You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Iptables配置CentOS 7服务器仅允许单个指定IP访问?

Hey there! Let's get your CentOS 7 server locked down so only that one specific IP can access it. I'll cover both adjusting your current setup (since you've got 5 IPs allowed right now) and the general step-by-step method for anyone starting fresh.

Step 1: First, Backup Your Current Iptables Config

Before making any changes, it's smart to save your current rules so you can roll back if something goes wrong. Run this command:

iptables-save > /root/iptables_backup_$(date +%Y%m%d).txt

This creates a timestamped backup file in your root directory—easy to find if you need it later.

Step 2: Adjust Your Existing Setup (From 5 Allowed IPs to One)

First, let's see what rules you have right now. Run:

iptables -L -n

You'll see lines like ACCEPT all -- 192.168.1.100 0.0.0.0/0 for each of the 5 allowed IPs. We need to delete those old rules first.

For each of the 5 IPs you no longer want to allow, run:

iptables -D INPUT -s <OLD_IP_ADDRESS> -j ACCEPT

Replace <OLD_IP_ADDRESS> with each of the 5 IPs one by one.

Next, add the rule to allow only your specified IP:

iptables -A INPUT -s <YOUR_ALLOWED_IP> -j ACCEPT

Make sure to swap <YOUR_ALLOWED_IP> with the actual IP you want to grant access to.

Now, we need to add a couple of critical rules to keep your server functioning:

  • Allow loopback connections (so the server can talk to itself):
    iptables -A INPUT -i lo -j ACCEPT
    
  • Allow established/related connections (so you don't get kicked out mid-session if you're configuring this remotely):
    iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
    

Finally, set the default policy for incoming traffic to DROP (so any IP not explicitly allowed gets blocked):

iptables -P INPUT DROP

Don't forget to save these changes so they persist after a reboot:

service iptables save
# Or alternatively:
# iptables-save > /etc/sysconfig/iptables
General Method: Lock Down to a Single IP from Scratch

If you were starting with a clean slate, here's the full workflow:

  1. Backup current rules (same as Step 1 above)
  2. Flush all existing rules to start fresh:
    iptables -F  # Flush all chains
    iptables -X  # Delete all custom chains
    iptables -Z  # Zero out packet/byte counters
    
  3. Allow loopback connections:
    iptables -A INPUT -i lo -j ACCEPT
    
  4. Allow established/related connections:
    iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
    
  5. Allow your specific IP (you can restrict to specific ports too, like SSH on 22):
    • Allow all traffic from the IP:
      iptables -A INPUT -s <YOUR_ALLOWED_IP> -j ACCEPT
      
    • Or allow only SSH traffic (port 22):
      iptables -A INPUT -s <YOUR_ALLOWED_IP> -p tcp --dport 22 -j ACCEPT
      
    • Repeat this line for any other ports you need to open (e.g., 80 for HTTP, 443 for HTTPS).
  6. Set default drop policies:
    iptables -P INPUT DROP
    iptables -P FORWARD DROP  # Only needed if your server isn't acting as a router
    
  7. Save and apply the rules:
    service iptables save
    systemctl restart iptables
    systemctl enable iptables  # Ensure iptables starts on boot
    
Important Notes
  • Don't lock yourself out! If you're configuring this over a remote connection (like SSH), make sure you add the rule allowing your IP before setting the default INPUT policy to DROP. Otherwise, you'll lose access immediately.
  • Test your setup: After making changes, try accessing the server from the allowed IP and from another IP to confirm the restriction works.
  • Restore from backup: If something goes wrong, you can restore your old rules with:
    iptables-restore < /root/iptables_backup_YYYYMMDD.txt
    

内容的提问来源于stack exchange,提问作者Thế Hải Nguyễn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 04:24:38