如何阻止VPS通过sshd连接至其他VPS/IP/443端口?已尝试规则无效
Hey Andrew, let's break down why your current iptables/firewalld rules aren't working and get this fixed properly.
The Core Problem with Your Existing Rules
Your rules are using -s 1.1.1.1 (source IP) in the OUTPUT chain, but when your VPS initiates an outgoing connection to 1.1.1.1:443, your VPS's own IP is the source, and 1.1.1.1 is the destination. So you need to use -d 1.1.1.1 instead of -s for outgoing blocks. Additionally:
- The
INPUTchain handles incoming traffic (not outgoing), so those rules are irrelevant to your goal. - The
FORWARDchain only applies if your VPS is acting as a router (which it probably isn't), so those rules do nothing here.
Correct iptables Rules
Choose the rule that fits your exact needs:
1. Block only SSHD from initiating any outgoing TCP 443 connections
This uses the owner module to target the sshd user/process specifically:
# Add rule to reject SSHD's outgoing 443 connections iptables -A OUTPUT -p tcp --dport 443 -m owner --uid-owner sshd -j REJECT --reject-with tcp-reset
2. Block SSHD from initiating outgoing 443 connections to a specific IP (e.g., 1.1.1.1)
If you only want to block connections to one target IP, add the -d parameter:
iptables -A OUTPUT -p tcp -d 1.1.1.1 --dport 443 -m owner --uid-owner sshd -j REJECT --reject-with tcp-reset
3. Block your entire VPS from initiating outgoing 443 connections to a specific IP
If you don't need to limit it to SSHD and want to block all outgoing 443 traffic to that IP:
iptables -A OUTPUT -p tcp -d 1.1.1.1 --dport 443 -j REJECT --reject-with tcp-reset
Correct firewalld Rules
If you prefer using firewalld instead of raw iptables, use these direct rules (targeting the OUTPUT chain correctly):
Block all outgoing 443 connections to 1.1.1.1
# Add temporary rule firewall-cmd --direct --add-rule ipv4 filter OUTPUT 0 -p tcp -d 1.1.1.1 --dport 443 -j REJECT --reject-with tcp-reset # Make it permanent (requires reload) firewall-cmd --permanent --direct --add-rule ipv4 filter OUTPUT 0 -p tcp -d 1.1.1.1 --dport 443 -j REJECT --reject-with tcp-reset firewall-cmd --reload
Block only SSHD's outgoing 443 connections via firewalld
firewall-cmd --direct --add-rule ipv4 filter OUTPUT 0 -p tcp --dport 443 -m owner --uid-owner sshd -j REJECT --reject-with tcp-reset # Add --permanent and reload if you want it to persist after reboot
How to Verify the Rules Work
- Check that your rules are active in the OUTPUT chain:
iptables -L OUTPUT -n -v - Test if you can still reach the target IP's 443 port (this should fail):
curl https://1.1.1.1 -v
内容的提问来源于stack exchange,提问作者Andrew Jetun

