rc_00_fi.{__

来自「grub安装实例教你怎样安装GRUB以及使用在红帽中遇到的问题!」· {__ 代码 · 共 60 行

{__
60
字号
#!/bin/shPATH=/sbin:/bin:/usr/sbin:/usr/binexit 0 ;. /etc/rc.d/rc.functions. /etc/firewall.confecho -n "Starting basic firewall: "# set up spoofing protection# taken from IPCHAINS-HOWTOfor f in /proc/sys/net/ipv4/conf/*/rp_filterdo  echo 1 > $fdone# log impossible addressesfor f in /proc/sys/net/ipv4/conf/*/log_martiansdo  echo 1 > $fdone# default setting: deny everythingipchains -F inputipchains -P input DENYipchains -F outputipchains -P output DENY# allow all non-external interfaces for everythingipchains -A input  -i ! $EXT -j ACCEPTipchains -A output -i ! $EXT -j ACCEPT# external interface  # icmp incoming  ipchains -A input -i $EXT -p icmp -s 0/0 echo-request -j DENY  ipchains -A input -i $EXT -p icmp -j ACCEPT  # tcp incoming  if [ "$ALLOW_HTTP" = "yes" ]; then    ipchains -A input -i $EXT -p tcp -d 0/0 http     -j ACCEPT  fi  if [ "$ALLOW_TELNET" = "yes" ]; then    ipchains -A input -i $EXT -p tcp -d 0/0 telnet   -j ACCEPT  fi  ipchains -A input -i $EXT -p tcp -d 0/0 ftp-data   -j ACCEPT  ipchains -A input -i $EXT -p tcp -d 0/0 auth       -j REJECT  ipchains -A input -i $EXT -p tcp -d 0/0 6000:6010  -j DENY  ipchains -A input -i $EXT -p tcp -d 0/0 1024:65535 -j ACCEPT  # udp incoming  ipchains -A input -i $EXT -p udp -d 0/0 1024:65535 -j ACCEPT  # all protocols outgoing  ipchains -A output -i $EXT -j ACCEPTcheck_status

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?