# grep " 80 " user*.rules user6.rules:### tuple ### allow tcp 80 ::/0 any ::/0in user6.rules:-A ufw6-user-input -p tcp --dport 80 -j ACCEPT user.rules:### tuple ### allow tcp 800.0.0.0/0 any 0.0.0.0/0in user.rules:-A ufw-user-input -p tcp --dport 80 -j ACCEPT You have new mail in /var/mail/root # grep 443 user*.rules user6.rules:### tuple ### allow tcp 443 ::/0 any ::/0in user6.rules:-A ufw6-user-input -p tcp --dport 443 -j ACCEPT user.rules:### tuple ### allow tcp 4430.0.0.0/0 any 0.0.0.0/0in user.rules:-A ufw-user-input -p tcp --dport 443 -j ACCEPT
使用 ufw,你还可以使用以下命令轻松地阻止来自一个 IP 地址的连接:
1 2
$ sudo ufw deny from 208.176.0.50 Rule added
status 命令将显示更改:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
$ sudo ufw status verbose Status: active Logging: on (low) Default: deny (incoming), allow (outgoing), disabled (routed) New profiles: skip
To Action From -- ------ ---- 22 ALLOW IN192.168.0.0/24 9090 ALLOW IN Anywhere 80/tcp ALLOW IN Anywhere 443/tcp ALLOW IN Anywhere Anywhere DENY IN208.176.0.50 <== new 9090 (v6) ALLOW IN Anywhere (v6) 80/tcp (v6) ALLOW IN Anywhere (v6) 443/tcp (v6) ALLOW IN Anywhere (v6)