iptables规则持久化

发布时间 2023-03-24 16:09:59作者: 王冰冰

命令修改iptables后重启会丢失。持久化文件在:

/etc/iptables/rules.v4
/etc/iptables/rules.v6

存储和恢复命令:

netfilter-persistent save
netfilter-persistent start

iptables-save  > /etc/iptables/rules.v4
ip6tables-save > /etc/iptables/rules.v6

iptables-restore  < /etc/iptables/rules.v4
ip6tables-restore < /etc/iptables/rules.v6

systemctl stop    netfilter-persistent
systemctl start   netfilter-persistent
systemctl restart netfilter-persistent

比如我的rules.v4长这样:

root@hecs-301353:/etc/iptables# cat rules.v4.bak
# Generated by iptables-save v1.8.7 on Wed Jan  4 20:32:54 2023
*nat
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A PREROUTING -d 192.168.0.163/32 -p tcp -m tcp --dport 27896 -j DNAT --to-destination 192.168.0.121:27896
-A POSTROUTING -d 192.168.0.121/32 -p tcp -m tcp --dport 27896 -j SNAT --to-source 192.168.0.163
COMMIT
# Completed on Wed Jan  4 20:32:54 2023