Membuat settingan iptables di Centos 5.x / RHEL5.x


Setting Firewall di server CENTOS:
system-config-securitylevel –> set enable
uncheklist semua port

cd /root
vi myfirewall
copy paste script dibawah:
——————————————————————————
#!/bin/bash
#
# iptables example configuration script
#
# Flush all current rules from iptables
#
iptables -F
#
# Allow SSH connections on tcp port 22
# This is essential when working on remote servers via SSH to prevent locking yourself out of the system
#
iptables -A INPUT -s 192.168.88.190 -j ACCEPT
iptables -A OUTPUT -d 192.168.88.190 -j ACCEPT
iptables -A INPUT -s 116.90.xx.xx -j ACCEPT
iptables -A OUTPUT -d 116.90.xx.xx -j ACCEPT

# Allow port SSH(22), mysql(3306) & HTTP(80)
iptables -A INPUT -p tcp -s 192.168.88.190 –dport 22 -j ACCEPT
iptables -A INPUT -p tcp -s 192.168.88.190 –dport 80 -j ACCEPT
iptables -A INPUT -p tcp -s 192.168.88.190 –dport 3306 -j ACCEPT
iptables -A INPUT -p tcp -s 116.90.xx.xx –dport 22 -j ACCEPT
iptables -A INPUT -p tcp -s 116.90.xx.xx –dport 80 -j ACCEPT
iptables -A INPUT -p tcp -s 116.90.xx.xx –dport 3306 -j ACCEPT

# Set default policies for INPUT, FORWARD and OUTPUT chains
#
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT DROP
#
# Set access for localhost
#
iptables -A INPUT -i lo -j ACCEPT
#
# Accept packets belonging to established and related connections
#
iptables -A INPUT -m state –state ESTABLISHED,RELATED -j ACCEPT
#
# Save settings
#
/sbin/service iptables save
#
# List rules
#
iptables -L -v
——————————————————————————-

Lalu simpan dengan perintah
#:wq

Rubah mode untuk bisa dieksekusi
#chmod +x myfirewall

Jalankan script myfrewall
#./myfirewall

0 Responses to “Membuat settingan iptables di Centos 5.x / RHEL5.x”



  1. Leave a Comment

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s





%d bloggers like this: