You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linux防火墙配置求助:添加DNS规则失败,需实现指定访问控制策略

防火墙规则配置方案(iptables)

Hey there! Let's build the firewall rules you need step by step. Since you're working through How Linux Works, I'll use iptables (the most common beginner-friendly firewall tool on Linux) to match your goal: block all incoming connections initiated from outside, while letting your system send DNS queries and browse the web freely.

Step 1: Reset Existing Rules

First, clear any existing rules to start fresh (this avoids conflicts with old settings):

sudo iptables -F
sudo iptables -X
sudo iptables -Z

Step 2: Set Default Policies

We'll set strict default rules, then open only what we need:

  • Drop all incoming traffic by default (blocks external-initiated connections like SSH, incoming ICMP/pings)
  • Drop all outgoing traffic by default (we'll explicitly allow only what we need, making the setup more secure)
  • Drop all forwarded traffic (you mentioned local servers don't matter, so we don't need this)
sudo iptables -P INPUT DROP
sudo iptables -P OUTPUT DROP
sudo iptables -P FORWARD DROP

Step 3: Allow Local Loopback Traffic

Your system needs to communicate with itself (e.g., local apps connecting to localhost), so we must allow the loopback interface:

sudo iptables -A INPUT -i lo -j ACCEPT
sudo iptables -A OUTPUT -o lo -j ACCEPT

Step 4: Allow Response Traffic for Your Outgoing Requests

When you send a DNS query or browse a website, the external server sends a response back. We need to allow these "related/established" connections (they're not initiated from outside—they're replies to your requests):

sudo iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT

Step 5: Allow DNS Queries

DNS uses both UDP (standard for most queries) and TCP (for large queries like zone transfers). We'll allow outgoing traffic to DNS ports (53):

# Allow UDP DNS requests (most common)
sudo iptables -A OUTPUT -p udp --dport 53 -j ACCEPT
# Allow TCP DNS requests (for large payloads)
sudo iptables -A OUTPUT -p tcp --dport 53 -j ACCEPT

For curl, wget, and regular web browsing, we need to allow outgoing traffic to HTTP (port 80) and HTTPS (port 443). If you use telnet to test external ports, we'll add that too:

# Allow HTTP (port 80) outgoing
sudo iptables -A OUTPUT -p tcp --dport 80 -j ACCEPT
# Allow HTTPS (port 443) outgoing
sudo iptables -A OUTPUT -p tcp --dport 443 -j ACCEPT
# Allow telnet outgoing (if you use it to test ports like 80/443)
sudo iptables -A OUTPUT -p tcp --dport 23 -j ACCEPT
# Alternatively, if you want to allow telnet to specific ports only (e.g., 80 and 443):
# sudo iptables -A OUTPUT -p tcp -m multiport --dports 23,80,443 -j ACCEPT

Verify the Rules

Check that your rules are set correctly with:

sudo iptables -L -v

Save the Rules (Important!)

If you're using a system with iptables-persistent (common on Debian/Ubuntu), save your rules so they survive a reboot:

sudo netfilter-persistent save

On RHEL/CentOS systems, use:

sudo service iptables save

Why Your Previous DNS Rules Might Have Failed

A common mistake is forgetting to allow the related/established incoming traffic—without that, the DNS server's response can't get back to your system. Another issue is blocking outgoing UDP/TCP port 53 entirely, or mixing up source/destination ports (DNS queries send to destination port 53, not source).


内容的提问来源于stack exchange,提问作者user10089632

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:40:49