# 允许流量通过的端口 for port in"${ports_to_allow[@]}"; do iptables -A INPUT -p tcp --dport $port -j ACCEPT iptables -A OUTPUT -p tcp --sport $port -j ACCEPT done
# 关闭的端口 for port in"${ports_to_close[@]}"; do iptables -A INPUT -p tcp --dport $port -j DROP iptables -A OUTPUT -p tcp --sport $port -j DROP done
# 保存iptables规则(redhat系统) service iptables save # 或 iptables-save > /etc/sysconfig/iptables
# (debian系统) # sudo sh -c "iptables-save > /etc/iptables/rules.v4"