禁止响应ping
sudo iptables -A INPUT -p icmp --icmp-type 8 -s 0/0 -j DROP
允许响应ping
sudo iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
sudo iptables -A OUTPUT -p icmp --icmp-type echo-reply -j ACCEPT
存储设置
sudo service iptables save