【问题标题】:Iptables -mac adress accept with a loopiptables -mac 地址接受循环
【发布时间】:2021-07-21 02:10:48
【问题描述】:

我正在尝试制定一个 iptables 规则,以便只接受一些 mac 地址。为此,首先,我向端点 api 发出 get 请求以获取 mac 地址,并将 mac 地址存储在数组中。

例子:

declare -a MAC_ADDRESS=()

MAC_ADDRESS+=($(curl -sb "Application: accept/json" "https://myurl/endpoint_api"))

#(这不是真的正确,但我的get请求确实有效)。

然后我创建一个循环,为存储在我的数组中的所有项目应用 iptable 规则,如下所示:

for element in $MAC_ADDRESS
do
iptables -A INPUT -i enp0s7 -p tcp --dport 8080 -m --mac-source ${element} -j ACCEPT

done

这不起作用..我不知道为什么。

我只想将此规则(以及许多其他规则)应用于我数组中的所有项目,但这样它不起作用,你知道它是否可能以及如何实现?

非常感谢 莫

【问题讨论】:

  • 重新阅读 bash 数组介绍。
  • 我不认为这是一个重复的问题,因为我试图为我的数组中的所有元素制定规则。这与其他问题不同。谢谢

标签: bash loops iptables mac-address


【解决方案1】:

TIL bash 做数组!这很有帮助。

https://opensource.com/article/18/5/you-dont-know-bash-intro-bash-arrays

看起来您用来调用数组项的语法不正确。要调用数组元素,您需要使用 ${ARRAY_NAME[@]}。

for element in ${MAC_ADDRESS[@]}; do 
    iptables -A INPUT -i enp0s7 -p tcp --dport 8080 -m --mac-source ${element} -j ACCEPT
done

我没有方便测试的 JSON,所以我只是在我自己的 HTP 主机上使用了一个带有平面文件的模拟。

$ cat test1.sh
#!/bin/bash
unset LIST
declare -a LIST=( $( curl -s http://www.someurl.tld/z0th/file ) )
for item in ${LIST[@]} ; do
        echo "some text" ${item} "more text"
done

当你运行它时;

$ sh test1.sh
some text one more text
some text two more text
some text three more text
some text four more text
some text five more text

我通过做测试了数组;

$ echo $LIST
$ echo -e "${LIST[@]} \n"

第一个 echo 命令,如果是一个数组,将只输出第一个元素。第二个将交还整个阵列。将 @ 替换为元素编号以专门调用它。

【讨论】:

    猜你喜欢
    • 2014-07-14
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多