Linux防火墙配置求助:添加DNS规则失败,需实现指定访问控制策略
Hey there! Let's build the firewall rules you need step by step. Since you're working through How Linux Works, I'll use iptables (the most common beginner-friendly firewall tool on Linux) to match your goal: block all incoming connections initiated from outside, while letting your system send DNS queries and browse the web freely.
Step 1: Reset Existing Rules
First, clear any existing rules to start fresh (this avoids conflicts with old settings):
sudo iptables -F sudo iptables -X sudo iptables -Z
Step 2: Set Default Policies
We'll set strict default rules, then open only what we need:
- Drop all incoming traffic by default (blocks external-initiated connections like SSH, incoming ICMP/pings)
- Drop all outgoing traffic by default (we'll explicitly allow only what we need, making the setup more secure)
- Drop all forwarded traffic (you mentioned local servers don't matter, so we don't need this)
sudo iptables -P INPUT DROP sudo iptables -P OUTPUT DROP sudo iptables -P FORWARD DROP
Step 3: Allow Local Loopback Traffic
Your system needs to communicate with itself (e.g., local apps connecting to localhost), so we must allow the loopback interface:
sudo iptables -A INPUT -i lo -j ACCEPT sudo iptables -A OUTPUT -o lo -j ACCEPT
Step 4: Allow Response Traffic for Your Outgoing Requests
When you send a DNS query or browse a website, the external server sends a response back. We need to allow these "related/established" connections (they're not initiated from outside—they're replies to your requests):
sudo iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
Step 5: Allow DNS Queries
DNS uses both UDP (standard for most queries) and TCP (for large queries like zone transfers). We'll allow outgoing traffic to DNS ports (53):
# Allow UDP DNS requests (most common) sudo iptables -A OUTPUT -p udp --dport 53 -j ACCEPT # Allow TCP DNS requests (for large payloads) sudo iptables -A OUTPUT -p tcp --dport 53 -j ACCEPT
Step 6: Allow Web Browsing & Related Tools
For curl, wget, and regular web browsing, we need to allow outgoing traffic to HTTP (port 80) and HTTPS (port 443). If you use telnet to test external ports, we'll add that too:
# Allow HTTP (port 80) outgoing sudo iptables -A OUTPUT -p tcp --dport 80 -j ACCEPT # Allow HTTPS (port 443) outgoing sudo iptables -A OUTPUT -p tcp --dport 443 -j ACCEPT # Allow telnet outgoing (if you use it to test ports like 80/443) sudo iptables -A OUTPUT -p tcp --dport 23 -j ACCEPT # Alternatively, if you want to allow telnet to specific ports only (e.g., 80 and 443): # sudo iptables -A OUTPUT -p tcp -m multiport --dports 23,80,443 -j ACCEPT
Verify the Rules
Check that your rules are set correctly with:
sudo iptables -L -v
Save the Rules (Important!)
If you're using a system with iptables-persistent (common on Debian/Ubuntu), save your rules so they survive a reboot:
sudo netfilter-persistent save
On RHEL/CentOS systems, use:
sudo service iptables save
Why Your Previous DNS Rules Might Have Failed
A common mistake is forgetting to allow the related/established incoming traffic—without that, the DNS server's response can't get back to your system. Another issue is blocking outgoing UDP/TCP port 53 entirely, or mixing up source/destination ports (DNS queries send to destination port 53, not source).
内容的提问来源于stack exchange,提问作者user10089632

