iptables -F
iptables -X
iptables -Z
iptables -L -n -v -x
加載ip_nat_ftp ,ip_conntrack_ftp模塊
iptables -A INPUT -d 192.168.137.3 -p tcp --dport 21 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -s 192.168.137.3 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -d 10.0.0.3 -limit --limit 50/second --limit-burst 5 -j ACCEPT
iptables -A OUTPUT -s 192.168.137.3 -m multiport --destination 21,22,80 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
iptables -I OUTPUT -s 192.168.137.3 -m string --algo kmp --string "h7ng" -j REJECT
iptables -I INPUT -d 192.168.137.3 -p tcp --dport 22 -m connlimit-above 6 -j DROP
iptables -I INPUT -p -tcp --dport 22 -m state --state NEW -m recent --set --name SSH
iptables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 300 --hitcount 3 --name SSH -j DROP