Phantse wonke umntu oSebenzayo uBuntu unomdla wokuqinisekisa ukhuseleko kwinethiwekhi yayo. Ukongeza, uninzi lusebenzisa izixhobo ezithile zenethiwekhi eziya kusebenza ngokuchanekileyo emva kokwenza imithetho ethile kwi-firewall. Namhlanje sifuna ukuthetha malunga nokucwangcisa i-firewall kumzekelo we-UFW (umlilo oswelekileyo). Esi sesona sixhobo silula sokumiliselwa kwemithetho yeMithetho yeFirewall, ke kuyacetyiswa kubasebenzisi be-novice kunye nabo bangoneliseki ukuba basebenza nzima kakhulu. Masingene ngenyathelo, cinga yonke le nkqubo yokuseta, ukrakra inyathelo ngalinye kwezona zichazwe kakhulu.
Qwalasela i-UFW kwi-Ubuntu
Awudingi ukufaka i-ufw kwinkqubo yokusebenza kuba ikhoyo apho ngokungagqibekanga. Nangona kunjalo, kwifom esemgangathweni, ayisebenzi kwaye ayinayo imithetho kwaphela. Okokuqala, siza kujongana nokusebenza, emva koko siqwalasele ezona zinto ziphambili. Nangona kunjalo, eyona nto iphambili kufuneka ihlolwe yi-syntax, kwaye ihlala ichaphazela abo basebenzisi baceba ukusebenzisa le firewall rhoqo.Inyathelo 1: Ukufunda iSyntax
Njengoko uyazi, i-UFW yindawo yokusebenza yekhonkco, okuthetha ukuba yenziwa ngokusebenzisa "isiphelo sendlela" okanye nawuphi na umsebenzisi. Ukunxibelelana kolu hlobo kwenziwa ngoncedo lwemiyalelo efakiweyo. Zonke zihlala zikumaxwebhu, kodwa azinangqondo ukufunda iqela elikhulu lezinto, ngakumbi kwimeko yesixhobo sanamhlanje. Umgaqo-nkqubo wegalelo ubonakala ngolu hlobo: I-Sudo Ufs Iparamitha. USudo unoxanduva lokuqhuba egameni le-superuser, i-UFW yingxoxo esemgangathweni ebonisa inkqubo ebizwa, kunye namabinzana aseleyo kwaye achaze imithetho efakiweyo. Yenzelwe abo sifuna ukuyeka ngakumbi.
- Yenza iparamitha esemgangathweni inoxanduva lokujika icime i-firewall. Kule meko, iya kongezwa ngokuzenzekelayo kwi-auto.
- Khubaza-ikhubaza i-ufw kwaye isuse kwi-auto.
- Phinda ulayishe- isetyenziselwa ukuqala i-firewall. Ichaphazeleka ikakhulu emva kokufaka imithetho emitsha.
- Ukungagqibeki-ibonisa ukuba ukhetho olulandelayo luya kufakwa ngokungagqibekanga.
- Ukungena-kuvula ukudalwa kweefayile zelog apho lonke ulwazi olusisiseko kwisenzo somlilo siyagcinwa.
- Seta kwakhona-ibuyisela kwakhona zonke iisetingi ukuya kumgangatho.
- Isimo-sisetyenziselwa ukujonga imeko yangoku.
- Veza-ukujonga ngokukhawuleza kweengxelo zomlilo. Izinketho ezongeziweyo zisebenza kule parameter, kodwa siya kuthetha ngazo ngenyathelo elahlukileyo.
- Vumela ubandakanyekile xa uyongeza imithetho evumayo.
- Uyakhanyela uyafana, kodwa ufake isicelo sokuthintela.
- Yala-yongeza ulawulo lokulahla.
- Umda-ukufaka imigaqo yokunciphisa.
- Cima - ususa umthetho ochaziweyo.
- Faka-faka umthetho.
Njengoko ubona, akukho maqela amaninzi. Zichanekile okanye ziphantsi kwezinye iindawo ezikhoyo zomlilo, kwaye ungakhumbula i-syntax emva kokuzama ukunxibelelana ne-UFW. Ihlala kuphela ukujongana nomzekelo woqwalaselo, ngala manyathelo alandelayo alandelayo avela kuyo.
Inyathelo 2: Vumela / Khubaza / Buyisa useto
Sigqibe kwelokuba ibalaselisa amaqela oqwalaselo oliqela kwinqanaba elinye, kuba badibene ngokuyinxenye kwaye bafana nokuphunyezwa. Njengoko sele uyazi, i-UFW iqala kwimo enqunyalisiweyo, ke masisebenzise ngokusebenzisa umyalelo omnye kuphela.
- Vula ipaneli ngezicelo kwaye uqhuba "i-terminal". Ungayivula i-console kunye nenye indlela efanelekileyo kuwe.
- Ngaphambi kokuba wenze isebenze, jonga, mhlawumbi ngaphambi kwakho okanye esinye isicelo sele senziwe i-firewall. Oku kwenziwa ngokungena kumyalelo we-sudo fu.
- Ngenisa igama eligqithisiweyo ukuze ufumane amalungelo aphezulu kwaye ucinezele nge-Enter. Qaphela ukuba kwangaxeshanye, oonobumba begalelo ababoniswanga kumqolo wokhuseleko.
- Kumgca omtsha uya kufumana ulwazi malunga nemeko yangoku ye-UFW.
- Ukusebenza komlilo kwenziwa ngeparamitha esele ikhankanywe apha ngasentla, kwaye wonke umyalelo ujongeka ngolu hlobo: Sudo Ufw yenza ukuba.
- Uya kwazisa ukuba i-Firewall yenziwe kwaye iya kubaleka kunye nenkqubo yokusebenza.
- Sebenzisa i-SUDOUW ikhubaza ukuvala phantsi.
- I-DeActivation iya kwazisa umyalezo ofanayo.
- Kwixa elizayo, ukuba ufuna ukuseta kwakhona imigaqo okanye kufuneka wenze le nto ngoku, faka uMyalelo weSudo Uft kwaye ucofe iqhosha le-ENTO.
- Qinisekisa ukusetwa ngokukhetha impendulo efanelekileyo.
- Uya kubona imiqolo emithandathu eyahlukeneyo ngedilesi ye-backup. Ungahamba nangaliphi na ixesha kule ndawo ukubuyisela iiparamitha.
Ngoku uyazi ukuba loluphi uhlobo lwamaqela anoxanduva lokulawula indlela yokuziphatha jikelele ye-firewall ethathelwa ingqalelo. Onke amanye amanyathelo aya kugxila kuphela kuhlobo, kwaye iiparamitha zinikwa njengomzekelo, oko kukuthi, kufuneka uzitshintshe, kufuneka uphinde uzifumane kwiimfuno zakho.
Inyathelo 3: Ukuseta imigaqo engagqibekanga
Kunyanzelekile, faka imithetho emiselweyo eya kunxibelelana nazo zonke izithintelo ezingenayo neziphuma zingakhankanywa ngokwahlukeneyo. Oku kuthetha ukuba lonke unxibelelwano olungenayo olungaboniswanga ngabantu kuya kuvalwa, kwaye ukuphuma nokuphuma kuphumelele. Isikimu sonke siphunyezwe ngolu hlobo lulandelayo:
- Sebenzisa iseshini entsha ye-console kwaye ufake i-sudo ofw engasasebenziyo. Yenza kuyo ngokucinezela iqhosha le-Enter. Ukuba sele uziqhelanise nemithetho ye-syntax ekhankanywe apha ngasentla, uyazi ukuba kuthetha ukuthintela lonke uqhagamshelo oluzayo.
- Kunyanzelekile, kuya kufuneka ufake ipaswedi engaphezulu. Uya kulukhankanya lonke ixesha xa uqala iseshoni ye-console entsha.
- Emva kokufaka umthetho, uya kwaziswa ukuba umthetho ongagqibekanga ungene kwi-Aces.
- Ngokuhambelana, kuya kufuneka usete umyalelo wesibini oza kucombulula imilinganiselo. Ijongeka ngathi: I-Sudo Ufw emiselweyo ivumela ukuphuma.
- Kwakhona umyalezo uvela kwisicelo somthetho.
Ngoku awukwazi ukukhathazeka malunga nenyani yokuba nayiphi na imizamo engenayo yokunxibelelana engaziwayo iya kuphumelela kwaye umntu othile uya kuba nakho ukufikelela kwinethiwekhi yakho. Ukuba awuyi kuvimba yonke imizamo yonxibelelwano engenayo, tsiba olu mthetho ungasentla kwaye uye kwindalo eyakho, funda inyathelo elilandelayo.
Inyathelo 4: Yongeza imithetho yakho ye-firewall
Imithetho yeFirewall-Olona khetho luphambili luhlengahlengiso lwabasebenzisi kwaye basebenzise i-UFW. Siza kuqwalasela umzekelo wemvume yokufikelela, kunye nokungalibali malunga nokuvinjwa ngamazibuko ngoku, jonga isixhobo se-OpenSsh. Ukuqala, kufuneka ukhumbule imiyalelo eyongezelelweyo ye-syntax enoxanduva lokusongeza imigaqo:
- Ufw vumela_na igama
- I-UFW ivumela izibuko
- I-UFW ivumela i-port / protocol
Emva koko, unokuqalisa ngokukhuselekileyo imigaqo evumayo okanye eyiyo. Masijongane nohlobo ngalunye lwezopolitiko ngolungelelwano.
- Sebenzisa i-SUDOWW ivumela i-Openshsh yokufikelela ekufinyeleleni kwinkonzo yenkonzo.
- Uya kwaziswa ukuba le mithetho ihlaziyiwe.
- Unokuvula ukufikelela ngokuchaza izibuko, hayi igama legama lenkonzo, elikhangeleka ngolu hlobo: Sudo Ufw Vumela 22.
- Inye into eyenzekayo kwiPort / Protocol - Sudo UFW Vumela i-22 / TCP.
- Emva kokwenza le mithetho, jonga uluhlu lwezicelo ezikhoyo ngokungena kuluhlu lwe-SUDOWW. Ukuba yonke into isetyenziswe ngempumelelo, inkonzo efunekayo iya kuvela kwenye yezi migca ilandelayo.
- Ngokuphathelele imvume kwaye kuthintele ugqithiso lwezithuthi phezu kwamazibuko, oku kwenziwa ngokungena kwi-UFW Vumela indlela ye-Syntax. Kwi-skrini, ubona umzekelo wesigqibo sendlela ephumayo kwizibuko (i-sudo fu vumela ukuba i-80 / TCP), kunye nokuthintela imigaqo-nkqubo enye kwicandelo (i-sudo fuw i-80 / TCP).
- Ukuba unomdla kumzekelo wokudibanisa umgaqo-nkqubo ngokufaka i-Syntax ebanzi ye-syntax, sebenzisa i-UFW CROCT PROCTOR MALI WE-MPTOCOM PROCTOC Umgaqo-nkqubo we-IP_nage to Port Port_Name.
Inyathelo 5: Ukufaka umda
Sizise isihloko sokufakelwa kwemithetho yokumisa umda kwinqanaba elahlukileyo, kuba kuya kuba yimfuneko ukuthetha ngakumbi malunga noku. Lo mgaqo unciphisa inani leedilesi ze-IP ezixhunyiwe kwizibuko elinye. Eyona nto isetyenziswayo yale parameter kukukhusela ekuhlaseleni okunemilinganiselo yokuhlawula. Ukufakwa kwemigaqo-nkqubo emiselweyo ngolu hlobo:
- Kwi-console, sudo fit umda i-ssh / tcp kwaye ucofe ku-Enter.
- Ngenisa igama eligqithisiweyo kwi-akhawunti yakho ye-Superuser.
- Uya kwaziswa ukuba uhlaziyo lwemithetho luphumelele ngempumelelo.
Ngendlela efanayo, imigaqo-nkqubo yezithintelo kunye nezinye iinkqubo zisekiweyo. Sebenzisa eli gama lenkonzo, izibuko okanye izibuko / iprotocol.
Inyathelo 6: Jonga imeko ye-UFW
Ngamanye amaxesha kuya kufuneka ubukele imeko yangoku ye-firewall hayi kuphela ngokomsebenzi, kodwa ikwamiselwe nemithetho. Kule nto, kukho iqela elahlukileyo esilithethileyo ngaphambili, kwaye ngoku siza kuyithatha ngakumbi.
- I-sunday sudo fit imeko yokufumana ulwazi olusezantsi.
- Imigca emitsha iya kubonisa yonke imigaqo-nkqubo emise iidilesi, imigaqo-nkqubo kunye namagama enkonzo. Kwilungelo lokulinganisa kunye nemikhombandlela.
- Ulwazi oluthe kratya luboniswa xa usebenzisa ingxoxo eyongezelelweyo, kwaye umyalelo ufumana uhlobo lwe-sudo fit imeko ye-sudo fit.
- Uluhlu lwazo zonke iigunya kwizinto ezingaqondakaliyo kubaqalayo lomsebenzisi ziboniswe ngombala we-sudo fuw obonisa i-Sudo UFW.
Kukho ezinye iindlela ezinokukhethwa ezibonisa ulwazi oluthile malunga nemithetho esele ikho kunye nemeko ye-firewall. Masibaleke kancinci sonke:
- I-Raw-ibonisa yonke imithetho esebenzayo isebenzisa ifomathi yokungenisa i-Iuphe Fables.
- Yakhiwe-kubandakanya kuphela imigaqo eyongezwe njengemithetho.
- Ngaphambi kweMigaqo-ibonisa imigaqo-nkqubo eyenziwe ngaphambi kokwamkela iphakheji evela kumthombo wangaphandle.
- Imigaqo yomsebenzisi-ngokulandelelana, ibonisa umgaqo-nkqubo ongezwe ngumsebenzisi.
- Imithetho yasemva kwe-emva yayo iyafana naphambi kweMigaqo, kodwa ibandakanya kuphela loo mithetho isebenzeleyo emva kokwenza iiphakheji.
- Imigaqo yokuGqibela-ibonisa ulwazi malunga neziganeko ezingenayo.
- Ukumamela-isetyenziselwa ukujonga ukusebenza (emamela).
- Yongezwe-ubandakanyeka xa ujonga imithetho yokongeza.
Ngexesha lokufuna wena, ungasebenzisa naluphi na onokukhetha ukufumana ulwazi olufunayo kwaye ulisebenzise ngeenjongo zakho.
Inyathelo 7: Cima imithetho ekhoyo
Abanye abasebenzisi, befumene ulwazi oluyimfuneko malunga nemithetho ekhoyo, banqwenela ukucima ezinye zazo ukuseka unxibelelwano okanye ubeke imigaqo-nkqubo emitsha. I-firewall ejongene nomlilo ikuvumela ukuba wenze oku ngalo naliphi na ixesha elikhoyo, eliqhutywa ngolu hlobo:
- Faka i-sudo fure cima i-80 / TCP yomyalelo. Iya kucima ngokuzenzekelayo umgaqo ovumela unxibelelwano oluphumayo ngePort / Iprotocol 80 / TCP.
- Uya kwaziswa ukuba umgaqo-nkqubo ususwe ngempumelelo zombini kwi-IPV4 ne-IPV6.
- Oku kuyasebenza kunxibelelwano oluthintelweyo, umzekelo, uSudo Ufw Cima ukuya kwi-80 / TCP.
Sebenzisa iindlela zokujonga imeko ukukopa imigaqo efunekayo kwaye uzicingele ngendlela efanayo njengoko kubonisiwe kumzekelo.
Inyathelo 8: Ukujika kwi-Logage
Inqanaba lokugqibela lenqaku lanamhlanje lithetha ukusebenza kwenketho enokuthi igcine ulwazi ngokuzenzekelayo kwifayile eyahlukileyo. Kuyimfuneko ukuba bonke abasebenzisi, kodwa basebenza ngolu hlobo:
- Bhala i-sudo ffu fick kwaye ucinezele i-Enter.
- Lindela isaziso sokuba lelog iza kusindiswa.
- Ungasebenzisa enye inketho, umzekelo, uSudo uff ukungena. Kusekho iphantsi (igcina ulwazi malunga neephakeji ezivaliweyo) kwaye iphakamileyo (igcina lonke ulwazi). Inketho e-avareji ibhala kwimagazini itshixiwe kwaye ivumela iipakethi.
Ngasentla ufundile kangangenyathelo ezisibhozo, ezisetyenziselwa ukuqwalasela i-UFW firewall kwinkqubo yokusebenza kobuntu. Njengoko ubona, le yindawo elula yomlilo, elungele abasebenzisi be-novice ngenxa yokufumana lula i-syntax. I-UFW isenokuba yinkalipho ukuba ibize indawo efanelekileyo yokutshintsha i-Imples