Configure iptables:
Update to iptable on system on file: /etc/systemd/scripts/iptables
To view the list of rules, use the command:
sudo iptables -nvL
To open access to Samba in IPTables, you must add four rules at once:
sudo iptables -A INPUT -p udp -m udp --dport 137 -j ACCEPT
sudo iptables -A INPUT -p udp -m udp --dport 138 -j ACCEPT
sudo iptables -A INPUT -p tcp -m tcp --dport 139 -j ACCEPT
sudo iptables -A INPUT -p tcp -m tcp --dport 445 -j ACCEPT
To only allow access to a particular network, for example 192.168.1.0/24:
sudo iptables -A INPUT -s 192.168.1.0/24 -p udp -m udp --dport 137 -j ACCEPT
sudo iptables -A INPUT -s 192.168.1.0/24 -p udp -m udp --dport 138 -j ACCEPT
sudo iptables -A INPUT -s 192.168.1.0/24 -p tcp -m tcp --dport 139 -j ACCEPT
sudo iptables -A INPUT -s 192.168.1.0/24 -p tcp -m tcp --dport 445 -j ACCEPT
To remove a rule, we’ll specify the same command, replacing -A with -D, for example:
sudo iptables -D INPUT -s 192.168.1.0/24 -p udp -m udp --dport 137 -j ACCEPT
sudo iptables -D INPUT -s 192.168.1.0/24 -p udp -m udp --dport 138 -j ACCEPT
sudo iptables -D INPUT -s 192.168.1.0/24 -p tcp -m tcp --dport 139 -j ACCEPT
sudo iptables -D INPUT -s 192.168.1.0/24 -p tcp -m tcp --dport 445 -j ACCEPT
To enable a port (8000) to access
iptables -A INPUT -p tcp -m tcp -s 0/0 --dport 8000 -j ACCEPT
Enable to response the ping command from another server
iptables -A INPUT -p icmp -j ACCEPT
Enable samba have accessed
iptables -A INPUT -m state --state NEW,ESTABLISHED -p tcp -dport 137 -j ACCEPT
iptables -A INPUT -m state --state NEW,ESTABLISHED -p tcp -dport 138 -j ACCEPT
iptables -A INPUT -m state --state NEW,ESTABLISHED -p tcp -dport 139 -j ACCEPT
iptables -A INPUT -m state --state NEW,ESTABLISHED -p tcp -dport 145 -j ACCEPT
Enable chome cast
iptables -I INPUT -p udp -m multiport --sports 32768:61000 -j ACCEPT
iptables -I INPUT -p udp -m multiport --dports 32768:61000 -j ACCEPT
iptables -A OUTPUT -p tcp -m multiport --sports 32768:61000 -j ACCEPT
iptables -A OUTPUT -p tcp -m multiport --dports 32768:61000 -j ACCEPT
iptables -A OUTPUT -p udp --dport 1900 -j ACCEPT
Enable Airplay