#!/bin/sh # iptables 初期化 iptables -F INPUT iptables -F OUTPUT iptables -F FORWARD # 受信を破棄 / 送信を許可 / 通過を拒否 iptables -P INPUT DROP iptables -P OUTPUT ACCEPT iptables -P FORWARD DROP # 自ホストからのアクセスをすべて許可 iptables -A INPUT -i lo -j ACCEPT iptables -A OUTPUT -o lo -j ACCEPT # 内部から行ったアクセスに対する外部からの返答アクセスを許可 iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT # ping(icmp)許可 iptables -I INPUT -
![iptablesの設定【最小構成】 - Qiita](https://cdn-ak-scissors.b.st-hatena.com/image/square/5f4fac3e0212314981370bbf7c33ad49c7b3272c/height=288;version=1;width=512/https%3A%2F%2Fqiita-user-contents.imgix.net%2Fhttps%253A%252F%252Fcdn.qiita.com%252Fassets%252Fpublic%252Farticle-ogp-background-9f5428127621718a910c8b63951390ad.png%3Fixlib%3Drb-4.0.0%26w%3D1200%26mark64%3DaHR0cHM6Ly9xaWl0YS11c2VyLWNvbnRlbnRzLmltZ2l4Lm5ldC9-dGV4dD9peGxpYj1yYi00LjAuMCZ3PTkxNiZoPTMzNiZ0eHQ9aXB0YWJsZXMlRTMlODElQUUlRTglQTglQUQlRTUlQUUlOUElRTMlODAlOTAlRTYlOUMlODAlRTUlQjAlOEYlRTYlQTclOEIlRTYlODglOTAlRTMlODAlOTEmdHh0LWNvbG9yPSUyMzIxMjEyMSZ0eHQtZm9udD1IaXJhZ2lubyUyMFNhbnMlMjBXNiZ0eHQtc2l6ZT01NiZ0eHQtY2xpcD1lbGxpcHNpcyZ0eHQtYWxpZ249bGVmdCUyQ3RvcCZzPTQyYTk5MmVlYzc2MWM0MzQxOTgxOTVjM2RkNDI3MGI0%26mark-x%3D142%26mark-y%3D112%26blend64%3DaHR0cHM6Ly9xaWl0YS11c2VyLWNvbnRlbnRzLmltZ2l4Lm5ldC9-dGV4dD9peGxpYj1yYi00LjAuMCZ3PTYxNiZ0eHQ9JTQwYXNtaW4mdHh0LWNvbG9yPSUyMzIxMjEyMSZ0eHQtZm9udD1IaXJhZ2lubyUyMFNhbnMlMjBXNiZ0eHQtc2l6ZT0zNiZ0eHQtYWxpZ249bGVmdCUyQ3RvcCZzPThiM2ZmODg1NTIwOGJhOTk5NmU4NTVkNmQ2YmEyYTY0%26blend-x%3D142%26blend-y%3D491%26blend-mode%3Dnormal%26s%3Dd754818075331c9c5c0b28215fc6b38f)