<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[刘新修]]></title> 
<link>http://pic1.liuxinxiu.com:80/index.php</link> 
<description><![CDATA[刘新修的个人博客 (Liuxinxiu'S Blog)]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[刘新修]]></copyright>
<item>
<link>http://pic1.liuxinxiu.com:80/SSH-firewall/</link>
<title><![CDATA[SSH使用ROOT更改防火墙，放行80端口]]></title> 
<author>刘新修 &lt;admin@yourname.com&gt;</author>
<category><![CDATA[技术分类]]></category>
<pubDate>Wed, 15 Sep 2010 07:38:09 +0000</pubDate> 
<guid>http://pic1.liuxinxiu.com:80/SSH-firewall/</guid> 
<description>
<![CDATA[ 
	<p><strong><span style="color: #0000ff">Fedora - 13 虚拟机，成功构架了NGINX 使用内网IP无法访问。则防火墙未通过：</span></strong></p><p><strong><span style="color: #0000ff">解决如下：</span></strong></p><p><span style="color: #ff0000"><strong><span>安装路径找到相关防火墙配置文件：</span></strong></span></p><p><strong><span style="color: #0000ff"><font color="#000000">修改<span style="color: #ff0000">/etc/sysconfig/iptables</span> 文件，默认的内容为：</font></span></strong></p><p><span style="color: #0000ff">--------------------------------------------------------------------------------</span></p><p><span style="color: #000000"><span># Firewall configuration written by system-config-firewall<br /># Manual customization of this file is not recommended.<br />*filter<br />:INPUT ACCEPT [0:0]<br />:FORWARD ACCEPT [0:0]<br />:OUTPUT ACCEPT [0:0]<br />-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT<br />-A INPUT -p icmp -j ACCEPT<br />-A INPUT -i lo -j ACCEPT<br />-A INPUT -m state --state NEW -m tcp -p tcp --dport <span>22</span> -j ACCEPT<br /></span><span>-A INPUT -j REJECT --reject-with icmp-host-prohibited<br />-A FORWARD -j REJECT --reject-with icmp-host-prohibited<br />COMMIT</span></span></p><p><span style="color: #000000"><strong><span>复制SSH（22）端口这一行,在以下添加80，更改为以下：</span></strong></span></p><p>&nbsp;</p><p>***************************************************************************</p><p>&nbsp;</p><p><span style="color: #0000ff"># Firewall configuration written by system-config-firewall<br /># Manual customization of this file is not recommended.<br />*filter<br />:INPUT ACCEPT [0:0]<br />:FORWARD ACCEPT [0:0]<br />:OUTPUT ACCEPT [0:0]<br />-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT<br />-A INPUT -p icmp -j ACCEPT<br />-A INPUT -i lo -j ACCEPT<br />-A INPUT -m state --state NEW -m tcp -p tcp --dport <span style="color: #ff0000">22</span> -j ACCEPT<br /></span><strong><span style="color: #000000"><span>-A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT</span></span></strong><span style="color: #339966"><br /></span><span style="color: #0000ff">-A INPUT -j REJECT --reject-with icmp-host-prohibited<br />-A FORWARD -j REJECT --reject-with icmp-host-prohibited<br />COMMIT</span></p><p><span style="color: #0000ff">***************************************************************************</span></p><p>[<strong>chkconfig</strong> ]</p><p>永久性生效，重启后不会复原。 <br />开启： chkconfig iptables on <br />关闭： chkconfig iptables off</p><p>&nbsp;</p><p>[<strong>service</strong> ]<br />即时生效，重启后复原。 <br />开启： service iptables start <br />关闭： service iptables stop</p>
]]>
</description>
</item><item>
<link>http://pic1.liuxinxiu.com:80/SSH-firewall/#blogcomment</link>
<title><![CDATA[[评论] SSH使用ROOT更改防火墙，放行80端口]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://pic1.liuxinxiu.com:80/SSH-firewall/#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>