Hafi Abakoresha bose mu CentOS 7 gukwirakwiza bishobora iyinjizaporogaramu in A Sisitemu, kuko imikorere neza bikaba ushaka byambu Gufungura imibare runaka. Ibi ni ngombwa kugira isano isanzwe na ntirigwa umutekano guhanahana amakuru. Igikorwa rikorwa na guhindura amategeko firewall ku. Birumvikana, buri Umukoresha Koresha A zitandukanye firewalls, ariko ihame ni: in. Ni ku rugero rwe ko dutanga kugira byambu Gufungura, i Amabwiriza akurikira.
byambu Open mu CentOS 7
Atangiza byambu - Igikorwa ni Byoroheje, kuko ibyo ugomba kwinjira gusa amategeko bake mu console ku. Ariko, niba ikubitiro ntibyatumye Igenamiterere y'inyongera na firewall cyangwa gukoresha igikoresho cyagatatu, muzobwirizwa Vyongeye Guhindura Ibigenga ngombwa. Rero, turi ibice ngingo yacu byiciro kugira ngo Abakoresha munyeshuri bari kworoha kwihanganira buri ntambwe, maze ubu reka gutangira na installation kanya: in i CentOS 7.Intambwe 1: mucabyi cyangwa: in update
Nk'uko byavuzwe haruguru,: in i CentOS 7 ibikorwa nk'uko firewall a Mburabuzi. Niba intoki nta mpinduka bagizwe, ushobora amahoro skip ntambwe by gusa stage nyuma na installation ya firewall utility. Niba ukeneye kugenzura agezweho cyangwa re-installation gikoresho, turi inama gukoresha manual bikurikira.
- Ibikorwa byose bivugwa muri iki gihe kuba mu "Bihera", kugira byose bitangirana na mugaragaro yayo. Koresha & Ctrl + Alt + T hot Urufunguzo Cyangwa Agashushondanga Kyongewe Kuri "Favorites" igice mu Ibikubiyemo Porogaramu.
- Hano yinjira mu Ikwirakwiza Yum Install command: in, na Hanyuma Kanda ku Kwinjira urufunguzo.
- Kwemeza iri tegeko, uzokenera Kugaragaza superuser password. Rimbura ko na Ubwoko iyi nyandiko, Inyuguti yinjira ntabwo yagaragaje.
- Uzoba kumenyeshwa ko iyinjizaporogaramu cyangwa update ni neza ruganda. Niba inyandiko latest ya: in ni Kyongewe Kuri i Sisitemu, i Verisiyo nyuma: in ni Kyongewe, i Ikurikiranyanyuguti "gukora ubusa" ku i Mugaragaza.
- Uzuza iyi ntambwe na Ikwirakwiza Yum -y Install: in-Serivisi command. Ibi mugaragaro installation ya serivisi ngombwa.
- Ushobora kujya ntambwe ikurikira iyo ubutumwa asa ku Mugaragaza ku Uretse neza ya biyagize.
Intambwe ya 2: Kugarura amategeko asanzwe ya firewall
Niba abakoresha cyangwa umukoresha batagizwe mbere yumuyobozi wa sisitemu cyangwa umukoresha, igenamiterere risanzwe rigomba gutaka ko ejo hazaza ntakibazo cyo guhuza amategeko. Byongeye kandi, bizaba ngombwa kwerekana amategeko asanzwe, kugirango ukemure neza ishyirwa mu bikorwa ry'ibice byinjira kandi bisohoka. Ibi byose bibaho gutya:
- Kwinjira mu: in -L -L -V -n itegeko mu console bwo kubona urutonde Ibigenga ubu.
- Niba badakubereye, noneho ugomba gusubiramo no kuboneza intoki.
- Gusiba amategeko ariho bikorwa ukoresheje umurongo umwe sudo iptable -f.
- Ibikurikira, emerera amakuru yose yinjiye muri seriveri, shyiramo Sudo Iptables -injiza -i lo -j yemera.
- Kubihuza bisohoka, hafi yibanze ikurikizwa: Sudo Iptables -Umusohoka -O Lo -J Wemeye.
- Birasabwa kugabanya amasano mashya no kwemerera abariho kurinda umutekano no gushiraho umurimo wamategeko yerekanwe. Bibaho binyuze muri Sudo Iptables -Umunjiza -m leta - ishyirwaho, bijyanye -j yemera.
Ibindi bikoresho byose byafatwa nkibisanzwe bikozwe mu ntoki, harimo ibyambu bimbumba. Tuzavuga kubyerekeye ingingo yanyuma muntambwe zikurikira, kandi iboneza ryagutse ntabwo rikubiye murwego rwibikoresho byuyu munsi. Ahubwo, turagusaba kumenyera ibikoresho byihariye byamahugurwa kuriyi ngingo, ukoresheje ihuza hepfo.
Soma Ibikurikira: Gushiraho Iptable muri Centos 7
Intambwe ya 3: Hagarika Firewalld
Kuri iyi ntambwe, ugomba kureba abakoresha mbere bashyizeho umuriro cyangwa wongeyeho mu buryo bwikora. Mugihe ushyiraho ibyambunze ibyanditswe, iki gikoresho kirashobora kubangamira kurangiza amategeko, bityo bizaba ngombwa kugirango uhagarike.
- Ubwa mbere, hagarika serivisi binyuze muri sudo sisitemu ihagarika firewalld.
- Ibikurikira, kora ushikamye ukoresheje sudo sisitemu ya sudo systemstl guhagarika itegeko.
- Uzakira amakuru ahuza ikigereranyo yasibwe, bityo, Firewanld ntabwo yiruka kuriyi ngingo.
Niba ushaka gusiba ububiko bwububiko bugenewe igenamiterere ryakariro hejuru yamategeko yavuzwe haruguru, shyiramo imirongo ikurikira muri terminal igaragara hepfo hanyuma ubikoreshe.
rm '/etc/systemd/system/system/dbus-org.ibikoresho.frodora ofpect.firalDailld1.Service'.Service'.Service'
RM '/etc/Systemd/System/System/basic.target.Bants/firewalld.Service.
Mugihe kizaza, umukoresha wese arashobora gukenera ibikorwa nibisobanuro bya firewalld, cyane cyane mugihe ugomba gukorana na seriveri zitandukanye. Turasaba gukora ibi ukoresheje imfashanyigisho zikurikira.
Soma birambuye: Kugena Firewall muri Centos 7
Intambwe ya 4: Ibimenyetso bifungura binyuze muri iptable
Igihe kirageze cyo gukora igikorwa cyibanze, cyitangiye ingingo yuyu munsi. Hejuru, twakoze rwose umurimo wo kwitegura cyane kuri ubu kuri ubungubu ibyambu bifunguye muri Cenos 7. Noneho ntihagomba kubaho ikibazo kuri ibi, kugirango winjire mumategeko akurikira.
- Mu maboko, ongeraho firewall ku mukoresha, kugirango utayikore buri gihe. Ibi bizafasha sudo gahunda ishobote iptable.
- Uzabimenyeshwa kurema umurongo wikigereranyo.
- Koresha uburenganzira bwo gukomeza uburenganzira bwinjira winjira muri iki kugirango buri tegeko ryiyi ngingo yiyi ngingo idakenewe kugirango ikitire Sudo.
- Emeza iki gikorwa wandika ijambo ryibanga.
- Fungura icyambu hejuru ya Iptables -i kwinjiza -p tcp --dport 22 -m leta - aho guhera, aho 22 usimbuze umubare usabwa.
- Urashobora guhita ufungura icyambu gikurikira, kurugero, kuri numero 25 (SMTP seriveri). Kugirango ukore ibi, andika Iptables -i kwinjiza -p tcp --dport 25 -m - leta nshya - emera.
- Bika impinduka zose ushyiramo serivisi iptables kubika umugozi.
- Uzamenyeshwa ko iboneza ryakoreshejwe neza.
- Ongera utangire firewall kugirango impinduka zose zikurikire. Ibi bikorwa binyuze muri sisitemu yo gutangira gusa.
- Kurangiza, dutanga gukoresha Sudo Iptables -nvl kugirango dusuzume ibyambu byose bifunguye.
Muri iki kiganiro, wize byose kubyerekeye ibyambu bifungura ibyambu bya Centos 7. Nkuko mubibona, ntibizatwara igihe kinini, kandi impinduka zose zizakoreshwa nyuma yo gutangira serivisi. Koresha amategeko yavuzwe haruguru muguhindura gusa nimero yicyambu kugirango ibintu byose bigenda neza.