此内容没有您所选择的语言版本。

7.7. ip6tables


The introduction of the next-generation Internet Protocol, called IPv6, expands beyond the 32-bit address limit of IPv4 (or IP). IPv6 supports 128-bit addresses and, as such, carrier networks that are IPv6 aware are able to address a larger number of routable addresses than IPv4.
Red Hat Enterprise Linux supports IPv6 firewall rules using the Netfilter 6 subsystem and the ip6tables command. The first step in using ip6tables is to start the ip6tables service. This can be done with the command:
service ip6tables start
Copy to Clipboard Toggle word wrap

Warning

The iptables services must be turned off to use the ip6tables service exclusively:
service iptables stop
chkconfig iptables off
Copy to Clipboard Toggle word wrap
To make ip6tables start by default whenever the system is booted, change the runlevel status on the service using chkconfig.
chkconfig --level 345 ip6tables on
Copy to Clipboard Toggle word wrap
The syntax is identical to iptables in every aspect except that ip6tables supports 128-bit addresses. For example, SSH connections on a IPv6-aware network server can be enabled with the following rule:
ip6tables -A INPUT -i eth0 -p tcp -s 3ffe:ffff:100::1/128 --dport 22 -j ACCEPT
Copy to Clipboard Toggle word wrap
For more information about IPv6 networking, refer to the IPv6 Information Page at http://www.ipv6.org/.
返回顶部
Red Hat logoGithubredditYoutubeTwitter

学习

尝试、购买和销售

社区

关于红帽文档

通过我们的产品和服务,以及可以信赖的内容,帮助红帽用户创新并实现他们的目标。 了解我们当前的更新.

让开源更具包容性

红帽致力于替换我们的代码、文档和 Web 属性中存在问题的语言。欲了解更多详情,请参阅红帽博客.

關於紅帽

我们提供强化的解决方案,使企业能够更轻松地跨平台和环境(从核心数据中心到网络边缘)工作。

Theme

© 2025 Red Hat