`
cakin24
  • 浏览: 1389032 次
  • 性别: Icon_minigender_1
  • 来自: 西安
社区版块
存档分类
最新评论

iptables场景三——模拟公司常用简单iptables规则场景

阅读更多
一 场景要求
1、员工在公司内部(192.168.0.0/24)能访问服务器上的任何服务
2、当员工出差例如在上海,通过VPN连接到公司外网===拨号到===>VPN服务器=====>内网FTP,SAMBA,NFS,SSH
3、公司有一个门户网站需要运行公网访问
二 常见端口梳理


 


 
三 配置规则基本思路

<!--5f39ae17-8c62-4a45-bc43-b32064c9388a:W3siYmxvY2tUeXBlIjoicGFyYWdyYXBoIiwic3R5bGVzIjp7ImFsaWduIjoibGVmdCIsImluZGVudCI6MCwidGV4dC1pbmRlbnQiOjAsImxpbmUtaGVpZ2h0IjoxLjc1fSwiYmxvY2tJZCI6IjY1cWNxeDE1MDMxMjQxMDM4MjUiLCJyaWNoVGV4dCI6eyJpc1JpY2hUZXh0Ijp0cnVlLCJrZWVwTGluZUJyZWFrIjp0cnVlLCJkYXRhIjpbeyJjaGFyIjoi5LiAIiwic3R5bGVzIjp7ImJvbGQiOnRydWV9fSx7ImNoYXIiOiIgIiwic3R5bGVzIjp7ImJvbGQiOnRydWV9fSx7ImNoYXIiOiLlnLoiLCJzdHlsZXMiOnsiYm9sZCI6dHJ1ZX19LHsiY2hhciI6IuaZryIsInN0eWxlcyI6eyJib2xkIjp0cnVlfX0seyJjaGFyIjoi6KaBIiwic3R5bGVzIjp7ImJvbGQiOnRydWV9fSx7ImNoYXIiOiLmsYIiLCJzdHlsZXMiOnsiYm9sZCI6dHJ1ZX19XX19LHsiYmxvY2tUeXBlIjoicGFyYWdyYXBoIiwic3R5bGVzIjp7ImFsaWduIjoibGVmdCIsImluZGVudCI6MCwidGV4dC1pbmRlbnQiOjAsImxpbmUtaGVpZ2h0IjoxLjc1fSwiYmxvY2tJZCI6IjM4cHRjZjE1MDMxMjQyNDA1NDgiLCJyaWNoVGV4dCI6eyJpc1JpY2hUZXh0Ijp0cnVlLCJrZWVwTGluZUJyZWFrIjp0cnVlLCJkYXRhIjpbeyJjaGFyIjoiMSJ9LHsiY2hhciI6IuOAgSJ9LHsiY2hhciI6IuWRmCJ9LHsiY2hhciI6IuW3pSJ9LHsiY2hhciI6IuWcqCJ9LHsiY2hhciI6IuWFrCJ9LHsiY2hhciI6IuWPuCJ9LHsiY2hhciI6IuWGhSJ9LHsiY2hhciI6IumDqCJ9LHsiY2hhciI6Iu+8iCJ9LHsiY2hhciI6IjEifSx7ImNoYXIiOiI5In0seyJjaGFyIjoiMiJ9LHsiY2hhciI6Ii4ifSx7ImNoYXIiOiIxIn0seyJjaGFyIjoiNiJ9LHsiY2hhciI6IjgifSx7ImNoYXIiOiIuIn0seyJjaGFyIjoiMCJ9LHsiY2hhciI6Ii4ifSx7ImNoYXIiOiIwIn0seyJjaGFyIjoiLyJ9LHsiY2hhciI6IjIifSx7ImNoYXIiOiI0In0seyJjaGFyIjoi77yJIn0seyJjaGFyIjoi6IO9In0seyJjaGFyIjoi6K6/In0seyJjaGFyIjoi6ZeuIn0seyJjaGFyIjoi5pyNIn0seyJjaGFyIjoi5YqhIn0seyJjaGFyIjoi5ZmoIn0seyJjaGFyIjoi5LiKIn0seyJjaGFyIjoi55qEIn0seyJjaGFyIjoi5Lu7In0seyJjaGFyIjoi5L2VIn0seyJjaGFyIjoi5pyNIn0seyJjaGFyIjoi5YqhIn1dfX0seyJibG9ja1R5cGUiOiJwYXJhZ3JhcGgiLCJzdHlsZXMiOnsiYWxpZ24iOiJsZWZ0IiwiaW5kZW50IjowLCJ0ZXh0LWluZGVudCI6MCwibGluZS1oZWlnaHQiOjEuNzV9LCJibG9ja0lkIjoiM29rY2QxNTAzMTI0MjkzMTczIiwicmljaFRleHQiOnsiaXNSaWNoVGV4dCI6dHJ1ZSwia2VlcExpbmVCcmVhayI6dHJ1ZSwiZGF0YSI6W3siY2hhciI6IjIifSx7ImNoYXIiOiLjgIEifSx7ImNoYXIiOiLlvZMifSx7ImNoYXIiOiLlkZgifSx7ImNoYXIiOiLlt6UifSx7ImNoYXIiOiLlh7oifSx7ImNoYXIiOiLlt64ifSx7ImNoYXIiOiLkvosifSx7ImNoYXIiOiLlpoIifSx7ImNoYXIiOiLlnKgifSx7ImNoYXIiOiLkuIoifSx7ImNoYXIiOiLmtbcifSx7ImNoYXIiOiLvvIwifSx7ImNoYXIiOiLpgJoifSx7ImNoYXIiOiLov4cifSx7ImNoYXIiOiJWIn0seyJjaGFyIjoiUCJ9LHsiY2hhciI6Ik4ifSx7ImNoYXIiOiLov54ifSx7ImNoYXIiOiLmjqUifSx7ImNoYXIiOiLliLAifSx7ImNoYXIiOiLlhawifSx7ImNoYXIiOiLlj7gifSx7ImNoYXIiOiLlpJYifSx7ImNoYXIiOiLnvZEifSx7ImNoYXIiOiI9In0seyJjaGFyIjoiPSJ9LHsiY2hhciI6Ij0ifSx7ImNoYXIiOiLmi6gifSx7ImNoYXIiOiLlj7cifSx7ImNoYXIiOiLliLAifSx7ImNoYXIiOiI9In0seyJjaGFyIjoiPSJ9LHsiY2hhciI6Ij0ifSx7ImNoYXIiOiI+In0seyJjaGFyIjoiViJ9LHsiY2hhciI6IlAifSx7ImNoYXIiOiJOIn0seyJjaGFyIjoi5pyNIn0seyJjaGFyIjoi5YqhIn0seyJjaGFyIjoi5ZmoIn0seyJjaGFyIjoiPSJ9LHsiY2hhciI6Ij0ifSx7ImNoYXIiOiI9In0seyJjaGFyIjoiPSJ9LHsiY2hhciI6Ij0ifSx7ImNoYXIiOiI+In0seyJjaGFyIjoi5YaFIn0seyJjaGFyIjoi572RIn0seyJjaGFyIjoiRiJ9LHsiY2hhciI6IlQifSx7ImNoYXIiOiJQIn0seyJjaGFyIjoi77yMIn0seyJjaGFyIjoiUyJ9LHsiY2hhciI6IkEifSx7ImNoYXIiOiJNIn0seyJjaGFyIjoiQiJ9LHsiY2hhciI6IkEifSx7ImNoYXIiOiLvvIwifSx7ImNoYXIiOiJOIn0seyJjaGFyIjoiRiJ9LHsiY2hhciI6IlMifSx7ImNoYXIiOiLvvIwifSx7ImNoYXIiOiJTIn0seyJjaGFyIjoiUyJ9LHsiY2hhciI6IkgifV19fSx7ImJsb2NrVHlwZSI6InBhcmFncmFwaCIsInN0eWxlcyI6eyJhbGlnbiI6ImxlZnQiLCJpbmRlbnQiOjAsInRleHQtaW5kZW50IjowLCJsaW5lLWhlaWdodCI6MS43NX0sImJsb2NrSWQiOiI0NGZvZ2cxNTAzMTI0NDA1NzQyIiwicmljaFRleHQiOnsiaXNSaWNoVGV4dCI6dHJ1ZSwia2VlcExpbmVCcmVhayI6dHJ1ZSwiZGF0YSI6W3siY2hhciI6IjMifSx7ImNoYXIiOiLjgIEifSx7ImNoYXIiOiLlhawifSx7ImNoYXIiOiLlj7gifSx7ImNoYXIiOiLmnIkifSx7ImNoYXIiOiLkuIAifSx7ImNoYXIiOiLkuKoifSx7ImNoYXIiOiLpl6gifSx7ImNoYXIiOiLmiLcifSx7ImNoYXIiOiLnvZEifSx7ImNoYXIiOiLnq5kifSx7ImNoYXIiOiLpnIAifSx7ImNoYXIiOiLopoEifSx7ImNoYXIiOiLov5AifSx7ImNoYXIiOiLooYwifSx7ImNoYXIiOiLlhawifSx7ImNoYXIiOiLnvZEifSx7ImNoYXIiOiLorr8ifSx7ImNoYXIiOiLpl64ifV19fSx7ImJsb2NrVHlwZSI6InBhcmFncmFwaCIsInN0eWxlcyI6eyJhbGlnbiI6ImxlZnQiLCJpbmRlbnQiOjAsInRleHQtaW5kZW50IjowLCJsaW5lLWhlaWdodCI6MS43NX0sImJsb2NrSWQiOiIxNGplaHYxNTAzMTI0NDUxNTcwIiwicmljaFRleHQiOnsiaXNSaWNoVGV4dCI6dHJ1ZSwia2VlcExpbmVCcmVhayI6dHJ1ZSwiZGF0YSI6W3siY2hhciI6IuS6jCIsInN0eWxlcyI6eyJib2xkIjp0cnVlfX0seyJjaGFyIjoiICIsInN0eWxlcyI6eyJib2xkIjp0cnVlfX0seyJjaGFyIjoi5bi4Iiwic3R5bGVzIjp7ImJvbGQiOnRydWV9fSx7ImNoYXIiOiLop4EiLCJzdHlsZXMiOnsiYm9sZCI6dHJ1ZX19LHsiY2hhciI6IuerryIsInN0eWxlcyI6eyJib2xkIjp0cnVlfX0seyJjaGFyIjoi5Y+jIiwic3R5bGVzIjp7ImJvbGQiOnRydWV9fSx7ImNoYXIiOiLmorMiLCJzdHlsZXMiOnsiYm9sZCI6dHJ1ZX19LHsiY2hhciI6IueQhiIsInN0eWxlcyI6eyJib2xkIjp0cnVlfX1dfX0seyJibG9ja1R5cGUiOiJwYXJhZ3JhcGgiLCJzdHlsZXMiOnsiYWxpZ24iOiJsZWZ0IiwiaW5kZW50IjowLCJ0ZXh0LWluZGVudCI6MCwibGluZS1oZWlnaHQiOjEuNzV9LCJibG9ja0lkIjoiNTRldmlxMTUwMzEyNDQ2NDE1MSIsInJpY2hUZXh0Ijp7ImlzUmljaFRleHQiOnRydWUsImtlZXBMaW5lQnJlYWsiOnRydWUsImRhdGEiOlt7ImNoYXIiOiIyIiwic3R5bGVzIjp7ImNvbG9yIjoiI0RGNDAyQSJ9fSx7ImNoYXIiOiIwIiwic3R5bGVzIjp7ImNvbG9yIjoiI0RGNDAyQSJ9fSx7ImNoYXIiOiI3Iiwic3R5bGVzIjp7ImNvbG9yIjoiI0RGNDAyQSJ9fSx7ImNoYXIiOiIuIiwic3R5bGVzIjp7ImNvbG9yIjoiI0RGNDAyQSJ9fSx7ImNoYXIiOiJwIiwic3R5bGVzIjp7ImNvbG9yIjoiI0RGNDAyQSJ9fSx7ImNoYXIiOiJuIiwic3R5bGVzIjp7ImNvbG9yIjoiI0RGNDAyQSJ9fSx7ImNoYXIiOiJnIiwic3R5bGVzIjp7ImNvbG9yIjoiI0RGNDAyQSJ9fV19fSx7ImJsb2NrVHlwZSI6InBhcmFncmFwaCIsInN0eWxlcyI6eyJhbGlnbiI6ImxlZnQiLCJpbmRlbnQiOjAsInRleHQtaW5kZW50IjowLCJsaW5lLWhlaWdodCI6MS43NX0sImJsb2NrSWQiOiI4MG51dnMxNTAzMTI0NTQyOTkwIiwicmljaFRleHQiOnsiaXNSaWNoVGV4dCI6dHJ1ZSwia2VlcExpbmVCcmVhayI6dHJ1ZSwiZGF0YSI6W3siY2hhciI6IjIiLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6IjAiLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6IjgiLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6Ii4iLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6InAiLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6Im4iLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6ImciLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19XX19LHsiYmxvY2tUeXBlIjoicGFyYWdyYXBoIiwic3R5bGVzIjp7ImFsaWduIjoibGVmdCIsImluZGVudCI6MCwidGV4dC1pbmRlbnQiOjAsImxpbmUtaGVpZ2h0IjoxLjc1fSwiYmxvY2tJZCI6Ijhla2lsMTUwMzEyNDU4MTA0MSIsInJpY2hUZXh0Ijp7ImlzUmljaFRleHQiOnRydWUsImtlZXBMaW5lQnJlYWsiOnRydWUsImRhdGEiOlt7ImNoYXIiOiLkuIkiLCJzdHlsZXMiOnsiYm9sZCI6dHJ1ZX19LHsiY2hhciI6IiAiLCJzdHlsZXMiOnsiYm9sZCI6dHJ1ZX19LHsiY2hhciI6IumFjSIsInN0eWxlcyI6eyJib2xkIjp0cnVlfX0seyJjaGFyIjoi572uIiwic3R5bGVzIjp7ImJvbGQiOnRydWV9fSx7ImNoYXIiOiLop4QiLCJzdHlsZXMiOnsiYm9sZCI6dHJ1ZX19LHsiY2hhciI6IuWImSIsInN0eWxlcyI6eyJib2xkIjp0cnVlfX0seyJjaGFyIjoi5Z+6Iiwic3R5bGVzIjp7ImJvbGQiOnRydWV9fSx7ImNoYXIiOiLmnKwiLCJzdHlsZXMiOnsiYm9sZCI6dHJ1ZX19LHsiY2hhciI6IuaAnSIsInN0eWxlcyI6eyJib2xkIjp0cnVlfX0seyJjaGFyIjoi6LevIiwic3R5bGVzIjp7ImJvbGQiOnRydWV9fV19fSx7ImJsb2NrVHlwZSI6InBhcmFncmFwaCIsInN0eWxlcyI6eyJhbGlnbiI6ImxlZnQiLCJpbmRlbnQiOjAsInRleHQtaW5kZW50IjowLCJsaW5lLWhlaWdodCI6MS43NX0sImJsb2NrSWQiOiI4MHFxcmMxNTAzMTI0NTk0NjMxIiwicmljaFRleHQiOnsiaXNSaWNoVGV4dCI6dHJ1ZSwia2VlcExpbmVCcmVhayI6dHJ1ZSwiZGF0YSI6W3siY2hhciI6IjIiLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6IjAiLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6IjkiLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6Ii4iLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6InAiLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6Im4iLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19LHsiY2hhciI6ImciLCJzdHlsZXMiOnsiY29sb3IiOiIjREY0MDJBIn19XX19XQ==-->



 
  • 大小: 70.4 KB
  • 大小: 88.2 KB
  • 大小: 102.7 KB
分享到:
评论

相关推荐

    网络安全课程设计之D防火墙——Iptables.docx

    iptables 常用的通用匹配条件和扩展匹配条件;添加、修 改、删除自定义链的方法。 实验内容:1)使用 iptables 制定规则,包括添加、修改、保存和删除规则等。 2)使用通用匹配条件和扩展匹配条件定义 iptables ...

    Linux系统Iptables规则执行顺序详细讲解

    Iptables是采用规则堆栈的方式来进行过滤,当一个封包进入网卡,会先检查Prerouting,然后检查目的IP判断是否需要转送出去,接着就会跳到INPUT或Forward进行过滤,如果封包需转送处理则检查Postrouting,如果是来自...

    iptables基本命令规则简介

    iptables 是基于内核的防火墙,功能非常强大,iptables 内置了 filter,nat 和 mangle 三张表。filter 负责过滤数据包,包括的规则链有,input,output 和 forward;nat 则涉及到网络地址转换,包括的规则链有,...

    centos6 iptables常用操作

    ### CentOS 6 iptables 常用操作及规则配置 #### 概述 在Linux系统中,`iptables`是一款强大的工具,用于管理网络流量并控制数据包过滤规则。CentOS 6作为一款广泛使用的服务器操作系统,其内置的`iptables`功能...

    Linux防火墙:iptables禁IP与解封IP常用命令.docx

    Linux防火墙:iptables禁IP与解封IP常用命令.docx

    Centos离线安装iptables.docx

    在CentOS系统中,iptables是用于设置网络规则的重要工具之一。然而,在某些情况下,由于网络环境限制或安全考虑,我们可能无法通过在线方式安装iptables。本文将详细介绍如何在CentOS系统上离线安装iptables及其服务...

    iptables常用命令和使用

    ### iptables常用命令详解 #### 一、iptables简介 **iptables** 是一款强大的包过滤防火墙工具,它允许用户通过定义一系列复杂的规则来控制进出主机的数据包。此工具需要Linux内核版本至少为2.4及以上,对于2.6及...

    linux防火墙iptables常用规则.docx

    ### Linux防火墙iptables常用规则详解 #### 一、iptables基础操作与配置 ##### 删除现有规则 在使用iptables之前,我们通常需要先清除已有的规则,以便于重新建立新的规则集。这可以通过`iptables -F`命令来实现。...

    1个iptables主机 模拟4个不同的网络环境的网关

    1个iptables主机 模拟4个不同的网络环境的网关

    iptables命令实例

    三、iptables 规则的设定 iptables 规则的设定可以分为两个方面:输入链和输出链。输入链用于控制进入系统的流量,而输出链用于控制离开系统的流量。 例如,要开启 80 端口,可以使用以下命令:`iptables -I INPUT...

    iptables-1.6.0.tar.bz2

    ———————————————— 版权声明:本文为CSDN博主「dhjibk」的原创文章,遵循CC 4.0 BY-SA版权协议,转载请附上原文出处链接及本声明。 原文链接:...

    android流量防火墙iptables原理详解

    Iptables 是一个功能强大的 IP 信息包过滤系统,可以用于添加、编辑和删除规则,这些规则是在做信息包过滤决定时,防火墙所遵循和组成的规则。 Iptables 的工作原理: Iptables 是与最新的 2.6.x 版本 Linux 内核...

    Linux iptables Pocket Refrence

    - **The iptables Subcommands(iptables子命令)**:包括如`-A`添加规则、`-D`删除规则、`-R`替换规则等。 - **iptables Matches and Targets(iptables匹配条件与目标)**:提供了各种匹配条件和目标的使用方法。 ...

    Linux上iptables防火墙的应用教程

    Linux 上的 iptables 防火墙是一种常用的防火墙软件,能够控制访问 Linux 系统的流量。iptables 防火墙的基本应用包括安装、清除规则、开放指定端口、屏蔽指定 IP、删除已添加的规则等。 安装 iptables 防火墙 若...

    iptables详解:图文并茂理解iptables.pdf

    iptables 防火墙 linux

    iptables 语法 (经典)

    以上只是一部分iptables的常用语法和示例,实际使用中还可以根据需要添加更复杂的规则,如基于时间的规则、自定义标记等。iptables提供了一种灵活的方式来控制网络流量,确保系统安全并优化网络性能。理解并熟练掌握...

    IPTables规则保护Linux安全.pdf

    IPTables规则保护Linux安全.pdf

Global site tag (gtag.js) - Google Analytics