【问题标题】:bash script excutes multiple iptables chainbash 脚本执行多个 iptables 链
【发布时间】:2015-04-12 00:32:56
【问题描述】:

我正在使用下面的脚本通过从 whitelist.txt 文件中过滤 IP 来应用 iptables

如果我在列表中有多个 IP,我的iptables 会显示多个链:

#!/bin/bash

# allowed ip file location
WHITELIST=/usr/src/firewall/whitelist.txt
#
## Specify where IP Tables is located
#

IPTABLES=/sbin/iptables
IPTABLES_SAVE=/sbin/iptables-save

#
## Save current iptables running configuration in case we want to revert back
##  To restore using our example we would run "/sbin/iptables-restore < /usr/src/iptables.last"
#
$IPTABLES_SAVE > /usr/src/iptables.last
#
## Clear current rules
#
##If current INPUT policy is set to DROP we will be locked out once we flush the rules
## so we must first ensure it is set to ACCEPT.
#
$IPTABLES -P INPUT ACCEPT
echo 'Setting default INPUT policy to ACCEPT'

$IPTABLES -F
echo 'Clearing Tables F'
$IPTABLES -X
echo 'Clearing Tables X'
$IPTABLES -Z
echo 'Clearing Tables Z'

#Always allow localhost.
echo 'Allowing Localhost'
$IPTABLES -A INPUT -s 127.0.0.1 -j ACCEPT

#
## Whitelist
#

for x in `grep -v ^# $WHITELIST | awk '{print $1}'`; do
echo "Permitting $x..."
# $IPTABLES -A INPUT -s $x -j ACCEPT
$IPTABLES -A INPUT -p tcp --dport 22 -j ACCEPT
$IPTABLES -A INPUT -p tcp -m tcp -s "$x" --dport 80 -j ACCEPT
$IPTABLES -A INPUT -p udp -m udp -s "$x" --dport 5060 -j ACCEPT
done

# block all other traffice

$IPTABLES -A INPUT -p all -j DROP
#
## Save the rules so they are persistent on reboot.
#
/etc/init.d/iptables save

我的 iptables -L -n 输出显示为

firewall]# iptables -L -n
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
ACCEPT     all  --  127.0.0.1            0.0.0.0/0
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:22
ACCEPT     tcp  --  192.168.1.125        0.0.0.0/0           tcp dpt:80
ACCEPT     udp  --  192.168.1.125        0.0.0.0/0           udp dpt:5060
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:22
ACCEPT     tcp  --  192.168.1.1          0.0.0.0/0           tcp dpt:80
ACCEPT     udp  --  192.168.1.1          0.0.0.0/0           udp dpt:5060
DROP       all  --  0.0.0.0/0            0.0.0.0/0

Chain FORWARD (policy DROP)
target     prot opt source               destination

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

如何避免重复,该脚本有什么问题......

【问题讨论】:

  • whitelist.txt 看起来怎么样?
  • 也许您应该将非源地址限定 $IPTABLES -A INPUT -p tcp --dport 22 -j ACCEPT 行放在 for-each-source-address 循环之外?
  • 感谢在外面输入无源地址后它工作完美.....

标签: linux shell firewall iptables python-iptables


【解决方案1】:

我猜你的whitelist.txt 包含两个IP:192.168.1.125 和192.168.1.1?!

然后您为每个 IP 设置三个规则,一个用于 SSH,一个用于 HTTP,一个用于 SIP,只是您没有为 SSH 指定--source/-s,因此对于白名单中的任何 IP,该规则自然会与之前的任何一个相同。

TL;DR:在 SSH 规则中添加 -s "$x" 应该没问题。

额外提示:如果要允许整个私有 C 类子网,可以使用语法-s 192.168.1.0/24 :-)

干杯,

【讨论】:

    猜你喜欢
    • 2020-08-18
    • 2013-10-06
    • 2016-07-11
    • 2015-03-02
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2018-12-14
    • 1970-01-01
    相关资源
    最近更新 更多