ywtywt 发表于 2015-4-6 22:58:49

iptables如何允许被ping

我现在的规则是这样的

# Generated by iptables-save v1.4.7 on Mon Apr6 22:39:02 2015
*filter
:INPUT ACCEPT
:FORWARD ACCEPT
:OUTPUT ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22000 -j ACCEPT
-A INPUT -s 127.0.0.1/32 -d 127.0.0.1/32 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 3306 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -j REJECT --reject-with icmp-port-unreachable
-A OUTPUT -j ACCEPT
COMMIT
# Completed on Mon Apr6 22:39:02 2015

但是ping的时候提示端口无法访问

licess 发表于 2015-4-7 13:23:14

icmp的两条删掉
页: [1]
查看完整版本: iptables如何允许被ping