Firewall yashizwe muri sisitemu y'imikorere ikoreshwa mu gukumira traffike itemewe hagati yimiyoboro ya mudasobwa. Igitabo cyangwa gihita gitanga amategeko yihariye ya firewall, ashinzwe kugenzura. Muri OS, yateye imbere kuri kernel ya Linux, CONTOS 7 hari firewall yubatswe, kandi igenzurwa na firewall. Umuriro usanzwe urimo, kandi turashaka kubiganiraho uyu munsi.
Hindura Firewall muri Centos 7
Nkuko byavuzwe haruguru, firewall isanzwe muri Centos 7 yahawe agaciro firewal. Niyo mpamvu igenamigambi rya firewall rizasuzumwa kurugero rwiki gikoresho. Urashobora gushiraho amategeko ashungura hamwe nazo rimwe gusa, ariko birakorwa bitandukanye gato. Turasaba kubimenyereye hamwe niboneza ryingirakamaro ukanze kumurongo ukurikira, kandi tuzatangira kwicika intege.Niba umaze guhagarika by'agateganyo cyangwa burundu guhagarika firewall, turagugira inama yo gukoresha amabwiriza yatanzwe muyindi ngingo ukurikije umurongo ukurikira.
Soma birambuye: Hagarika Firewall muri Centos 7
Reba amategeko asanzwe hamwe na zone zihendutse
Ndetse na firewall isanzwe ifite amategeko yayo asobanutse hamwe na zone. Mbere yo gutangira guhindura umunyapolitiki, turagugira inama yo kumenyera iboneza riho. Ibi bikorwa ukoresheje amategeko yoroshye:
- Agace gasanzwe kazerekana firewall-CMD - itegeko-risanzwe.
- Nyuma yo gukora, uzabona umugozi mushya aho parameter yifuzwa izerekanwa. Kurugero, "ahatabaye" "bisuzumwa mumashusho hepfo.
- Ariko, uduce twinshi turashobora guhita dukora, usibye, bafitanye isano nimikorere itandukanye. Shakisha aya makuru ukoresheje Firewall-CMD --Gege-Zone-Zones.
- Firewall-CMD - itegeko ryose rizerekana amategeko yashyizweho kuri zone isanzwe. Witondere amashusho hepfo. Urabona ko rubanda rukora "rubanda" rwahawe itegeko "risanzwe" - imikorere isanzwe, intera enp0s3 Imigaragarire na serivisi ebyiri zongeweho.
- Niba ufite icyifuzo cyo kwiga ahantu hose haboneka firewall, andika Firewall-CMD - Zone.
- Ibipimo byakarere runaka bisobanuwe binyuze kuri firewall-cmd --Zone = izina - byose, nihe izina ryakarere.
Nyuma yo kumenya ibisabwa bisabwa, urashobora kwimukira mumpinduka zabo hanyuma wongere. Reka dusesengure inshuro nyinshi zigezweho muburyo burambuye.
Gushiraho interineti
Nkuko mubizi kumakuru hejuru, agace kawe gasanzwe gasobanurwa kuri buri nterineti. Bizaba birimo kugeza igenamiterere rihindura umukoresha cyangwa gahunda. Birashoboka kwimura intoki umurongo kuri zone kuri buri somo, kandi bikorwa mugukora sudo firewall-cmd --Zone = Urugo Itegeko - Itegeko-Imigaragarire = eth0. Igisubizo "Intsinzi" yerekana ko iyimurwa ryagenze neza. Wibuke ko igenamiterere nkiryo risubirwamo nyuma yo kongera gukoresha firewall.
Hamwe nimpinduka nkiyi mubipimo, bigomba kwizirikana ko imikorere ya serivisi ishobora gusubirwamo. Bamwe muribo ntibashyigikiye imikorere ahantu runaka, reka tuvuge, SSH nubwo igerwaho "murugo", ariko mumukoresha cyangwa serivisi idasanzwe izakora. Menya neza ko interineti yahujwe neza nishami rishya, yinjira muri firewall-cmd --ge-akarere.
Niba ushaka gusubiramo igenamiterere ryakozwe mbere, kora gusa ubwunganire bwa firewall: sudo sisitemu yo gutangira firewal.Service.
Rimwe na rimwe, ntabwo buri gihe byoroshye guhindura interineti mugice kimwe gusa. Muri iki gihe, uzakenera guhindura dosiye iboneza kugirango igenamiterere ryose rishyizwe ku buryo buhoraho. Kugira ngo dukore ibi, turagugira inama yo gukoresha umwanditsi wa Nano, tukabarwa mububiko bwemewe bwa Sudo Yum shyira nano. Ibikurikira biracyari ibyo bikorwa:
- Fungura dosiye iboneza ukoresheje umwanditsi winjiye sudo nano / etc / sysconfig / umuyoboro-etcfg / eth0, aho eth0 nizina ryibisabwa.
- Emeza konte yawe kwemeza kugirango ukore ibindi bikorwa.
- Imiterere ya "Zone" kandi igahindure agaciro kayo, kurugero, rusange cyangwa murugo.
- Fata Ctrl + o urufunguzo kugirango uzigame impinduka.
- Ntugahindure izina rya dosiye, ariko kanda gusa kuri Enter.
- Sohoka umwanditsi wanditse muri Ctrl + X.
Noneho inkomoko ya interineti izaba imwe wabigaragaje, kugeza ubutaha guhindura dosiye iboneza. Kubipimo bigezweho, koresha sudo gahunda ya sisitemu yo gutangira imiyoboro.service na sudo sisitemu yo gutangira firewanld.Service.
Gushiraho akarere gasanzwe
Hejuru, tumaze kwerekana ikipe igufasha kwiga akarere gasanzwe. Irashobora kandi guhinduka mugushiraho ibipimo kubyo wahisemo. Kugirango ukore ibi, muri konsole, birahagije kwiyandikisha SUDO Firewall-CMD - isanzwe-ya zone = izina, niryo izina, nizina ryizina rya zone isabwa.
Intsinzi y'Itegeko rizagaragaramo ko inyandiko "intsinzi" mu murongo wihariye. Nyuma yibyo, interineti zose zubu zizavuka kuri zone yagenwe, niba irindi ridasobanuwe muri dosiye iboneza.
Gukora amategeko kuri gahunda na Urwego
Mu ntangiriro yingingo, twaganiriye kubikorwa bya buri karere. Gusobanura serivisi, ibikorwa na gahunda mumashami bigomba kwemerera gukoresha ibipimo byihariye kuri buri kimwe muri buri mukoresha. Kugirango dutangire, turagugira inama yo kumenyera urutonde rwuzuye rwa serivisi ziboneka muriki gihe: Firewall-CMD - Serivisi.
Igisubizo kizerekanwa muri konsole. Buri seriveri igabanijwe numwanya, kandi urashobora kubona byoroshye igikoresho ushimishijwe. Niba serivisi ikenewe ibuze, igomba kuba yarashyizweho. Ku Mategeko yo kwishyiriraho, soma mubyangombwa bya software.
Itegeko ryavuzwe haruguru ryerekana gusa amazina ya serivisi. Ibisobanuro birambuye kuri buri kimwe muri byo kiboneka binyuze muri dosiye kugiti cye kumuhanda / usr / lib / firewalld / serivisi. Inyandiko nkizo zifite imiterere ya XML, inzira, kurugero, kuri ssh isa nkiyi: /USR/Firewalld/Sh.xml, kandi inyandiko ifite ibiyiti bikurikira:
Ssh.
Igikonoshwa kitekanye (ssh) ni protocole yo kwinjira no gukora amategeko kumashini ya kure. Itanga itumanaho ryizewe. Niba uteganya kugera kuri mashini yawe ukoresheje ssh hejuru yimikorere yaka umuriro, fasha ubu buryo. Ukeneye paki ya Opensh-seriveri yashyizwe kuriyi nzira kugirango ingirakamaro.
Inkunga ya serivisi ikora muri zone runaka intoki. Muri terminal, ugomba gushyiraho sudo firowall-cmd --Zone = rusange - Serivise = APORT-PORMOMS-REVER-SERIVISI-SERIVISI = HTTP - Izina rya serivisi. Menya ko impinduka nkizo zizemezwa gusa mugihe kimwe.
Kwiyongera guhoraho bikorwa binyuze muri Sudo Firewall-CMD --Zone = rusange - PORTMBent - SERIVISI = HYP, na ibisubizo "gutsinda" byerekana kurangiza neza ibikorwa.
Urashobora kureba urutonde rwuzuye rwakarere runaka ugaragaza urutonde mumurongo wihariye wa konsole: sudo firewall-cmd --Zone = rusange - serivisi-rusange.
Ikibazo cyo gufata ibyemezo kubwo kubura serivisi
Amategeko asanzwe ya firewall agaragazwa nibikorwa bizwi cyane kandi bifite umutekano nkuko byemewe, ariko porogaramu zisanzwe cyangwa za gatatu zihagarara. Muri iki kibazo, umukoresha akeneye gufata intoki kugirango ahindure igenamiterere kugirango bakemure ikibazo. Urashobora kubikora muburyo bubiri butandukanye.
Icyambu
Nkuko mubizi, serivisi zose zurusobe zikoresha icyambu cyihariye. Bigaragara byoroshye na firewall, kandi ibirungo birashobora gukorwa. Kugira ngo wirinde ibikorwa nkibi muri firewall, ugomba gufungura icyambu cyifuzwa cya sudo firewall-cmd --Zone - Port-Port-TCP, AHO - URUBUGA Port = 0000 / TCP - Umubare wa Port na protocole. Firewall-CMD - Ihitamo ryanditse rizerekana urutonde rwibyambu bifunguye.
Niba ukeneye gufungura ibyambu birimo intera, koresha SMD Umugozi wa SMDewall --Zone = rusange - Port-Icyambu = 000099 / UDP - Urubanza na protocole yabo.
Amabwiriza yavuzwe haruguru akwemerera kugerageza gukoresha ibipimo bisa. Niba yaranyuze neza, ugomba kongeramo ibyambu bimwe, kandi ibi bikorwa winjiza sudo firewall-cmd --Zone = rusange - PMP ya TCP cyangwa SudoWall-CMD - Zone = rusange --permanent - icyambu = 0000-9999 / UDP. Urutonde rwibimenyetso bihamye bifatwa nkibi bikurikira: SMDO Firewall-CMD --Zone = rusange - Prissmant - Ibyambu.
Ibisobanuro bya serivisi
Nkuko mubibona, ongeraho ibyambu ntibitera ingorane, ariko inzira iragoye mugihe ibyifuzo bikoresha amafaranga menshi. Gukurikirana ibyambu byose byakoreshejwe biragoye, urebye ko kwiyemeza serivisi bizaba byoroshye amahitamo:
- Gukoporora dosiye iboneza ukoresheje Sudo Cp /USR/Firewalld/Serml /SEMLY IZINA / Urugero rwa dosiye ya serivisi, nurugero.xml ni Izina rya kopi zayo.
- Fungura kopi kugirango uhindure ukoresheje inyandiko iyo ari yo yose, kurugero, sudo nano /etc/firewalld/seamplevices/zemple.xml.
- Kurugero, twashizeho kopi ya serivisi ya HTTP. Muri inyandiko, ukubonaga ahanini metadata zitandukanye, kurugero, izina rigufi namagambo. Ireba seriveri gukora gusa impinduka za nimero yicyambu na protocole. Hejuru yumugozi "" ugomba kongerwaho kugirango ufungure icyambu. TCP - Yakoreshejwe Porotokole, a 0000 - nimero ya Port.
- Bika impinduka zose (Ctrl + o), Funga dosiye (Ctrl + X), hanyuma utangire firewall kugirango ukoreshe ibipimo binyuze muri Sudo Firewall-CMD --ReTaLe. Nyuma yibyo, serivisi izagaragara kurutonde rwibiboneka, ishobora kurebwa binyuze muri Firewall-CMD - Serivisi.
Ugomba guhitamo gusa igisubizo gikwiye kubibazo bya serivisi kugirango ubone serivisi kandi usohoze amabwiriza yatanzwe. Nkuko mubibona, ibikorwa byose bikorwa byoroshye, kandi ntihagomba kubaho ingorane.
Gukora ahantu gakondo
Usanzwe uzi ko mu ntangiriro umubare munini wibice bitandukanye hamwe namategeko yasobanuwe muri Firewalld. Ariko, ibihe bibaho mugihe umuyobozi wa sisitemu akeneye gukora akarere k'umukoresha, nka "Reserweb" kuri web urubuga rwashyizweho cyangwa "kwikorera kuri interineti" - kuri seriveri ya DNS. Kuri izi ngero zombi, tuzasesengura kongeramo amashami:
- Kora uturere twose duhoraho na sudo firewall-cmd --permanent --new-zone = cmdwob na sudo firewall-cmd - cmd - zone = zone.
- Bazaboneka nyuma yo kongera kwishyura ibikoresho bya SMD - CMD --Beload. Kugaragaza uturere duhoraho, andika sudo firewall-cmd --permanent - aho-zone.
- Kubaha serivisi zikenewe, nka "ssh", "http" na "https". Ibi bikorwa na Sudo Firewall-CMD --Zone = Umunyamakuru Wedweb - Umunyamakuru-Servineb - CMDWob Ongeraho- serivisi = HTTPS, aho - Manzane = magicswab nizina rya zone kugirango wongere. Urashobora kureba ibikorwa bya serivisi mugutegereza Firewall-cmd --Zone = Umunyamakuru wa Recweb - Byose-Byose.
Duhereye kuriyi ngingo, wize gukora ahantu fatiro kandi wongere serivisi kuri bo. Tumaze kubabwira intera yo hejuru no gutanga ibisobanuro hejuru, urashobora kwerekana gusa amazina yukuri. Ntiwibagirwe gutangira firewall nyuma yo guhindura ikintu cyose gihoraho.
Nkuko mubibona, firewall firewall nigikoresho cya ecficly yagufasha gukora iboneza rya firewall. Biracyahari gusa kugirango umenye neza ko ibikorwa byatangiriye kuri sisitemu namategeko yihariye ahita atangira akazi kabo. Bikore hamwe na sudo sisitemu ishoboza firewalld itegeko.