<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[沧海一粟]]></title> 
<link>http://www.dzhope.com/index.php</link> 
<description><![CDATA[Web系统架构与服务器运维,php开发]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[沧海一粟]]></copyright>
<item>
<link>http://www.dzhope.com/post//</link>
<title><![CDATA[centos禁止ip段和禁止icmp 包]]></title> 
<author>jed &lt;jed521@163.com&gt;</author>
<category><![CDATA[服务器技术]]></category>
<pubDate>Mon, 28 May 2012 02:31:59 +0000</pubDate> 
<guid>http://www.dzhope.com/post//</guid> 
<description>
<![CDATA[ 
	# iptables -F<br/># iptables -P INPUT ACCEPT<br/># iptables -P OUTPUT ACCEPT<br/># iptables -P FORWARD ACCEPT<br/># iptables -A FORWARD -s 124.115.0.0/24 -j DROP<br/># iptables -I FORWARD -d 202.96.170.164 -j DROP<br/><br/>补充：：<br/><br/>单个IP的命令是<br/>iptables -I INPUT -s 124.115.0.199 -j DROP<br/><br/>封IP段的命令是<br/>iptables -I INPUT -s 124.115.0.0/16 -j DROP<br/>iptables -I INPUT -s 124.115.3.0/16 -j DROP<br/>iptables -I INPUT -s 124.115.4.0/16 -j DROP<br/><br/>封整个段的命令是<br/>iptables -I INPUT -s 124.115.0.0/8 -j DROP<br/><br/>封几个段的命令是<br/>iptables -I INPUT -s 61.37.80.0/24 -j DROP<br/>iptables -I INPUT -s 61.37.81.0/24 -j DROP<br/><br/>用iptables禁止一个ＩＰ地址范围<br/><br/>iptables -A FORWARD -s 10.0.0.1-255 -j DROP<br/><br/>用防火墙禁止(或丢弃) icmp 包<br/>iptables -A INPUT -p icmp -j DROP<br/><br/>Tags - <a href="http://www.dzhope.com/tags/iptables/" rel="tag">iptables</a> , <a href="http://www.dzhope.com/tags/ip%25E6%25AE%25B5/" rel="tag">ip段</a>
]]>
</description>
</item><item>
<link>http://www.dzhope.com/post//#blogcomment</link>
<title><![CDATA[[评论] centos禁止ip段和禁止icmp 包]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.dzhope.com/post//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>