systemctl stop firewalld && systemctl disable firewalld
yum install iptables-services
systemctl enable iptables && systemctl start iptables
systemctl status iptables,未启动则启动。service iptables save或iptables-save > /etc/sysconfig/iptables。lsmod | grep ip_tables,缺失则加载(如modprobe ip_tables)。iptables -L -n --line-numbers,调整顺序或删除冲突规则。systemctl restart iptables。/etc/sysctl.conf:sysctl -w net.ipv4.ip_conntrack_max=100000
echo "net.ipv4.ip_conntrack_max=100000" >> /etc/sysctl.conf
sysctl -p
dockerd --iptables=false(需在Docker配置中设置)。setenforce 0,若生效则调整策略:semanage permissive -a iptables_t # 需安装policycoreutils-python
cp /etc/sysconfig/iptables /etc/sysconfig/iptables.bak。service iptables restore < /etc/sysconfig/iptables.bak。update-alternatives --set iptables /usr/sbin/iptables-legacy
update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy