iptables -I INPUT -i lo -j ACCEPT #允许本地回环地址访问;
iptables -I INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -s 192.168.235.0/24 -j ACCEPT
iptables -A INPUT -s 192.168.8.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -p tcp --dport 1723 -j ACCEPT #VPN端口;
iptables -A INPUT -j REJECCT#拒绝掉不在规则内的全部请求