Gadzirisa firewall mu centsos 7

Anonim

Gadzirisa firewall mu centsos 7

Firewall yakaiswa mune yekushandisa system inoshandiswa kudzivirira isingatenderwa traffic pakati pemakomputa. Manual kana otomatiki inogadzira yakakosha mitemo yeiyo firewall, iyo ine mutoro wekutonga kwekuwana. MuOs, yakagadziriswa paLinux kernel, Centos 7 kune iyo Firewall-In firewall, uye inodzorwa neFirewall. Iyo default firewalld inobatanidzwa, uye isu tinoda kutaura nezvazvo nhasi.

Gadzira firewall muCentos 7

Sezvataurwa pamusoro apa, iyo standard firewall mu centos 7 inopihwa utility yekushandisa moto. Ndokusaka marimill em firewall ichakurukurwa pane iyo chiitiko chechishandiso ichi. Iwe unogona kugadza mitemo yekuputika pamwe chete neicho mukana, asi inoitwa zvishoma zvakasiyana. Isu tinokukurudzira kuzvijaira nekugadziriswa kwekutaurwa kwekushandisa nekudzvanya pane inotevera link, uye isu tizotanga kudzikisira kwemoto.

Kana iwe uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchitevera.

Verenga Zvimwe: Dzivisa Firewall muCentos 7

Wona mitemo yekuita uye inokwanisika nzvimbo

Kunyangwe nguva dzose firewall ine yayo chaiyo chaiyo mitemo uye nzvimbo dzinowanikwa. Usati watanga kugadzirisa kwezvematongerwo enyika, tinokupa zano kuti uzvizive nezvokugadziriswa kwazvino. Izvi zvinoitwa uchishandisa mirairo yakapusa:

  1. Iyo default zone ichaona iyo firewall-cmd - deget-default-zone command.
  2. Kuona iyo default firewall zone muCentos 7

  3. Mushure mekutora kwayo, iwe uchaona tambo nyowani panoratidzwa paramende yaunoda. Semuenzaniso, "nzvimbo yeruzhinji" inotariswa mune skrini pazasi.
  4. Kuratidza iyo default firewall zone mune muzana 7

  5. Nekudaro, nzvimbo dzinoverengeka dzinogona kushanda pakarepo, kunze kweizvozvo, ivo vakasungwa kune imwe nhoroondo. Tsvaga urwu ruzivo kuburikidza neFirewall-cmd --get-inoshanda-nzvimbo.
  6. Tarisa ese anoshanda pharyvol matunhu muCentos 7

  7. Iyo firewall-cmd - ndeyerist-rese rairo inoratidza iyo mitemo yakagadzirirwa nzvimbo yekufadzwa. Teerera kune iyo skrini pazasi. Iwe unoona kuti nzvimbo inoshanda "yeruzhinji" inopihwa iyo "default" mutemo - iyo default basa, iyo enp0s3 interface uye maviri masevhisi akawedzerwa.
  8. Wona mitemo yeanoshanda pharyvol matunhu kuburikidza neiyo terminal muCentos 7

  9. Kana iwe uine zvinodiwa kuti udzidze zvese zviripo zvinowanikwa firewall nzvimbo, pinda firewall-cmd - nzvimbo.
  10. Kuwana rondedzero yezvinhu zvese zviripo zve firewall nzvimbo kuburikidza neThe Terminal muCentos 7

  11. Iyo paramita yenzvimbo yakatsanangurwa kuburikidza neFirewall-Cmd - Cmd - Zita = zita - Zvese, zita rinonzi zita renzvimbo.
  12. Kuratidza mitemo yeiyo yakataurwa firewall nzvimbo kuburikidza neiyo terminal mune muzana 7

Mushure mekusarudza iyo inodiwa parameter, iwe unogona kutamira pakuchinja kwavo uye nekuwedzera. Ngationgororei vanoverengeka vevakakurumbira midziyo yakadzama.

Kumisikidza nzvimbo dzeInterface

Sezvaunoziva kubva kune ruzivo pamusoro, yako default zone inotsanangurwa kune imwe neimwe interface. Ichave iri mariri kusvikira marongero achinja mushandisi kana hurongwa. Izvo zvinokwanisika kuendesa maneja kune iyo nzvimbo pachikamu chimwe nechikamu, uye chinoitwa nekumisa iyo Sudo Firewall-Cmd - Command = Interface = eth0. Mhedzisiro "Kubudirira" kunoratidza kuti kuendesa kwakabudirira. Yeuka kuti zvigadziriso zvakadaro zvakagadzirwazve pakarepo mushure mekurerutsa moto wemoto.

Govera yakatarwa interface yeiyo firewall nzvimbo muCentos 7

Nekuchinja kwakadaro mumaperetera, inofanira kutakurwa mupfungwa kuti kushanda kwemasevhisi kunogona kugadzirwazve. Vamwe vacho havatsigire kushanda mune mamwe matunhu, ngatiti, shama kunyangwe inowanikwa mu "kumba", asi mushandisi kana service yakakosha ichaita. Ita shuwa kuti interface yakabudirira kusungirirwa kubazi idzva, nekupinda firewall-cmd - get-get-inoshanda-nzvimbo.

Wona iyo Inoshanda Phaervoola Zone uye Interface Yayo muCentos 7

Kana iwe uchida kugadzirisa iyo yakamboitwa magadzirirwo, ingozvimhanyisa resentart of the firewall: Sudo Systemctl restart firewalld.serviside.

Kutangazve firewall mushure mekuita shanduko kune zana

Dzimwe nguva hazviwanzo nyore nyore kuchinja nzvimbo interface muchikamu chimwe chete. Mune ino kesi, iwe uchafanirwa kugadzirisa iyo faira rekugadziriswa kuitira kuti zvigadziriswe zvese zvine kuzivikanwa zvachose. Kuti tiite izvi, tinokurayira kuti ushandise iyo nano mavara euritor, iyo yakaiswa kubva pakuchengetedza kwepamutemo kweSudo yum kuisa nano. Inotevera inoramba ichiita zviito:

  1. Vhura iyo faira yekugadzirisa kuburikidza neyekupindurwa nekupinda Sudo Nano / etc / sssconfig / Network-scripts / IFCFG-ETTL0, apo ETE0 izita reiyo inodiwa interface.
  2. Kuvhura iyo firevol interface yekugadziriswa faira muCentos 7

  3. Simbisa yako account account yekuita zvimwe zviito.
  4. Isa iyo password kuti uvhure faira rekugadziriswa kweiyo interface muCentos 7

  5. Dhizaini iyo "Zone" paramende uye shandura kukosha kwayo kune inodiwa, semuenzaniso, veruzhinji kana imba.
  6. Kuchinja nzvimbo interface kuburikidza nefaira rekugadzirisa muCentos 7

  7. Bata CTRL + O makiyi ekuchengetedza shanduko.
  8. Kurekodha shanduko muMutungamiriri Ekurapa Centers 7

  9. Usachinja zita refaira, asi ingo tinya pane Enter.
  10. Kugovera faira yekunyora shanduko mumasangano 7 zvinyorwa zvemavara

  11. Buda mupepeti wezvinyorwa kuburikidza neCTRL + X.
  12. Buda mudzidzisi wezvinyorwa mushure meCentos 7 Shanduko

Zvino nzvimbo interface ichave iyo yamakareva iyo, kusvika iyo inotevera kugadziriswa kwefaira rekugadzirisa. Zvemashoko akagadziridzwa, run sudo Sydoctl restart network.servic system restart restart firewalld.serviside.

Kuisa nzvimbo yekutarisa

Pamusoro, isu takatoratidza timu inokubvumira kuti udzidze nzvimbo yekufadzwa. Inogona zvakare kuchinjwa nekuisa paramende kusarudzo yako. Kuti uite izvi, mune console, zvakaringana kuinyoresa sudo firewall-cmd - default-default-zone = zita, zita rinonzi zita renzvimbo inodiwa.

Chinangwa cheiyo default firewall zone muCentos 7

Kubudirira kwemirairo kuchaoneka neyakanyorwa "kubudirira" mumutsara wakasiyana. Mushure meizvozvo, zvese zviripo zvazvinongozvarwa zvichazvarwa kune iyo yakatarwa zone, kana imwe yacho isina kutaurwa mumafaira ekugadzirisa.

Kubudirira Kuenda neDefault Zone muCentos 7

Kugadzira mitemo yezvirongwa uye zvinoshandiswa

Pakutanga chaiko kwechinyorwa, takataura nezve chiito chenzvimbo imwe neimwe. Kutsanangura masevhisi, zvinoshandiswa uye zvirongwa mumatavi akadaro zvinobvumidza kushandisa madhimoni emumwe neumwe wavo kune imwe neimwe yemashandisi. Kutanga, isu tinokupa zano kuti iwe uzvijaire neiyo yakazara rondedzero yemasevhisi inowanikwa panguva ino: firewall-cmd - masevhisi.

Murayiro wekutarisa unowanikwa muCentos 7 Sangano rebasa

Mhedzisiro yacho icharatidzwa zvakananga mumanyorero. Server yega yega yakakamurwa nenzvimbo, uye unogona kuwana nyore nyore chishandiso chauri kufarira. Kana basa rinodiwa riripo, rinofanira kuiswa. Pamitemo yekuisa, verenga muzvinyorwa zveSoftware.

Rondedzero yemasevhisi anowanikwa mune muzana 7

Murayiro uri pamusoro unoratidza chete mazita emasevhisi. Ruzivo rwakadzama rweumwe neumwe wavo rwakawanikwa kuburikidza nefaira romunhu pane iyo nzira / USR / Lib / Firewald / Services. Zvinyorwa zvakadaro zvine XML fomati, iyo nzira, semuenzaniso, kuita kuti ssh inoita kunge iyi: /usr/lib/firewalld/serv.xml, uye gwaro rine zvinotevera zvirimo:

Ssh.

Chengetedza Shell (SHH) iri protocol yekupinda mukati uye kuuraya mirairo pane michina kure. Iyo inopa yakachengeteka yakachengetedzwa kutaurirana. Kana iwe ukaronga pakuwana yako muchina kure kuburikidza neSsh pamusoro peiyo firewaled interface, gonesa iyi sarudzo. Iwe unoda iyo Opensh-server package yakaiswa pane iyi sarudzo kuti ibatsire.

Tsigiro yebasa inoitwa mune yakatarwa nzvimbo nemaoko. MuThe Terminal, iwe unofanirwa kuseta iyo Sudo Firewall-Cmd - yeruzhinji = Ruzhinji - Kunodhara Ziva kuti shanduko yakadaro ichave inoshanda chete mukati meimwe chikamu.

Kuwedzera sevhisi kune yakatarwa stone zone centos 7

Kuwedzeredzwa kwekusingaperi kunoitwa kuburikidza neSudo Firewall-Cmd - Genone = Ruzhinji - Service = HTTP, uye mhedzisiro "inoratidza kupedzwa kwekupedzisira kwekuvhiya.

Zvachose kuwedzera basa kune iyo FireVola Centos 7

Iwe unogona kutarisa rondedzero yakazara yemitemo yechigarire kune yakatarwa nzvimbo nekuratidzira runyorwa mumutsara wakasiyana weConsole: Sudo Firewall-Cmd - Genone = Ruzhinji - Rubarits - Services.

View rondedzero yeChisingagumi Firewall Sevhisi Centos 7

Dambudziko resarudzo nekushaikwa kwekuwana basa

Standard Firewall Mitemo inoratidzwa nemhando dzakakurumbira uye dzakachengetedzeka sekubvumirwa, asi zvimwe zviyero kana zvechitatu-bato-bato zvikumbiro zvazvinoshanda. Mune ino kesi, mushandisi wemunhu anofanirwa kuchinja marongero ekugadzirisa dambudziko nekuwana. Iwe unogona kuita izvi munzira mbiri dzakasiyana.

Portes Port

Sezvaunoziva, ese metwork masevhisi anoshandisa iyo chaiyo chiteshi. Iyo inoonekwa nyore nyore neiyo firewall, uye zvidhinha zvinogona kuitwa. Kuti udzivise zviito zvakadai kubva kuFirewall, iwe unofanirwa kuvhura chiteshi chemuti weSudo Firewall-Cmd - Ruzhinji = Portd-portp, uko - ingo - port = 0000 / tcp - port nhamba uye protocol. Iyo firewall-cmd - yeCmd-ports sarudzo inoratidza rondedzero yezvirimwa zvakavhurika.

Kuvhura kwechiteshi mune imwe nzvimbo yetiwall zone centos 7

Kana iwe uchifanira kuvhura madhiri akasanganiswa mune renji, shandisa sudo firewall-cmd tambo - yeruzhinji = yeruzhinji - 0000- uye protocol yavo.

Kuvhura chiteshi chikamu mune yakatarwa firevoola zone centos 7

Iwo mirairo iri pamusoro chete inobvumidza iwe kuti uedze kushandiswa kweakafanana paramita. Kana ikapfuura zvakabudirira, iwe unofanirwa kuwedzera iyo madhiri madiki ekugara, uye izvi zvinoitwa nekupinda Sudo Firewall-Cmd - Ruzhinji - Public - TCP kana Sudo Firewall-CMD - Zone = Ruzhinji --Permanent - DZVANYOR-Port = 0000-9999 / UDP. Rondedzero yezvakavhurika zvisingagumi zvirongwa zvinoonekwa seinotevera: Sudo Firewall-CMD --Zone = Ruzhinji - Reruzhinji --Ristman-Ports.

Tsanangudzo yebasa

Sezvauri kuona, zvigunwe zvinowedzera hazvikonzere chero matambudziko, asi maitiro akaomarara kana maficha achishandisa mari yakakura. Kutevedzera zvese zvinoshandiswa zviteshi zvinova zvakaoma, nekuda kwekusarudza kwebasa kuchave kwakaringana sarudzo:

  1. Kopa iyo yekugadzirisa faira nekunyora Sudo CP /usr/LiB/firewalld/servcald.xMLLD/ExML izita refaira rebasa, uye muenzaniso.xml ndiye zita remakopi ayo.
  2. Kopa faira faira refaira faira muCentos 7

  3. Vhura kopi kuti uchinje kuburikidza ne chero rugwaro rwekutaura, sugedo, sudo nano /etc/firewalld/services/exmx.xml.
  4. Kutanga Centers In 7 Service Faira

  5. Semuenzaniso, isu takagadzira kopi yeiyo http service. Mugwaro, iwe unoona zvakanyanya metadata, semuenzaniso, zita pfupi uye tsananguro. Inobata seva kuti ishandise chete shanduko yeiyo nhamba yechiteshi uye protocol. Pamusoro petambo "" inofanira kuwedzerwa kuti uvhure chiteshi. " TCP - yakashandiswa protocol, 0000 - nhamba yechiteshi.
  6. Kugadzirisa kufaira yebasa kune yakazaruka madhiri mune muzana 7

  7. Sevha zvese zvachinja (Ctrl + o), cvisa iyo faira (Ctrl + x), uye wozotangisa iyo firewall kuti ishandise paramita kuburikidza neSudo Firewall-cmd --Rourge. Mushure meizvozvo, iyo sevhisi ichaonekwa mune rondedzero inowanikwa, iyo inogona kutariswa kuburikidza neFirewall-Cmd - Gadziriro.
  8. Kutangazve iyo Firevol Service muCentos 7

Iwe unongofanira kusarudza mhinduro yakakodzera kune dambudziko rebasa nekuwana basa uye kuuraya mirayiridzo yakapihwa. Sezvauri kuona, zvese zviito zvinoitwa zviri nyore, uye hangofaniri kuve nematambudziko.

Kugadzira tsika nzvimbo

Iwe unotoziva kuti pakutanga nhamba yakakura yezvinhu zvakasiyana siyana nemitemo yakatsanangurwa yakagadzirwa mumoto. Nekudaro, mamiriro ezvinhu anoitika kana mutariri wesistimu achida kugadzira mushandisi nzvimbo, yakadai se "Publicweweb" yewebhusaiti yakaiswa "- kune iyo DNS server. Pane iyi mienzaniso miviri, tichaongorora kuwedzera kwematavi:

  1. Gadzira maviri idzva nzvimbo dzeSudo neSudo Firewall-Cmd --Permanent --new-zone
  2. Kuwedzera idzva mushandisi Zonelola zones centos 7

  3. Vachave varipo mushure mekudzosera iyo Sudo Firewall-Cmd --Rouloload chishandiso. Kuti uratidze zvigaro zvisingagumi, pinda iyo sudo firewall-cmd --permanent - nzvimbo.
  4. View inodhura firewall muCentos 7

  5. Vape masevhisi anodiwa, akadai se "SHS", "http" uye "HTTPS". Izvi zvinoitwa neSudo Firewall-Cmd - Cmd - Ruzhinji Wedzera- SEAST = HTTPS, kupi - Iko - Ruzhinji = RuzhinjiB izita renzvimbo yekuwedzera. Iwe unogona kutarisa chiitiko cheSevhisi naKumirira Firewall-CMD --Zone = Publicworld- zvese.
  6. Kuwedzera mabasa kune centos 7 mushandisi nzvimbo

Kubva pachinyorwa ichi, iwe wakadzidza maitiro ekugadzira matunhu ezvetsamba uye unowedzera masevhisi kwavari. Isu tatovaudza sezvazvinonzvera uye kugovera madhiri kumusoro, iwe unogona chete kudoma mazita akakodzera. Usakanganwa kutangazve iyo firewall mushure mekuita chero shanduko yekugara.

Sezvauri kuona, firewald firewall ishandiso yekushongedza inokubvumira kuti uite iyo isingachinjiki yekugadziriswa kweiyo firewall. Iyo inoramba ichingove nechokwadi chekuti iyo yekushandisa inouya nehurongwa uye mitemo yakataurwa ichitanga basa ravo. Ita iyo neiyo sudo systemctl inoita kuti Firewalld Command.

Verenga zvimwe