通过配置firewalld可以较好的阻止恶意的流量
sudo systemctl start firewalld
sudo systemctl enable firewalld
/etc/firewalld
sudo firewall-cmd --list-all-zones
sudo firewall-cmd --state
firewall-cmd --zone=external --add-icmp-block=echo-request
firewall-cmd --zone=external --add-icmp-block=echo-reply
firewall-cmd --runtime-to-permanent
sudo firewall-cmd --reload
原文:https://www.cnblogs.com/t0m1tu/p/14854016.html