QUOTE:[root@mangle scejia]# iptables -vnL
Chain INPUT (policy DROP 23237 packets, 1762K bytes)
pkts bytes target prot opt in out source destination
337K 121M scrule all -- * * 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy DROP 1 packets, 176 bytes)
pkts bytes target prot opt in out source destination
4080 246K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
137K 10M ACCEPT tcp -- * * 0.0.0.0/0 192.168.88.0/24 tcp dpt:3306
27216 1983K ACCEPT udp -- * * 0.0.0.0/0 192.168.88.0/24 udp dpt:161
341 25840 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:5677
0 0 ACCEPT icmp -- * * 192.168.88.11 192.168.88.11
4 304 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:123
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:25
141 10127 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:53
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:111
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:111
0 0 ACCEPT icmp -- * * 192.168.88.0/24 192.168.88.0/24
173K 198M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
Chain scrule (1 references)
pkts bytes target prot opt in out source destination
9433 481K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3345
2187 155K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:5677
36493 5083K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
23353 4326K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:6455
27 1296 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:21
49246 2717K ACCEPT tcp -- * * 192.168.88.0/24 0.0.0.0/0 tcp dpt:873
0 0 ACCEPT tcp -- eth0 * 192.168.88.0/24 0.0.0.0/0 tcp dpt:111
0 0 ACCEPT tcp -- eth0 * 192.168.88.0/24 0.0.0.0/0 tcp dpt:793
1835 226K ACCEPT tcp -- eth0 * 192.168.88.0/24 0.0.0.0/0 tcp dpt:2049
0 0 ACCEPT udp -- eth0 * 192.168.88.0/24 0.0.0.0/0 udp dpt:111
0 0 ACCEPT udp -- eth0 * 192.168.88.0/24 0.0.0.0/0 udp dpt:2049
0 0 ACCEPT udp -- eth0 * 192.168.88.0/24 0.0.0.0/0 udp dpt:790
0 0 ACCEPT udp -- eth0 * 192.168.88.0/24 0.0.0.0/0 udp dpt:33288
6918 14M ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT icmp -- * * 192.168.88.0/24 192.168.88.0/24
184K 92M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
这是我防火墙规则