Ci-dessous, les différences entre deux révisions de la page.
| — |
ip6tables [18/09/2016 02:54] (Version actuelle) |
||
|---|---|---|---|
| Ligne 1: | Ligne 1: | ||
| + | ====== IP6Tables ====== | ||
| + | ===== Règles de base ===== | ||
| + | # Default policy | ||
| + | ip6tables -P INPUT DROP | ||
| + | ip6tables -P FORWARD DROP | ||
| + | ip6tables -P OUTPUT ACCEPT | ||
| + | | ||
| + | ip6tables -A INPUT -i lo -j ACCEPT | ||
| + | ip6tables -A INPUT -p tcp --dport PortSSH -j ACCEPT | ||
| + | ip6tables -A INPUT -m conntrack --ctstate RELATED, | ||
| + | ip6tables -A INPUT -p icmpv6 --icmpv6-type 0 -j ACCEPT | ||
| + | ip6tables -A INPUT -p icmpv6 --icmpv6-type 8 -j ACCEPT | ||
| + | ip6tables -A INPUT -j DROP | ||
| + | |||
| + | ===== Reset ===== | ||
| + | ip6tables -F | ||
| + | ip6tables -X | ||
| + | ip6tables -t nat -F | ||
| + | ip6tables -t nat -X | ||
| + | ip6tables -t mangle -F | ||
| + | ip6tables -t mangle -X | ||