Kukhazikitsa kwa malo opsinjika mu malo 7

Anonim

Kukhazikitsa kwa malo opsinjika mu malo 7

M'makina onse ogwiritsira ntchito a Linux Kernel, pali chowotchera moto, zomwe zimapangitsa kuti ziziwongolera komanso kusefa kwa magalimoto obwera komanso otuluka, kutengera malamulo omwe atchulidwa kapena papulatifomu. Mu malo ogawa, yomwe imagwira ntchito imagwira ntchito yotere, kucheza ndi moto wowombera ku netfilter. Nthawi zina woyang'anira makina kapena manejala ochezera ayenera kulinganiza ntchitoyi, kufotokozera malamulo oyenera. Monga gawo la nkhani yamakono, tikufuna kukambirana za zigawo za kukhazikitsidwa kwa ipleble zomwe zatchulidwazi.

Kukonzekera Kupsinjika M'minola 7

Chidacho chimapezeka kuti chizigwira ntchito nthawi yomweyo mutakhazikitsa ma Centon 7, komatu adzafunika kukhazikitsa mautumiki ena, omwe tidzakambirana. Pa nsanja ndikuganizira kuti pali chida china chomwe chimagwira ntchito yonyamula moto chotchedwa Firewalld. Kuti tipewe mikangano, ndi ntchito ina, timalimbikitsa olumala. Malangizo owonjezera pamutuwu amawerengera zinthu zina pa ulalo wotsatirawu.

Werengani zambiri: Lemekezani moto mu malo 7

Monga mukudziwa, IPV4 ndi IPV Protocols ikhoza kugwiritsidwa ntchito m'dongosolo. Lero tiyang'ana pa chitsanzo cha iPV4, koma ngati mukufuna kukhazikitsa protocol ina, mudzafunikira m'malo mwa gulu. Obowola. Kugwiritsa ntchito kwa Coutole Ip6.

Kukhazikitsa NJIRA

Iyenera kukhala yofunika kwambiri ku dongosolo lina lomwe limathandizira lomwe likuphunzitsidwa masiku ano. Adzathandizira kukhazikitsa malamulo ndi magawo ena. Kutsitsa kumachitika kuchokera ku malo osungira, chifukwa chake sizitenga nthawi yambiri.

  1. Zochita zina zonse zidzapangidwa mu kutonthoza kalankhulidwe kambiri, kotero muthamangitse mwanjira iliyonse yosavuta.
  2. Kuyambitsa terminal kuti ikhazikitse zofunikira za entuso 7

  3. Malamulo a SuDo yums amakhazikitsa malo ogwiritsira ntchito ndi udindo wokhazikitsa ntchito. Lowetsani ndikusindikiza batani la ENTER.
  4. Kukhazikitsa zothandiza pa Cretos 7

  5. Tsimikizani akaunti ya Superruser pofotokoza mawu achinsinsi. Chonde dziwani kuti mafunso a Sudo, otchulidwa omwe ali mu mzerewo sawonetsedwa.
  6. Lowetsani mawu achinsinsi kuti mukhazikitse mipata mu Cretos 7 kudzera mu terminal

  7. Idzafunsidwa kuti iwonjezere phukusi limodzi ku kachitidwe, tsimikizani izi posankha y Version.
  8. Chitsimikiziro chowonjezera phukusi latsopano la Septings mu malo 7

  9. Mukamaliza kukhazikitsa, onani mtundu wankhaniyo: SuDo wokayikitsa -
  10. Kuyang'ana mtundu wa zomwe zikuthandizira ku Centon 7 7 kudutsa ma terminal

  11. Zotsatira zake zidzawonekera mu chingwe chatsopano.
  12. Kuwonetsa mtundu wapano wa zothandizira ku Centon 7 7 kudutsa ma terminal

Tsopano Os ndi kwathunthu okonzekera kasinthidwe zina za makhoma oteteza mwa IPTABLES zofunikira. Ife zikusonyeza familiarizing nokha ndi kasinthidwe pa zinthu, kuyambira ndi ntchito yosamalira.

Kuyima ndi kukulozani ntchito IPTABLES

IPTables kasamalidwe mode chofunika pa nthawi imene muyenera kuonanso zochita za malamulo kapena kungoti Chisudzulo Chikuwononga chigawo cha. Izi zachitika ntchito malamulo ophatikizidwa.

  1. Lowani Sudo Service IpTables Imani ndi alemba pa Lowani kiyi kuletsa misonkhano.
  2. Kuyima IPTables Kagwiritsidwe Services mu CentOS 7 kudzera Pokwelera

  3. Kutsimikiza njirayi, mwachindunji ndi superuser achinsinsi.
  4. Achinsinsi kulowa amasiya IPTables zofunikira mu CentOS 7

  5. Ngati ndondomeko ukuyenda bwino, chingwe watsopanoyo adzaphulitsa kuwonetsedwa, kusonyeza kusintha file kasinthidwe.
  6. Zidziwitso za zosiya utumiki zofunikira IPTables mu CentOS 7

  7. The Launch mabungwe a imagwiridwa pafupifupi njira imodzi, mzere amapeza maganizo Sudo Service IpTables Start.
  8. Thamanga IPTables Zothandiza Services mu CentOS 7 kudwala

A kuyambiransoko zofanana, kuyambira kapena kulepheretsa zofunikira amapezeka nthawi iliyonse, musaiwale okha kubwerera phindu n'zosiyana kwambiri pamene kudzakhala zikufunika kwambiri.

View ndi kuchotsa malamulo

Monga tanena kale, ulamuliro wa makhoma oteteza ndi imagwiridwa ndi malamulo Buku kapena basi kuwonjezera. Mwachitsanzo, ena ntchito zina angathe kulumikiza chida, kusintha malamulo ena. Komabe, zochita kwambiri amenewa adakali mwachita pamanja. Kuwona mndandanda wa malamulo onse panopa alipo kudzera lamulo Sudo IpTables -L.

Onetsani mndandanda wa onse IPTables panopa malamulo zofunikira mu CentOS 7

Mu chifukwa anasonyeza kudzakhala mudziwe unyolo zitatu: "Muzifunsa", "linanena bungwe" ndi "MTSOGOLO" - ukubwera, kucheza ndi kutumiza magalimoto, motero.

View wa mndandanda wa malamulo onse zofunikira IPTables mu CentOS 7

Mukhoza chimatanthauza udindo wa maunyolo onse anapita Sudo IpTables -S.

Kusonyeza mndandanda wa IPTables madera zofunikira mu CentOS 7

Ngati malamulo anawona sanakhutire ndi inu, amangoika ali zichotsedwa chabe. Mndandanda wonse chitakonzedwa monga izi: sudo iptables -f. Pambuyo kutsegula, ulamuliro zidzachotsedwa mwamtheradi pakuti unyolo onse atatu.

Chotsani List Onse Malamulo IPTables Zothandiza mu CentOS 7

Pamene muyenera bwanji kokha ndondomeko ku unyolo ena osakwatiwa, mkangano zina anawonjezera kuti mzere:

Sudo IpTables -F Lowetsani

Sudo iptables -f linanena bungwe

Sudo IpTables -f Forward

Lambulani mndandanda wa malamulo enieni IPTABLES unyolo mu CentOS 7

Pakalibe onse akulamulira njira kuti palibe magalimoto imathandiza zoikamo sizigwiritsidwa ntchito mu gawo lirilonse. Lotsatira, woyang'anira dongosolo adzakhala paokha mwachindunji magawo atsopano ntchito kutonthoza chomwecho, lamulo mfundo zosiyanasiyana.

Kulandira ndi akuponya magalimoto maunyolo

Chingwe chilichonse chimakonzedwa mosiyana ndi kulandira kapena kutsekereza magalimoto. Mwa kukhazikitsa tanthauzo lina, zitha kukwaniritsidwa, mwachitsanzo, magalimoto onse omwe akubwera adzatsekeredwa. Kuti muchite izi, lamuloli liyenera kukhala supo zopangira katundu - dontho lolowera, komwe limatchulanso dzina la unyolo, ndipo dontho ndi mtengo wotuluka.

Kubwezeretsanso mafunso omwe akubwera mu ogwiritsira ntchito mu Entersos 7

Ndondomeko zomwezo zimakhazikitsidwa pazigawo zina, mwachitsanzo, kuyika kwa subzale - dontho lotulutsa. Ngati mukufuna kukhazikitsa mtengo wolandila magalimoto, kenako kutsika kuvomerezedwa ndipo kumatembenuka ku SuDo Kupsinjika Kuvomereza -

Kutha kwa port ndi loko

Monga mukudziwa, mapulogalamu onse netiweki ndi njira zimagwirira ntchito padoko linalake. Poletsa kapena kuthetsa ma adilesi ena, mutha kuwunika mwayi wopeza maukonde onse. Tiyeni tisanthule pandege yaphiri 80. Kutalikirana, zidzakhala zokwanira kulowa ndi Sudurts - Refert -p -P Tcheni, -P - Tanthauzo la Protocol pamenepa, TCP, A - A --DPoli ndi doko lopita.

Lamulo lotsegulira padoko 80 mu opsinjika ku Entertos 7

Lamulo lomweli likugwiranso ntchito pa doko 22, lomwe limagwiritsidwa ntchito ndi SHsh Services: SuDo Septors --P -p tcp -

Lamulo lotsegulira padoko 22 mu optaps Ogwiritsira ntchito mu malo 7

Kuti mutsetse doko lomwe mwalongosoledwa, chingwecho chimagwiritsidwa ntchito chimodzimodzi, kumapeto kwa kuvomereza kusintha kwake kuti agwetse. Zotsatira zake, zimakhala choncho, mwachitsanzo, kuyika kwa Sudo kukayikira - polowetsedwa --p tcp --dport 2450 -j kugwetsa.

Lamulo la Port Bale mu Zothandiza Kugwiritsa Ntchito mu Malo 7

Malamulo onsewa amalowetsedwa mu fayilo yosintha ndipo mutha kuwaona nthawi iliyonse. Tikukumbutsani, zimachitika kudzera ku SuDo Kupsinjika -. Ngati mukufuna kulola adilesi ya IP ndi doko limodzi ndi doko, chingwecho chimasinthidwa pang'ono - pambuyo pa TPC imawonjezeredwa - ndi adilesi yomweyo. SuDo Iptures - Refert Log --p Tcp -s 12.12.12/3/Kodi, 5.12/3 / Adilesi ya IP.

Lamulo lovomera ma adilesi a IP ndi doko mu zopsinjika mu malo 7

Kuletsa kumachitika pamlingo womwewo mwa kusintha kumapeto kwa kuvomerezedwa. Kenako zikuchitika, mwachitsanzo, iDo Inbles - Resolter -p -p Tcp -s 12.12.12.12.12/Kodi.

Lamulo loletsa ma adilesi a IP ndi doko mu zopsinjika mu malo 7

Kuletsa

ICMP (Pa intaneti Protocol) - protocol yomwe imaphatikizidwa ku TCP / IP ndipo imakhudzidwa ndikutumiza mauthenga olakwika ndi zochitika zadzidzidzi mukamagwira ntchito ndi magalimoto. Mwachitsanzo, seva yopemphedwa ilibe, chida ichi chimagwira ntchito. Zomwe zimagwirira ntchito zimakupatsani mwayi woti mutseke pamoto, ndipo mutha kuyipanga kugwiritsa ntchito Sudoble - Publm - mtundu wa 8 -j Kuponyera. Idzaletsa zofunsira kuchokera ku seva yanu.

Lamulo loyamba kuti muletse malo obowola mu malo 7

Zopempha zomwe zikubwera zimatsekedwa pang'ono. Kenako muyenera kulowa optafesa -ilo - polowetsa -p icmp - mtundu wa 8 -j kugwetsa. Pambuyo pa kukhazikitsa malamulowa, seva siyingayankhe zopempha za poing.

Lamulo lachiwiri kuti litseke zolembera mu optaps mu malo 7

Pewani zochita zosavomerezeka pa seva

Nthawi zina maseva amakhudzidwa ndi ma DDOS kapena zochita zina zosaloledwa kuchokera m'malo ozungulira. Kusintha kolondola kwa moto kumakuthandizani kuti mudziteteze ku mtundu uwu. Poyamba, timalimbikitsa kukhazikitsa malamulo awa:

  1. Timalemba m'magulu omwe amapezeka - polowera -p tcp --Dort, . Mutha kutchula gawo la mlingo, mwachitsanzo, / chachiwiri, / mphindi, / ora, / tsiku. - nambala yophulika - malire pa kuchuluka kwa phukusi lakusowa. Mfundo zonse zimawonetsedwa payekha malinga ndi zomwe akukhulupirira.
  2. Chitetezo cha chitetezo chochokera ku DDOS pakupsinjika mu malo 7

  3. Kenako, mutha kuletsa kuwerengera kwa madoko otseguka kuti muchotse imodzi mwazomwe zingachitike. Lowetsani woyamba wa SuDonts -n-Cock-Scan.
  4. Lamulo loyamba kuletsa madoko aiwork mu malo 7

  5. Kenako lingalirani za Sustors -a block-scan -p -p-flags ycps yolumikizidwa, ack, Fin, RET - RELL -J Bweretsani.
  6. Lamulo lachiwiri kuti lile madoko aiwork mu malo 7

  7. Lamulo lachitatu lotsiriza ndi: SuDo IFTORS -A block-scan -j kugwera. Mawu otchinga a block - dzina la dera lomwe adagwiritsidwa ntchito.
  8. Lamulo lachitatu kuti liletse doko la Scan la STATS mu Cretos 7

Zolemba zomwe zili lero ndizo maziko a ntchitoyi mu chipangizo chowongolera moto. Mu zolembedwa zovomerezeka za zomwe mungapeze zomwe zilipo zotsutsana ndi zosankha zomwe zilipo ndipo mutha kusintha moto wapamwamba pamalingaliro anu. Pamwamba pa malamulo achitetezo osatetezedwa, omwe nthawi zambiri amagwiritsidwa ntchito ndipo nthawi zambiri amafunikira.

Werengani zambiri