ipsecconf -f --> bở cấu hình cũipsecconf -a /etc/inet/ipsecinit.conf --> tạo lại cấu hình theo config mới
{saddr <IP> dport <port> ulp tcp daddr <IP> dir out}bypass{}{saddr <IP> sport <port> ulp tcp daddr <IP> dir in}bypass{}
{saddr 222.252.101.111 smask 255.255.255.0 daddr <IPServer> dport 3306 ulp tcp dir in}bypass{}{daddr 222.252.101.111 smask 255.255.255.0 saddr <IPServer> sport 3306 ulp tcp dir out}bypass{}
iptables -flush hoặc iptables -Fservice iptables restart
-A INPUT -p tcp -s <IPClient> -d <IPServer> --dport 22 -j ACCEPT-A OUTPUT -p tcp -s <IPServer> --sport 22 -d <IPClient> -j ACCEPT
#ICMP-A INPUT -p icmp -d <IPServer> -j ACCEPT-A OUTPUT -p icmp -s <IPServer> -j ACCEPT