¸®´ª½º ¹æȺ® Æ÷Æ® Ãß°¡ iptables add port ¹× Æ÷Æ® ¼ø¼ º¯°æ
iptables ¹æȺ® »ç¿ë½Ã ¾Æ·¡¿Í °°ÀÌ Æ÷Æ®¸¦ Ãß°¡ÇÒ¼ö ÀÖ´Ù.
¾Æ·¡ÀÇ ¼ýÀÚ 22´Â Æ÷Æ®¸¦ ÀǹÌÇÑ´Ù.
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
¹æȺ® Æ÷Æ® »èÁ¦´Â ¾Æ·¡¿Í °°ÀÌ °¡´ÉÇÏ´Ù.
iptables -A INPUT -p tcp --dport 22 -j DROP
Æ÷Æ® ´ë¿ªÀ»... °¡·É 10 ~ 20 Æ÷Æ®±îÁö ó¸®ÇÏ°Ú´Ù¸é ¾Æ·¡¿Í °°ÀÌ ÇϸéµÈ´Ù.
¾Æ·¡¿Í °°Àº ¸í·É¾î´Â 10 ~ 20 Æ÷Æ®¸¦ Á¦°ÅÇÏ°Ô µÈ´Ù.
iptables -A INPUT -p tcp --dport 10:20 -j DROP
À§¿Í °°ÀÌ ¼³Á¤ÇßÀ¸³ª... °³¹æµÈ Æ÷Æ®·Î Á¢±ÙÀÌ ¾ÈµÉ°æ¿ì iptables ÀÇ »óŸ¦ È®ÀÎÇغ¸¸é ¾Ë¼öÀÖ´Ù.
# service iptables status
[root@tteongi ~]# service iptables status
Å×À̺í: filter
Chain INPUT (policy ACCEPT)
num target prot opt source destination
1 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
2 ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
3 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
4 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:1234
5 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:8080
6 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
7 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
8 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:3306
³ª´Â À§¿Í °°ÀÌ Ãâ·ÂµÆ´Ù... 6¹ø°ÁÙÀÇ REJECT ´ÙÀ½¿¡ ¿À´Â ¸ðµç Æ÷Æ®´Â °ÅºÎµÈ´Ù... ±×·¯¹Ç·Î ÇØ´ç ¼ø¼¸¦ º¯°æÇØÁÖ¸é ±ò²ûÇØÁø´Ù.
# vi /etc/sysconfig/iptables
À§ÀÇ ¸í·É¾î·Î ¼ø¼¸¦ ¹Ù²ÛÈÄ...
# service iptables restart
iptables ¼ºñ½º¸¦ Àç½ÃÀÛ ÇØÁÖ¸é ÇØ´ç ÇàÀÌ º¯°æµÈ°ÍÀ» È®ÀÎÇÒ¼ö ÀÖ´Ù.