iptables规则持久化
命令修改iptables后重启会丢失。持久化文件在:
/etc/iptables/rules.v4
/etc/iptables/rules.v6
存储和恢复命令:
netfilter-persistent save
netfilter-persistent start
iptables-save > /etc/iptables/rules.v4
ip6tables-save > /etc/iptables/rules.v6
iptables-restore < /etc/iptables/rules.v4
ip6tables-restore < /etc/iptables/rules.v6
systemctl stop netfilter-persistent
systemctl start netfilter-persistent
systemctl restart netfilter-persistent
比如我的rules.v4长这样:
root@hecs-301353:/etc/iptables# cat rules.v4.bak
# Generated by iptables-save v1.8.7 on Wed Jan 4 20:32:54 2023
*nat
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A PREROUTING -d 192.168.0.163/32 -p tcp -m tcp --dport 27896 -j DNAT --to-destination 192.168.0.121:27896
-A POSTROUTING -d 192.168.0.121/32 -p tcp -m tcp --dport 27896 -j SNAT --to-source 192.168.0.163
COMMIT
# Completed on Wed Jan 4 20:32:54 2023