You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何阻止VPS通过sshd连接至其他VPS/IP/443端口?已尝试规则无效

How to Block Your VPS's SSHD from Initiating Outgoing 443 Connections

Hey Andrew, let's break down why your current iptables/firewalld rules aren't working and get this fixed properly.

The Core Problem with Your Existing Rules

Your rules are using -s 1.1.1.1 (source IP) in the OUTPUT chain, but when your VPS initiates an outgoing connection to 1.1.1.1:443, your VPS's own IP is the source, and 1.1.1.1 is the destination. So you need to use -d 1.1.1.1 instead of -s for outgoing blocks. Additionally:

  • The INPUT chain handles incoming traffic (not outgoing), so those rules are irrelevant to your goal.
  • The FORWARD chain only applies if your VPS is acting as a router (which it probably isn't), so those rules do nothing here.

Correct iptables Rules

Choose the rule that fits your exact needs:

1. Block only SSHD from initiating any outgoing TCP 443 connections

This uses the owner module to target the sshd user/process specifically:

# Add rule to reject SSHD's outgoing 443 connections
iptables -A OUTPUT -p tcp --dport 443 -m owner --uid-owner sshd -j REJECT --reject-with tcp-reset

2. Block SSHD from initiating outgoing 443 connections to a specific IP (e.g., 1.1.1.1)

If you only want to block connections to one target IP, add the -d parameter:

iptables -A OUTPUT -p tcp -d 1.1.1.1 --dport 443 -m owner --uid-owner sshd -j REJECT --reject-with tcp-reset

3. Block your entire VPS from initiating outgoing 443 connections to a specific IP

If you don't need to limit it to SSHD and want to block all outgoing 443 traffic to that IP:

iptables -A OUTPUT -p tcp -d 1.1.1.1 --dport 443 -j REJECT --reject-with tcp-reset

Correct firewalld Rules

If you prefer using firewalld instead of raw iptables, use these direct rules (targeting the OUTPUT chain correctly):

Block all outgoing 443 connections to 1.1.1.1

# Add temporary rule
firewall-cmd --direct --add-rule ipv4 filter OUTPUT 0 -p tcp -d 1.1.1.1 --dport 443 -j REJECT --reject-with tcp-reset

# Make it permanent (requires reload)
firewall-cmd --permanent --direct --add-rule ipv4 filter OUTPUT 0 -p tcp -d 1.1.1.1 --dport 443 -j REJECT --reject-with tcp-reset
firewall-cmd --reload

Block only SSHD's outgoing 443 connections via firewalld

firewall-cmd --direct --add-rule ipv4 filter OUTPUT 0 -p tcp --dport 443 -m owner --uid-owner sshd -j REJECT --reject-with tcp-reset
# Add --permanent and reload if you want it to persist after reboot

How to Verify the Rules Work

  1. Check that your rules are active in the OUTPUT chain:
    iptables -L OUTPUT -n -v
    
  2. Test if you can still reach the target IP's 443 port (this should fail):
    curl https://1.1.1.1 -v
    

内容的提问来源于stack exchange,提问作者Andrew Jetun

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:15:42