{"id":918,"date":"2026-09-17T23:42:28","date_gmt":"2026-09-17T20:42:28","guid":{"rendered":"https:\/\/imaxis.ru\/?p=918"},"modified":"2026-09-18T00:05:51","modified_gmt":"2026-09-17T21:05:51","slug":"nastroyka-netfilter-s-pomoschyu-iptables-shpargalka-i-primery","status":"publish","type":"post","link":"https:\/\/imaxis.ru\/?p=918","title":{"rendered":"\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 netfilter \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e iptables: \u0448\u043f\u0430\u0440\u0433\u0430\u043b\u043a\u0430 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440\u044b"},"content":{"rendered":"<h1>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 netfilter \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e iptables: \u0448\u043f\u0430\u0440\u0433\u0430\u043b\u043a\u0430 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440\u044b<\/h1>\n<p><code>iptables<\/code> \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u0442 \u0431\u0440\u0430\u043d\u0434\u043c\u0430\u0443\u044d\u0440 netfilter \u0432 \u044f\u0434\u0440\u0435 Linux. \u0421\u0442\u0430\u0442\u044c\u044f \u043f\u043e\u0434\u043e\u0439\u0434\u0451\u0442 \u0438 \u043d\u043e\u0432\u0438\u0447\u043a\u0430\u043c \u0434\u043b\u044f \u043f\u043e\u043d\u0438\u043c\u0430\u043d\u0438\u044f \u043f\u0440\u0438\u043d\u0446\u0438\u043f\u043e\u0432, \u0438 \u043e\u043f\u044b\u0442\u043d\u044b\u043c \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0430\u043c \u043a\u0430\u043a \u0448\u043f\u0430\u0440\u0433\u0430\u043b\u043a\u0430.<\/p>\n<blockquote>\n<p>\u0412 \u043d\u043e\u0432\u044b\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 <code>iptables<\/code> \u0447\u0430\u0441\u0442\u043e \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0444\u0440\u043e\u043d\u0442\u0435\u043d\u0434\u043e\u043c \u043d\u0430\u0434 <code>nftables<\/code>. \u0421\u0438\u043d\u0442\u0430\u043a\u0441\u0438\u0441 \u0441\u043e\u0445\u0440\u0430\u043d\u044f\u0435\u0442\u0441\u044f, \u043d\u043e \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0439\u0442\u0435 \u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0439 \u0431\u044d\u043a\u0435\u043d\u0434 \u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0439 <code>iptables -V<\/code> \u0438 <code>nft list ruleset<\/code>.<\/p>\n<\/blockquote>\n<hr \/>\n<h2>\u041f\u0440\u0438\u043d\u0446\u0438\u043f \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438<\/h2>\n<p>\u041e\u0431\u0449\u0438\u0439 \u0441\u0438\u043d\u0442\u0430\u043a\u0441\u0438\u0441:<\/p>\n<pre><code>iptables -t &lt;\u0442\u0430\u0431\u043b\u0438\u0446\u0430&gt; &lt;\u043a\u043e\u043c\u0430\u043d\u0434\u0430&gt; &lt;\u0446\u0435\u043f\u043e\u0447\u043a\u0430&gt; [\u043d\u043e\u043c\u0435\u0440] &lt;\u0443\u0441\u043b\u043e\u0432\u0438\u0435&gt; -j &lt;\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435&gt;\n<\/code><\/pre>\n<ul>\n<li><strong><code>&lt;\u0442\u0430\u0431\u043b\u0438\u0446\u0430&gt;<\/code><\/strong> \u2014 \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u043a\u043b\u044e\u0447\u043e\u043c <code>-t<\/code>; \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e <code>filter<\/code>.<\/li>\n<li><strong><code>&lt;\u043a\u043e\u043c\u0430\u043d\u0434\u0430&gt;<\/code><\/strong> \u2014 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435 \u043d\u0430\u0434 \u043f\u0440\u0430\u0432\u0438\u043b\u043e\u043c (\u0441\u043e\u0437\u0434\u0430\u0442\u044c, \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u0438 \u0442. \u0434.).<\/li>\n<li><strong><code>&lt;\u0446\u0435\u043f\u043e\u0447\u043a\u0430&gt;<\/code><\/strong> \u2014 \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, <code>INPUT<\/code>, <code>OUTPUT<\/code>, <code>FORWARD<\/code>.<\/li>\n<li><strong><code>[\u043d\u043e\u043c\u0435\u0440]<\/code><\/strong> \u2014 \u0434\u043b\u044f \u043a\u043e\u043c\u0430\u043d\u0434, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0445 \u0441 \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u044b\u043c \u043f\u0440\u0430\u0432\u0438\u043b\u043e\u043c.<\/li>\n<li><strong><code>&lt;\u0443\u0441\u043b\u043e\u0432\u0438\u0435&gt;<\/code><\/strong> \u2014 \u043a\u0440\u0438\u0442\u0435\u0440\u0438\u0438 \u0441\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u043d\u0438\u044f.<\/li>\n<li><strong><code>&lt;\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435&gt;<\/code><\/strong> \u2014 \u0447\u0442\u043e \u0434\u0435\u043b\u0430\u0442\u044c \u0441 \u043f\u0430\u043a\u0435\u0442\u043e\u043c.<\/li>\n<\/ul>\n<p><strong>\u041a\u043b\u044e\u0447 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u043d\u0435 \u043e\u0431\u044f\u0437\u0430\u043d \u0431\u044b\u0442\u044c \u0432 \u043a\u043e\u043d\u0446\u0435, \u043d\u043e \u0442\u0430\u043a\u043e\u0439 \u043f\u043e\u0440\u044f\u0434\u043e\u043a \u0447\u0438\u0442\u0430\u0435\u043c\u0435\u0435.<\/strong><\/p>\n<hr \/>\n<h2>\u041a\u043b\u044e\u0447\u0438 iptables<\/h2>\n<h3>\u0422\u0430\u0431\u043b\u0438\u0446\u044b (<code>-t<\/code>)<\/h3>\n<table>\n<thead>\n<tr>\n<th>\u041a\u043b\u044e\u0447<\/th>\n<th>\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>-t filter<\/code><\/td>\n<td>\u0422\u0430\u0431\u043b\u0438\u0446\u0430 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e. \u0426\u0435\u043f\u043e\u0447\u043a\u0438: <code>INPUT<\/code> (\u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0435), <code>OUTPUT<\/code> (\u0438\u0441\u0445\u043e\u0434\u044f\u0449\u0438\u0435), <code>FORWARD<\/code> (\u0442\u0440\u0430\u043d\u0437\u0438\u0442\u043d\u044b\u0435)<\/td>\n<\/tr>\n<tr>\n<td><code>-t nat<\/code><\/td>\n<td>\u0414\u043b\u044f \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0449\u0438\u0445 \u043d\u043e\u0432\u043e\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u043e\u0432. \u0426\u0435\u043f\u043e\u0447\u043a\u0438: <code>PREROUTING<\/code>, <code>OUTPUT<\/code>, <code>POSTROUTING<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-t mangle<\/code><\/td>\n<td>\u0414\u043b\u044f \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u043f\u0430\u043a\u0435\u0442\u043e\u0432. \u0426\u0435\u043f\u043e\u0447\u043a\u0438: <code>INPUT<\/code>, <code>OUTPUT<\/code>, <code>FORWARD<\/code>, <code>PREROUTING<\/code>, <code>POSTROUTING<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-t raw<\/code><\/td>\n<td>\u0418\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0432 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439. \u0426\u0435\u043f\u043e\u0447\u043a\u0438: <code>PREROUTING<\/code>, <code>OUTPUT<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>\u041a\u043e\u043c\u0430\u043d\u0434\u044b<\/h3>\n<table>\n<thead>\n<tr>\n<th>\u041a\u043b\u044e\u0447<\/th>\n<th>\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>-A<\/code><\/td>\n<td>\u0414\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0432 \u043a\u043e\u043d\u0435\u0446: <code>iptables -A INPUT -s 192.168.0.15 -j DROP<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-D<\/code><\/td>\n<td>\u0423\u0434\u0430\u043b\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u043e: <code>iptables -D INPUT 10<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-I<\/code><\/td>\n<td>\u0412\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u043e: <code>iptables -I INPUT 5 -s 192.168.0.15 -j DROP<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-R<\/code><\/td>\n<td>\u0417\u0430\u043c\u0435\u043d\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u043e: <code>iptables -R OUTPUT 5 -s 192.168.0.15 -j ACCEPT<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-F<\/code><\/td>\n<td>\u0421\u0431\u0440\u043e\u0441\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0446\u0435\u043f\u043e\u0447\u043a\u0438: <code>iptables -F INPUT<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-Z<\/code><\/td>\n<td>\u041e\u0431\u043d\u0443\u043b\u0438\u0442\u044c \u0441\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0443: <code>iptables -Z INPUT<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-N<\/code><\/td>\n<td>\u0421\u043e\u0437\u0434\u0430\u0442\u044c \u0446\u0435\u043f\u043e\u0447\u043a\u0443: <code>iptables -N CHAINNEW<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-X<\/code><\/td>\n<td>\u0423\u0434\u0430\u043b\u0438\u0442\u044c \u0446\u0435\u043f\u043e\u0447\u043a\u0443: <code>iptables -X CHAINNEW<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-P<\/code><\/td>\n<td>\u041f\u043e\u043b\u0438\u0442\u0438\u043a\u0430 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e: <code>iptables -P INPUT DROP<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-E<\/code><\/td>\n<td>\u041f\u0435\u0440\u0435\u0438\u043c\u0435\u043d\u043e\u0432\u0430\u0442\u044c \u0446\u0435\u043f\u043e\u0447\u043a\u0443: <code>iptables -E CHAINNEW CHAINOLD<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>\u0423\u0441\u043b\u043e\u0432\u0438\u044f<\/h3>\n<table>\n<thead>\n<tr>\n<th>\u041a\u043b\u044e\u0447<\/th>\n<th>\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>-p<\/code><\/td>\n<td>\u041f\u0440\u043e\u0442\u043e\u043a\u043e\u043b (<code>tcp<\/code>, <code>udp<\/code>, <code>icmp<\/code>, <code>all<\/code>): <code>iptables -A INPUT -p tcp -j ACCEPT<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-s<\/code><\/td>\n<td>\u0418\u0441\u0442\u043e\u0447\u043d\u0438\u043a (\u0445\u043e\u0441\u0442, IP, CIDR): <code>iptables -A INPUT -s 192.168.0.50 -j DROP<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-d<\/code><\/td>\n<td>\u041d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435: <code>iptables -A OUTPUT -d 192.168.0.50 -j DROP<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-i<\/code><\/td>\n<td>\u0412\u0445\u043e\u0434\u044f\u0449\u0438\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441: <code>iptables -A INPUT -i eth2 -j DROP<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>-o<\/code><\/td>\n<td>\u0418\u0441\u0445\u043e\u0434\u044f\u0449\u0438\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441: <code>iptables -A OUTPUT -o eth3 -j ACCEPT<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>--dport<\/code><\/td>\n<td>\u041f\u043e\u0440\u0442 \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f: <code>iptables -A INPUT -p tcp --dport 80 -j ACCEPT<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>--sport<\/code><\/td>\n<td>\u041f\u043e\u0440\u0442 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0430: <code>iptables -A INPUT -p tcp --sport 1023 -j DROP<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>\u0418\u043d\u0432\u0435\u0440\u0441\u0438\u044f \u0447\u0435\u0440\u0435\u0437 <code>!<\/code>:<\/strong><\/p>\n<pre><code>iptables -A INPUT -s ! 192.168.0.50 -j DROP\n<\/code><\/pre>\n<p><strong>\u0417\u0430\u043f\u0440\u0435\u0442\u0438\u0442 \u0432\u0441\u0435\u0445, \u043a\u0440\u043e\u043c\u0435 <code>192.168.0.50<\/code>.<\/strong><\/p>\n<h3>\u0414\u0435\u0439\u0441\u0442\u0432\u0438\u044f (<code>-j<\/code>)<\/h3>\n<table>\n<thead>\n<tr>\n<th>\u0422\u0430\u0431\u043b\u0438\u0446\u0430<\/th>\n<th>\u0414\u0435\u0439\u0441\u0442\u0432\u0438\u0435<\/th>\n<th>\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>filter<\/td>\n<td><code>ACCEPT<\/code><\/td>\n<td>\u0420\u0430\u0437\u0440\u0435\u0448\u0438\u0442\u044c \u043f\u0430\u043a\u0435\u0442<\/td>\n<\/tr>\n<tr>\n<td>filter<\/td>\n<td><code>DROP<\/code><\/td>\n<td>\u0417\u0430\u043f\u0440\u0435\u0442\u0438\u0442\u044c \u043f\u0430\u043a\u0435\u0442<\/td>\n<\/tr>\n<tr>\n<td>filter<\/td>\n<td><code>REJECT<\/code><\/td>\n<td>\u0417\u0430\u043f\u0440\u0435\u0442\u0438\u0442\u044c \u0441 \u0443\u0432\u0435\u0434\u043e\u043c\u043b\u0435\u043d\u0438\u0435\u043c \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0430<\/td>\n<\/tr>\n<tr>\n<td>nat<\/td>\n<td><code>MASQUERADE<\/code><\/td>\n<td>\u0417\u0430\u043c\u0435\u043d\u0430 \u0430\u0434\u0440\u0435\u0441\u0430 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0430 \u043d\u0430 \u0430\u0434\u0440\u0435\u0441 \u0443\u0445\u043e\u0434\u044f\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430<\/td>\n<\/tr>\n<tr>\n<td>nat<\/td>\n<td><code>SNAT<\/code><\/td>\n<td>\u041a\u0430\u043a MASQUERADE, \u043d\u043e \u0441 \u0443\u043a\u0430\u0437\u0430\u043d\u0438\u0435\u043c \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430<\/td>\n<\/tr>\n<tr>\n<td>nat<\/td>\n<td><code>DNAT<\/code><\/td>\n<td>\u041f\u043e\u0434\u043c\u0435\u043d\u0430 \u0430\u0434\u0440\u0435\u0441\u0430 \u0434\u043b\u044f \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0445<\/td>\n<\/tr>\n<tr>\n<td>nat<\/td>\n<td><code>REDIRECT<\/code><\/td>\n<td>\u041f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043d\u0430 \u0434\u0440\u0443\u0433\u043e\u0439 \u043f\u043e\u0440\u0442 \u0442\u043e\u0439 \u0436\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b<\/td>\n<\/tr>\n<tr>\n<td>mangle<\/td>\n<td><code>TOS<\/code> \/ <code>DSCP<\/code><\/td>\n<td>\u041f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0437\u0430\u0446\u0438\u044f \u0442\u0440\u0430\u0444\u0438\u043a\u0430<\/td>\n<\/tr>\n<tr>\n<td>mangle<\/td>\n<td><code>TTL<\/code> \/ <code>HL<\/code><\/td>\n<td>\u0418\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u0436\u0438\u0437\u043d\u0438 (IPv4\/IPv6)<\/td>\n<\/tr>\n<tr>\n<td>mangle<\/td>\n<td><code>MARK<\/code> \/ <code>CONNMARK<\/code><\/td>\n<td>\u041c\u0430\u0440\u043a\u0438\u0440\u043e\u0432\u043a\u0430 \u043f\u0430\u043a\u0435\u0442\u0430\/\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f<\/td>\n<\/tr>\n<tr>\n<td>mangle<\/td>\n<td><code>TCPMSS<\/code><\/td>\n<td>\u0418\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 MTU<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<h2>\u0427\u0430\u0441\u0442\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u044b<\/h2>\n<h3>\u041e\u0431\u0449\u0438\u0435<\/h3>\n<pre><code class=\"language-bash\">iptables -L --line-numbers              # \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0441 \u043d\u043e\u043c\u0435\u0440\u0430\u043c\u0438\niptables -t nat -L --line-numbers       # \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0442\u0430\u0431\u043b\u0438\u0446\u044b nat\niptables -L -v                          # \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u044b\u0439 \u0432\u044b\u0432\u043e\u0434\niptables -F                             # \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u0432\u0441\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u0430\niptables -P INPUT DROP                  # \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0430: \u0437\u0430\u043f\u0440\u0435\u0442 \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0445\niptables -P OUTPUT DROP                 # \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0430: \u0437\u0430\u043f\u0440\u0435\u0442 \u0438\u0441\u0445\u043e\u0434\u044f\u0449\u0438\u0445\n<\/code><\/pre>\n<h3>\u0420\u0430\u0437\u0440\u0435\u0448\u0438\u0442\u044c \u0432\u0441\u0451<\/h3>\n<p><strong>\u0421\u043f\u043e\u0441\u043e\u0431 1 \u2014 \u043f\u0440\u0430\u0432\u0438\u043b\u0430\u043c\u0438:<\/strong><\/p>\n<pre><code class=\"language-bash\">iptables -I INPUT 1 -j ACCEPT\niptables -I OUTPUT 1 -j ACCEPT\niptables -I FORWARD 1 -j ACCEPT\n<\/code><\/pre>\n<p><strong>\u0421\u043f\u043e\u0441\u043e\u0431 2 \u2014 \u043e\u0447\u0438\u0441\u0442\u043a\u043e\u0439:<\/strong><\/p>\n<pre><code class=\"language-bash\">iptables -F\niptables -S\n<\/code><\/pre>\n<p><strong>\u0421\u043f\u043e\u0441\u043e\u0431 3 \u2014 \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u0430 (\u0434\u043b\u044f \u0434\u0438\u0430\u0433\u043d\u043e\u0441\u0442\u0438\u043a\u0438):<\/strong><\/p>\n<pre><code class=\"language-bash\">service iptables stop\n<\/code><\/pre>\n<h3>\u0420\u0430\u0431\u043e\u0442\u0430 \u0441 \u043f\u0440\u0430\u0432\u0438\u043b\u0430\u043c\u0438<\/h3>\n<pre><code class=\"language-bash\"># \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u0432 \u043a\u043e\u043d\u0435\u0446\niptables -A INPUT -p tcp --dport 25 -j ACCEPT\niptables -A INPUT -p tcp -s ! 192.168.0.25 --dport 993 -i eth0 -j ACCEPT\n\n# \u0434\u0438\u0430\u043f\u0430\u0437\u043e\u043d \u043f\u043e\u0440\u0442\u043e\u0432\niptables -A INPUT -p tcp --dport 3000:4000 -j ACCEPT\n\n# \u0432\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u043e\niptables -I FORWARD 15 -p udp -d 8.8.8.8 --dport 53 -i eth1 -j ACCEPT\n\n# \u0437\u0430\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u0442\u044c IP \u043d\u0430 \u043f\u043e\u0440\u0442\u0443 25\niptables -I INPUT 1 -s 1.1.1.1 -p tcp --dport 25 -j DROP\n\n# \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043f\u043e\u0440\u0442\u043e\u0432\niptables -A INPUT -p tcp --match multiport --dports 20,21,25,80,8080,3000:4000 -j ACCEPT\n<\/code><\/pre>\n<h3>\u041f\u0440\u043e\u0431\u0440\u043e\u0441 \u043f\u043e\u0440\u0442\u043e\u0432 (port forwarding)<\/h3>\n<p><strong>\u041e\u0434\u0438\u043d \u043f\u043e\u0440\u0442, \u043e\u0434\u0438\u043d\u0430\u043a\u043e\u0432\u044b\u0435 \u043f\u043e\u0440\u0442\u044b \u2014 PREROUTING + POSTROUTING:<\/strong><\/p>\n<pre><code class=\"language-bash\">iptables -t nat -A PREROUTING -p tcp -m tcp -d 19.8.232.80 --dport 22 -j DNAT --to-destination 192.168.1.15:22\niptables -t nat -A POSTROUTING -p tcp -m tcp -s 192.168.1.15 --sport 22 -j SNAT --to-source 19.8.232.80:22\n<\/code><\/pre>\n<p><strong>\u0433\u0434\u0435 <code>19.8.232.80<\/code> \u2014 \u0430\u0434\u0440\u0435\u0441 \u043f\u0440\u043e\u0441\u043b\u0443\u0448\u0438\u0432\u0430\u043d\u0438\u044f, <code>22<\/code> \u2014 \u043f\u043e\u0440\u0442, <code>192.168.1.15<\/code> \u2014 \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0438\u0439 \u0430\u0434\u0440\u0435\u0441.<\/strong><\/p>\n<p><strong>PREROUTING + FORWARD:<\/strong><\/p>\n<pre><code class=\"language-bash\">iptables -t nat -A PREROUTING -p tcp -i eth1 --dport 22 -j DNAT --to-destination 192.168.1.15:22\niptables -A FORWARD -p tcp -d 192.168.1.15 --dport 22 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT\n<\/code><\/pre>\n<p><strong>\u0420\u0430\u0437\u043d\u044b\u0435 \u043f\u043e\u0440\u0442\u044b:<\/strong><\/p>\n<pre><code class=\"language-bash\">iptables -t nat -A PREROUTING -p tcp -i eth1 --dport 8022 -j DNAT --to-destination 192.168.1.15:22\niptables -A FORWARD -p tcp -d 192.168.1.15 --dport 22 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT\n<\/code><\/pre>\n<p><strong>\u0414\u0438\u0430\u043f\u0430\u0437\u043e\u043d \u043f\u043e\u0440\u0442\u043e\u0432:<\/strong><\/p>\n<pre><code class=\"language-bash\">iptables -t nat -I PREROUTING -p tcp -m tcp --dport 1000:5000 -j DNAT --to-destination 192.168.1.15:1000-5000\niptables -A FORWARD -d 192.168.1.15 -i eth1 -p tcp -m tcp --dport 1000:5000 -j ACCEPT\n<\/code><\/pre>\n<h3>\u0421\u0442\u0430\u0440\u0442\u043e\u0432\u0430\u044f \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430<\/h3>\n<pre><code class=\"language-bash\">iptables -I INPUT -p tcp --dport 22 -j ACCEPT\niptables -I INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT\niptables -I INPUT -p icmp -j ACCEPT\niptables -I INPUT -i lo -j ACCEPT\niptables -P INPUT DROP\niptables -P OUTPUT ACCEPT\n<\/code><\/pre>\n<h3>\u0421\u0431\u0440\u043e\u0441 \u043a \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f\u043c \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e<\/h3>\n<pre><code class=\"language-bash\">iptables -P INPUT ACCEPT\niptables -P OUTPUT ACCEPT\niptables -F\niptables -t nat -F\niptables -t mangle -F\niptables -X\n<\/code><\/pre>\n<hr \/>\n<h2>\u0421\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u0435 \u043f\u0440\u0430\u0432\u0438\u043b<\/h2>\n<p>\u041f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0442\u0435\u0440\u044f\u044e\u0442\u0441\u044f \u043f\u043e\u0441\u043b\u0435 \u043f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438.<\/p>\n<h3>\u0421\u043f\u043e\u0441\u043e\u0431 1. iptables-save (\u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0430\u043b\u044c\u043d\u044b\u0439)<\/h3>\n<pre><code class=\"language-bash\">iptables-save &gt; \/etc\/iptables.rules\niptables-restore &lt; \/etc\/iptables.rules\n<\/code><\/pre>\n<p><strong>\u0412 \u0441\u0442\u0430\u0440\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u043b\u0438 \u0432 <code>\/etc\/network\/interfaces<\/code> \u0441\u0442\u0440\u043e\u043a\u0443 <code>pre-up iptables-restore<\/code>.<\/strong><\/p>\n<h3>\u0421\u043f\u043e\u0441\u043e\u0431 2. iptables-persistent (Debian\/Ubuntu)<\/h3>\n<pre><code class=\"language-bash\">apt install iptables-persistent\nnetfilter-persistent save\n<\/code><\/pre>\n<h3>\u0421\u043f\u043e\u0441\u043e\u0431 3. service iptables (CentOS)<\/h3>\n<pre><code class=\"language-bash\">yum install iptables-services\nservice iptables save          # \u0441\u043e\u0445\u0440\u0430\u043d\u0438\u0442 \u0432 \/etc\/sysconfig\/iptables\nsystemctl enable iptables\n<\/code><\/pre>\n<p><strong>\u0412 \u0441\u0442\u0430\u0440\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445: <code>chkconfig iptables on<\/code> (CentOS), <code>update-rc.d iptables defaults<\/code> (Ubuntu).<\/strong><\/p>\n<hr \/>\n<h2>Ubuntu \u0438 CentOS<\/h2>\n<p>\u0412 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0448\u0442\u0430\u0442\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u043d\u0435 iptables, \u0430 <code>ufw<\/code> (Ubuntu) \u0438 <code>firewalld<\/code> (RPM).<\/p>\n<h3>CentOS \/ Rocky<\/h3>\n<pre><code class=\"language-bash\">yum install iptables-services\nsystemctl stop firewalld\nsystemctl disable firewalld\nsystemctl enable iptables\nsystemctl start iptables\n<\/code><\/pre>\n<h3>Ubuntu<\/h3>\n<pre><code class=\"language-bash\">apt install iptables-persistent\nufw disable\n<\/code><\/pre>\n<hr \/>\n<h2>\u0422\u043e\u043d\u043a\u043e\u0441\u0442\u0438 \u0438 \u043f\u043e\u0434\u0432\u043e\u0434\u043d\u044b\u0435 \u043a\u0430\u043c\u043d\u0438<\/h2>\n<ul>\n<li><strong><code>-I<\/code> vs <code>-A<\/code><\/strong> \u2014 <code>-I<\/code> \u0432\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0432 \u043d\u0430\u0447\u0430\u043b\u043e, <code>-A<\/code> \u2014 \u0432 \u043a\u043e\u043d\u0435\u0446; \u043f\u0440\u0438 \u0437\u0430\u043f\u0440\u0435\u0449\u0430\u044e\u0449\u0438\u0445 \u043f\u0440\u0430\u0432\u0438\u043b\u0430\u0445 \u0432\u044b\u0448\u0435 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u044e\u0449\u0435\u0435 \u043c\u043e\u0436\u0435\u0442 \u043d\u0435 \u0441\u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c.<\/li>\n<li><strong><code>DROP<\/code> vs <code>REJECT<\/code><\/strong> \u2014 <code>DROP<\/code> \u043c\u043e\u043b\u0447\u0430 \u043e\u0442\u0431\u0440\u0430\u0441\u044b\u0432\u0430\u0435\u0442, <code>REJECT<\/code> \u0443\u0432\u0435\u0434\u043e\u043c\u043b\u044f\u0435\u0442 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a.<\/li>\n<li><strong>\u041f\u043e\u0440\u044f\u0434\u043e\u043a \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438<\/strong> \u2014 PREROUTING\/POSTROUTING (nat) \u0434\u043e FORWARD (filter); \u043f\u0440\u0438 \u043f\u0440\u043e\u0431\u0440\u043e\u0441\u0435 \u043e\u0442\u043a\u0440\u044b\u0432\u0430\u0439\u0442\u0435 \u043f\u043e\u0440\u0442 \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f.<\/li>\n<li><strong>\u0421\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u0435 \u043e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u044c\u043d\u043e<\/strong> \u2014 \u0431\u0435\u0437 <code>netfilter-persistent<\/code>\/<code>iptables-services<\/code> \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0438\u0441\u0447\u0435\u0437\u043d\u0443\u0442.<\/li>\n<li><strong><code>iptables -S<\/code> vs <code>-L<\/code><\/strong> \u2014 <code>-S<\/code> \u0432\u044b\u0432\u043e\u0434\u0438\u0442 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 \u043a\u043e\u043c\u0430\u043d\u0434 (\u0443\u0434\u043e\u0431\u043d\u043e \u0434\u043b\u044f \u0441\u043a\u0440\u0438\u043f\u0442\u043e\u0432).<\/li>\n<li><strong>nftables<\/strong> \u2014 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0439\u0442\u0435 \u0431\u044d\u043a\u0435\u043d\u0434; <code>iptables-legacy<\/code> \u0438 <code>iptables-nft<\/code> \u043c\u043e\u0433\u0443\u0442 \u0441\u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c.<\/li>\n<li><strong>\u0411\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0430 SSH<\/strong> \u2014 \u043f\u0435\u0440\u0435\u0434 <code>iptables -P INPUT DROP<\/code> \u0443\u0431\u0435\u0434\u0438\u0442\u0435\u0441\u044c, \u0447\u0442\u043e \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0434\u043b\u044f SSH \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043e.<\/li>\n<li><strong>\u0421\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u043e\u0441\u0442\u044c \u0441 Docker<\/strong> \u2014 Docker \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u0441\u0432\u043e\u0438\u043c\u0438 \u0446\u0435\u043f\u043e\u0447\u043a\u0430\u043c\u0438; \u043d\u0435 \u043e\u0447\u0438\u0449\u0430\u0439\u0442\u0435 \u0438\u0445 \u0447\u0435\u0440\u0435\u0437 <code>-F<\/code>.<\/li>\n<\/ul>\n<hr \/>\n<h2>\u0428\u043f\u0430\u0440\u0433\u0430\u043b\u043a\u0430<\/h2>\n<pre><code class=\"language-bash\">iptables -L --line-numbers\niptables -A INPUT -p tcp --dport 80 -j ACCEPT\niptables -I INPUT 1 -s 1.1.1.1 -j DROP\niptables -t nat -A PREROUTING -p tcp --dport 443 -j DNAT --to-destination 192.168.1.10:443\niptables-save &gt; \/etc\/iptables.rules\nnetfilter-persistent save\n<\/code><\/pre>\n<p><em>\u041f\u0440\u043e\u0432\u0435\u0440\u0435\u043d\u043e \u043d\u0430: Ubuntu 22.04\/24.04\/26.04, Rocky Linux 9 + iptables\/nftables.<\/em><br \/>\n<em>\u0414\u0430\u0442\u0430: \u0421\u0435\u043d\u0442\u044f\u0431\u0440\u044c 2026.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 netfilter \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e iptables: \u0448\u043f\u0430\u0440\u0433\u0430\u043b\u043a\u0430 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440\u044b iptables \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u0442<\/p>\n","protected":false},"author":0,"featured_media":968,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-918","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux"],"aioseo_notices":[],"views":9,"_links":{"self":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=918"}],"version-history":[{"count":2,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/918\/revisions"}],"predecessor-version":[{"id":921,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/918\/revisions\/921"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/media\/968"}],"wp:attachment":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}