#!/bin/bash
subnets=(10.110.12.10 10.110.12.11 10.110.12.12 10.110.12.13 10.110.12.14)
#多个端口使用空格隔开,连续的使用冒号,比如443:448,ports=(443:448 6443)
ports=(6443)
for port in ${ports[*]} ; do
for subnet in ${subnets[*]} ; do
echo iptables -A INPUT -p tcp -s $subnet --dport $port -j ACCEPT
done
echo iptables -A INPUT -p tcp --dport $port -j REJECT
done
网友评论