命令修改iptables后重启会丢失。持久化文件在:
1 2
| /etc/iptables/rules.v4 /etc/iptables/rules.v6
AWK
|
存储和恢复命令:
1 2 3 4 5 6 7 8 9 10 11 12
| netfilter-persistent save netfilter-persistent start
iptables-save > /etc/iptables/rules.v4 ip6tables-save > /etc/iptables/rules.v6
iptables-restore < /etc/iptables/rules.v4 ip6tables-restore < /etc/iptables/rules.v6
systemctl stop netfilter-persistent systemctl start netfilter-persistent systemctl restart netfilter-persistent
SMALI
|
比如我的rules.v4长这样:
1 2 3 4 5 6 7 8 9 10 11
| root@hecs-301353:/etc/iptables# cat rules.v4.bak # Generated by iptables-save v1.8.7 on Wed Jan 4 20:32:54 2023 *nat :PREROUTING ACCEPT [0:0] :INPUT ACCEPT [0:0] :OUTPUT ACCEPT [0:0] :POSTROUTING ACCEPT [0:0] -A PREROUTING -d 192.168.0.163/32 -p tcp -m tcp --dport 27896 -j DNAT --to-destination 192.168.0.121:27896 -A POSTROUTING -d 192.168.0.121/32 -p tcp -m tcp --dport 27896 -j SNAT --to-source 192.168.0.163 COMMIT # Completed on Wed Jan 4 20:32:54 2023
ASCIIDOC
|