Difference between revisions of "How to block someone's IP"
Line 38: | Line 38: | ||
'''Very important:''' Don't forget to add ISP/router to your friendly ip address list!!! | '''Very important:''' Don't forget to add ISP/router to your friendly ip address list!!! | ||
<br><br> | |||
===How to unblock IP=== | |||
Search for the IP under /etc/sysconfig/iptables: | |||
grep 123.123.123.123 /etc/sysconfig/iptables | |||
This would give the following output: | |||
-A INPUT -s 123.123.123.123 -j DROP | |||
-A INPUT -s 123.123.123.123 -j ACCEPT | |||
Then you can delete the rule using the '-D' option in iptables: | |||
iptables -D INPUT -s 123.123.123.123 -j DROP | |||
Now IP 123.123.123.123 is unblocked. | |||
<br><br> |
Revision as of 08:32, 16 June 2011
First of all install iptables if needed:
yum -y install iptables
To block incoming IP, use this command:
iptables -A INPUT -s IP -j DROP
For example:
iptables -A INPUT -s 123.123.123.123 -j DROP
To save the rules, run:
On Centos)
/etc/init.d/iptables save
On Debian)
Please read this link http://www.debian-administration.org/articles/445
Question: I want allow only specified IPs to my server and dissallow any other connections, how I could do that?
First of all enter all friendly ips:
iptables -A INPUT -s friendlyip. -j ACCEPT iptables -A INPUT -s another.friendly.ip -j ACCEPT iptables -A INPUT -s 127.0.0.1 -j ACCEPT # yes, accept connections from localhost.
And the most end enter:
iptables -A INPUT -s 0/0 -j DROP
Thats it.
If in future you will want to add some more ips, just first reject rule with DROP, and some friendly ip and then apply DROP rule again.
Very important: Don't forget to add ISP/router to your friendly ip address list!!!
How to unblock IP
Search for the IP under /etc/sysconfig/iptables:
grep 123.123.123.123 /etc/sysconfig/iptables
This would give the following output:
-A INPUT -s 123.123.123.123 -j DROP -A INPUT -s 123.123.123.123 -j ACCEPT
Then you can delete the rule using the '-D' option in iptables:
iptables -D INPUT -s 123.123.123.123 -j DROP
Now IP 123.123.123.123 is unblocked.