1.使用iptable实现: 放行ssh,telnet, ftp, web服务80端口,其他端口服务全部拒绝 [root@localhost ~]# iptables -A INPUT -p tcp -m multiport --dports 21:23,80 -j ACCEPT [root@localhost ~]# iptables -A INPUT -j REJECT [root@localhost ~]# iptables --list Chain INPUT (policy ACCEPT) target prot opt source destination ACCEPT tcp -...