
Use your favorite text editor: vi /etc/sysconfig/iptables This is how you ALLOW access to a range of IP addresses: # 211 -A RH-Lokkit-0-50-INPUT -p tcp -m state –state NEW,ESTABLISHED -s 64.1111.222.0/24 –dport 22 -j ACCEPT -A RH-Lokkit-0-50-INPUT -p tcp -m state –state NEW,ESTABLISHED -d 64.111.222.0/24 –sport 22 -j ACCEPT *********************************************************** by default, everybody should be locked out of the box - DO NOT FORGET THIS STEP - BE CAREFUL - DO NOT LOCK YOURSELF OUT (SEE ABOVE) -A RH-Lokkit-0-50-INPUT -p tcp -m tcp –dport 22 -j REJECT *********************************************************** This is how you lock up certain ports #shut out these imap hackers -A RH-Lokkit-0-50-INPUT -p tcp -m state –state NEW,ESTABLISHED -s 66.44.77.33 –dport 993 -j REJECT -A RH-Lokkit-0-50-INPUT -p tcp -m state –state NEW,ESTABLISHED -d 66.44.77.33 –sport 993 -j REJECT Now restart the service /etc/init.d/restart