如何用Iptables配置CentOS 7服务器仅允许单个指定IP访问?
Hey there! Let's get your CentOS 7 server locked down so only that one specific IP can access it. I'll cover both adjusting your current setup (since you've got 5 IPs allowed right now) and the general step-by-step method for anyone starting fresh.
Before making any changes, it's smart to save your current rules so you can roll back if something goes wrong. Run this command:
iptables-save > /root/iptables_backup_$(date +%Y%m%d).txt
This creates a timestamped backup file in your root directory—easy to find if you need it later.
First, let's see what rules you have right now. Run:
iptables -L -n
You'll see lines like ACCEPT all -- 192.168.1.100 0.0.0.0/0 for each of the 5 allowed IPs. We need to delete those old rules first.
For each of the 5 IPs you no longer want to allow, run:
iptables -D INPUT -s <OLD_IP_ADDRESS> -j ACCEPT
Replace <OLD_IP_ADDRESS> with each of the 5 IPs one by one.
Next, add the rule to allow only your specified IP:
iptables -A INPUT -s <YOUR_ALLOWED_IP> -j ACCEPT
Make sure to swap <YOUR_ALLOWED_IP> with the actual IP you want to grant access to.
Now, we need to add a couple of critical rules to keep your server functioning:
- Allow loopback connections (so the server can talk to itself):
iptables -A INPUT -i lo -j ACCEPT - Allow established/related connections (so you don't get kicked out mid-session if you're configuring this remotely):
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
Finally, set the default policy for incoming traffic to DROP (so any IP not explicitly allowed gets blocked):
iptables -P INPUT DROP
Don't forget to save these changes so they persist after a reboot:
service iptables save # Or alternatively: # iptables-save > /etc/sysconfig/iptables
If you were starting with a clean slate, here's the full workflow:
- Backup current rules (same as Step 1 above)
- Flush all existing rules to start fresh:
iptables -F # Flush all chains iptables -X # Delete all custom chains iptables -Z # Zero out packet/byte counters - Allow loopback connections:
iptables -A INPUT -i lo -j ACCEPT - Allow established/related connections:
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT - Allow your specific IP (you can restrict to specific ports too, like SSH on 22):
- Allow all traffic from the IP:
iptables -A INPUT -s <YOUR_ALLOWED_IP> -j ACCEPT - Or allow only SSH traffic (port 22):
iptables -A INPUT -s <YOUR_ALLOWED_IP> -p tcp --dport 22 -j ACCEPT - Repeat this line for any other ports you need to open (e.g., 80 for HTTP, 443 for HTTPS).
- Allow all traffic from the IP:
- Set default drop policies:
iptables -P INPUT DROP iptables -P FORWARD DROP # Only needed if your server isn't acting as a router - Save and apply the rules:
service iptables save systemctl restart iptables systemctl enable iptables # Ensure iptables starts on boot
- Don't lock yourself out! If you're configuring this over a remote connection (like SSH), make sure you add the rule allowing your IP before setting the default INPUT policy to DROP. Otherwise, you'll lose access immediately.
- Test your setup: After making changes, try accessing the server from the allowed IP and from another IP to confirm the restriction works.
- Restore from backup: If something goes wrong, you can restore your old rules with:
iptables-restore < /root/iptables_backup_YYYYMMDD.txt
内容的提问来源于stack exchange,提问作者Thế Hải Nguyễn

