想做白名单,但是默认的策略是 accept,故自己修改 xml.
改完之后,所有的 IP 都被拦截了,包括明确允许的 IP,请问如何解决?
自定义的配置:
- <zone>
- <short>Public</short>
- <description>
- moren diuqi
- </description>
-
- <target>DROP</target>
-
- <!-- 允许服务 -->
- <service name="ssh"/>
- <service name="dhcpv6-client"/>
-
- <!-- 允许端口 -->
- <port protocol="tcp" port="20"/>
- <port protocol="tcp" port="21"/>
- <port protocol="tcp" port="80"/>
- <port protocol="tcp" port="443"/>
- <port protocol="tcp" port="888"/>
- <port protocol="tcp" port="30655"/>
- <port protocol="tcp" port="5074"/>
- <port protocol="tcp" port="15678"/>
- <port protocol="tcp" port="39000-40000"/>
-
- <!-- 允许IP-->
- <rule family="ipv4">
- <source address="154.40.38.173/32"/>
- <accept/>
- </rule>
- </zone>
复制代码
|
|