Iptables rules

Iptables v1.2.7a

Usage:  iptables -[AD] chain rule-specificatio [options]
            iptables -[RI] chain rulenum rule-specification [options]
            iptables -D chain rulenum [options]
            iptables -[LFZ] [chain] [options]
            iptables -[NX] chain
            iptables -E old-chain-name new-chain-name
            iptables -P chain target [options]
            iptables -h (print this help information)

Commands:
Either long or short options are allowed.
  --append  -A chain   Append to chain
  --delete    -D chain   Delete matching rule from chain
  --delete    -D chain rulenum Delete rule rulenum(1 = first) from chain
  --insert     -I chain [rulenum] Insert in chain as rulenum(default 1=first)
  --replace  -R chain rulenum Replace rule rulenum(1 = first) in chain
  --list         -L [chain]  List the rules in a chain or all chains
  --flush      -F [chain]  Delete all rules in chain or all chains
  --zero      -Z [chain]  Zero counters in chain or all chains
  --new      -N chain  Create a new user-defined chain
  --delete-chain
                  -X [chain]  Deletc a user-defined chain
  --policy    -P chain target Change policy on chain to target
  --rename-chain
                  -E old-chain new-chain
                             Change chain name,(moving any references)

Options:
  --proto            -p [!] proto  protocol:by number or name,eg.'tcp'
  --source          -s [!] address[/mask]
                                              source specification
  --destination    -d [!] address[/mask]
                                              destination specification
  --in-interface    -i [1] input name[+]
                                               network interface name ([+] for wildcard)
  --jump              -j                   target targetd for rule (may load extension)
  --match            -m                  match extended match (may load extension)
  --numeric         -n                   numeric output of addresses and ports
  --out-interface  -o [!] output name[+]
                                               network interface name ([+] for wildcard)
  --table              -t                   table table to manipulate (default:'filter')
  --verbose         -v                  verbose mode
  --line-numbers                        print line numbers when listing
  --exact             -x                  expand numbers (display exact values)
[!] --fragment      -f                    match seconde or further fragments only
    --modprobe=<command>         try to insert modeules using this command
    --set-counters PKTS BYTES    set the counter during insert/append
[!] --version       -V                   print package version.

posted on 2007-03-16 11:42 黑虫 阅读(714) 评论(0)  编辑 收藏 引用 所属分类: Unix/Linux

只有注册用户登录后才能发表评论。
<2007年3月>
25262728123
45678910
11121314151617
18192021222324
25262728293031
1234567

导航

统计

常用链接

留言簿(4)

随笔分类(31)

随笔档案(31)

awmsky

搜索

最新评论

阅读排行榜

评论排行榜