VPS侦探论坛

标题: iptables如何允许被ping [打印本页]

作者: ywtywt    时间: 2015-4-6 22:58
标题: iptables如何允许被ping
我现在的规则是这样的

# Generated by iptables-save v1.4.7 on Mon Apr  6 22:39:02 2015
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22000 -j ACCEPT
-A INPUT -s 127.0.0.1/32 -d 127.0.0.1/32 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 3306 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -j REJECT --reject-with icmp-port-unreachable
-A OUTPUT -j ACCEPT
COMMIT
# Completed on Mon Apr  6 22:39:02 2015

但是ping的时候提示端口无法访问
作者: licess    时间: 2015-4-7 13:23
icmp的两条删掉




欢迎光临 VPS侦探论坛 (https://bbs.lnmp.com/) Powered by Discuz! X3.4