Linux with Operating System Concepts



Download 5,65 Mb.
Pdf ko'rish
bet192/254
Sana22.07.2022
Hajmi5,65 Mb.
#840170
1   ...   188   189   190   191   192   193   194   195   ...   254
Bog'liq
Linux-with-Operating-System-Concepts-Fox-Richard-CRC-Press-2014

Directive
Meaning
Default
IPTABLES_MODULES
List of modules to load after firewall rules are applied
“” (none)
IPTABLES_MODULES_
UNLOAD
Unloads modules on firewall stop or restart
Yes
IPTABLES_SAVE_ON_STOP
Rules may be added to your firewall from the command 
line; if this directive is set to yes, then all current rules 
are saved to iptables upon stopping the firewall
No
IPTABLES_SAVE_ON_RESTART
If set to yes, saves all current rules to iptables upon 
restarting the firewall
No
IPTABLES_SAVE_COUNTER
Saves all chains of rules and counters for rules to iptables 
upon stop or restart of firewall, or the command 
/sbin/service iptables save
No
IPTABLES_STATUS_NUMERIC
Prints IP addresses and ports in numeric format when 
status
of firewall is requested
Yes
IPTABLES_STATUS_VERBOSE
Prints statistics about packets and bytes when 
status
of firewall is requested
Yes
IPTABLES_STATUS_
LINENUMBERS
Prints line numbers of rules when 
status
of firewall is 
requested
Yes
FIGURE 12.6 
Verbose status from iptables.


Network Configuration

513
The value of 
chain
will be one of INPUT, OUTPUT or FORWARD, or a chain that you 
have defined. The value of 
target
will be one of ACCEPT, REJECT, DROP, or LOG that 
indicates what should be done with the message (these four values are described later). The 
–A option indicates that this rule should be 
appended
to the given chain. Thus, we are add-
ing to the chain so that if previous rules do not match, the firewall can continue to examine 
more rules of the chain.
The options in the rule specify the criteria by which the rule will match. You can think 
of these as the conditions of an if-then statement. Some of the most useful and common 
options available for the iptables rules are presented in Table 12.6. Notice --
dport
and 
--
dports
are subtly different. The former is used if you are comparing the message’s port 
to a single port of interest while the latter compares the message’s port against a list of 
ports. Similarly, there is a distinction between 
sport
and 
sports
.
Rules may have any number of options. For the rule to be true, 
all
options specified must 
be true. If a rule is true, the action specified under the target will take place. If any target 
other than LOG is used, chaining will stop. For instance, if a rule causes a packet to be 
accepted, then no more chaining takes place. The four targets are listed below.
• ACCEPT—permit the packet entry to the system
• REJECT—reject the packet and notify the sender
• DROP—reject the packet without notifying the sender
• LOG—log the packet but continue chaining rules to reach one of the other targets
TABLE 12.6 
iptable Rule Options

Download 5,65 Mb.

Do'stlaringiz bilan baham:
1   ...   188   189   190   191   192   193   194   195   ...   254




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish