2013-06-19 39 views
1

我使用bash文件工作,我想插入並獲得在iptables中的行文件插入線的文件

# Firewall configuration written by system-config-firewall 
# Manual customization of this file is not recommended. 
*filter 
:INPUT ACCEPT [0:0] 
:FORWARD ACCEPT [0:0] 
:OUTPUT ACCEPT [0:0] 
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT 
-A INPUT -p icmp -j ACCEPT 
-A INPUT -i lo -j ACCEPT 
{My Line Here} 
-A INPUT -m state --state NEW -m udp -p udp --dport 5353 -d 224.0.0.251 -j ACCEPT 
-A INPUT -j REJECT --reject-with icmp-host-prohibited 
-A FORWARD -j REJECT --reject-with icmp-host-prohibited 
COMMIT 

取代{這裏我行}到

-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT 
  1. 然後我想找到並獲得防火牆開放端口並顯示它們

回答

0
sed 's/-A INPUT -i lo -j ACCEPT/-A INPUT -i lo -j ACCEPT\n-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT/g' <filename> > temp ; mv temp <filename> 

用實際文件替換<filename>。這隻適用於如果前面的行是-A INPUT -i lo -j ACCEPT

+0

感謝它的作品,但如何找到開放端口? – mindia

+0

'netstat -tulpn | less'。我認爲這會有所幫助。更多信息,請點擊http://www.cyberciti.biz/faq/howto-rhel-linux-open-port-using-iptables/ –