||||
|
Loading…
Reference in New Issue
Block a user