tcpdump -i eth0 tcp src port 23 and host !192.168.1.111
iptables过滤掉的包,tcpdump也能抓到(经过物理网卡就可以?);
临时改,允许所有22端口的请求:
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
restart后失效,永久改:
/etc/sysconf/iptables