<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[静怡家园]]></title> 
<link>http://www.zhanghaijun.com/index.php</link> 
<description><![CDATA[书山有路勤为径，学海无涯苦作舟！]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[静怡家园]]></copyright>
<item>
<link>http://www.zhanghaijun.com/post//</link>
<title><![CDATA[iptables使用multiport 添加多个不连续端口]]></title> 
<author>碟舞飞扬 &lt;webmaster@zhanghaijun.com&gt;</author>
<category><![CDATA[Linux技术]]></category>
<pubDate>Mon, 16 May 2011 17:26:08 +0000</pubDate> 
<guid>http://www.zhanghaijun.com/post//</guid> 
<description>
<![CDATA[ 
	使用multiport可以添加多个不连接的端口，最多可以添加15组，如下：<br/> <br/>iptables -A INPUT -p tcp -m multiport --dports 21:25,135:139 -j DROP<br/>iptables -A INPUT -p tcp -m multiport --dports 110,80,25,445,1863,5222 -j ACCEPT<br/>iptables -A INPUT -i eth0 -p tcp -m multiport --dports 22,80,443 -m state --state NEW,ESTABLISHED -j ACCEPT<br/>iptables -A OUTPUT -o eth0 -p tcp -m multiport --sports 22,80,443 -m state --state ESTABLISHED -j ACCEPT<br/> <br/>如果不使用multiport参数，只能是添加连续的端口。<br/> <br/>如:<br/>iptables -A INPUT -p tcp –dport 21:25 -j DROP<br/> <br/>而不能写成21:25,135:139<br/>Tags - <a href="http://www.zhanghaijun.com/tags/iptables/" rel="tag">iptables</a> , <a href="http://www.zhanghaijun.com/tags/multiport/" rel="tag">multiport</a>
]]>
</description>
</item><item>
<link>http://www.zhanghaijun.com/post//#blogcomment</link>
<title><![CDATA[[评论] iptables使用multiport 添加多个不连续端口]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.zhanghaijun.com/post//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>