Cwangcisa i-IPIGS KWI-CENTOS 7

Anonim

Cwangcisa i-IPIGS KWI-CENTOS 7

Kuzo zonke iinkqubo zokusebenza ngokusekwe kwi-Linux kernel, kukho i-firewall eyakhelweyo, elawula kunye nokucoca izithuthi ezingenayo nezokusekwe kwiqonga elichaziweyo okanye iqonga elichaziweyo. ECenntos 7 Ukuhanjiswa, i-Iupebles Izixhobo zenza umsebenzi onjalo, ukunxibelelana ne-firewall eyakhiweyo. Ngamanye amaxesha umphathi wenkqubo okanye umphathi wenethiwekhi kufuneka aqwalasele ukusebenza kweli candelo, emisela imigaqo efanelekileyo. Njengenxalenye yenqaku lanamhlanje, singathanda ukuthetha malunga neziseko zoqwalaselo lwe-Iupebles kwi-OS ekhankanywe apha ngasentla.

Qwalasela i-IPEYS KWI-CENTOS 7

Isixhobo ngokwaso sifikeleleka ukusebenza kwangoko emva kokufakwa kwe-CENTOs 7 kugqityiwe, kodwa kuya kufuneka ukuba ufake iinkonzo, esiya kuthetha ngalo. Kwiqonga eliphantsi koqwalaselo ukhona esinye isixhobo esakhiweyo esisebenza ngomsebenzi we-firewall of Firewallld. Ukuthintela ukungqubana, ngomsebenzi ongaphezulu, sicebisa ukukhubazeka kweli candelo. Imiyalelo eyandisiweyo kwesi sihloko ifundwe kwenye impahla ngeli thuba ilandelayo.

Funda ngakumbi: Khubaza i-Firewald eCenntos 7

Njengoko uyazi, iiprotocol ze-IPv6 zinokusetyenziswa kwinkqubo. Namhlanje siza kugxila kumzekelo we-IPV4, kodwa ukuba ufuna ukuququmisa enye i-protocol, uya kudinga endaweni yeqela. Amagqabantshintshi. Ukusetyenziswa kwe-Console I-IP6Tebles.

Ukufakwa amaphiko

Ifanele ibe yeyona nto iphambili kwiNkqubo eyongezelelweyo yeNkqubo yokuSebenza ekuqwalaselweyo namhlanje. Baza kunceda ekubekeni imigaqo kunye nezinye iiparamitha. Ukulayisha kwenziwa kwindawo esemthethweni yokugcina, ngenxa yoko ayithathi ixesha elininzi.

  1. Zonke ezinye izinto ezenziwayo ziya kwenziwa kwikhonkco zeklasi, zibaleke nangayiphi na indlela efanelekileyo.
  2. Ukuqala i-terminal ukulungiselela ukusetyenziswa kwe-IPECES KWI-CENTOS 7

  3. I-Sudo yum Faka umthetho weenkonzo ze-Iupices unoxanduva lokufaka iinkonzo. Ngenisa kwaye ucinezele iqhosha le-ENTER.
  4. Ukufakelwa kweziphithiphithi eCentos 7

  5. Qinisekisa iakhawunti ye-Superuser ngokuchaza iphasiwedi kuyo. Nceda uqaphele ukuba xa imibuzo ye-sudo, oonobumba abangenayo kumqolo akaze babonakaliswe.
  6. Ngenisa igama eligqithisiweyo lokufaka i-IPOSES KWI-CENTOS 7 nge-terminal

  7. Kuya kunikwa ukongeza iphakheji enye kwinkqubo, qinisekisa le ntshukumo ngokukhetha i-y.
  8. Isiqinisekiso sokusongeza iiphakheji zenkonzo ezintsha ze-Centos

  9. Emva kokugqitywa kofakelo, jonga uhlobo lwangoku lwezixhobo: Sudo Ives-versionversions.
  10. Ukujonga inguqulelo ye-Uptables eSebenzayo eCentos 7 nge-terminal

  11. Iziphumo ziya kuvela kumtya omtsha.
  12. Ukubonisa inguqulelo yangoku yezigaba ze-iupys eCentos 7 nge-terminal

Ngoku i-OS ilungele ngokupheleleyo ukuqwalaselwa kwe-firewall ngokusebenzisa into esebenzayo. Sicebisa ukuba siqhelane noqwalaselo kwizinto, ukuqala ngeenkonzo zolawulo.

Ukuma kunye nokuqalisa iinkonzo ze-IPEYCS

Ulawulo lweModeli ye-Iuphecys iyafuneka kwiimeko apho ufuna ukukhangela isenzo semithetho ethile okanye uqalise nje icandelo. Oku kwenziwa kusetyenziswa imiyalelo ethengiweyo.

  1. Ngenisa i-SUDO YENKONZO YENKONZO YENKCAZO YAYEYIPHELE kwaye ucofe kwiqhosha lokungena ukuze uyeke iinkonzo.
  2. Ukumiswa kweenkonzo ze-IPTOCH kwi-CENTOS 7 nge-terminal

  3. Ukuqinisekisa le nkqubo, chaza igama eligqithisiweyo.
  4. I-password yokungena ukumisa impahla ye-IPOCY eCennto 7

  5. Ukuba inkqubo iphumelele, kuya kuboniswa umtya omtsha, ibonisa utshintsho kwifayile yoqwalaselo.
  6. Isaziso malunga nokumisa izicelo zenkonzo ye-Centos 7

  7. Ukuphehlelelwa kweenkonzo kwenziwa phantse ngendlela efanayo, kuphela umgca ofumana i-Sudo Inkonzo ye-Sudo Heemes qala.
  8. Sebenzisa iinkonzo ze-IPTEYs eCenntos 7 kwi-terminal

Ukuqala okufanayo, ukuqala okanye ukumisa izixhobo kuyafumaneka nangaliphi na ixesha, ungalibali ukubuyisela ixabiso elingasemva xa kuya kuba senkanuko.

Jonga kwaye ucime imithetho

Njengoko bekutshiwo ngaphambili, ulawulo lwe-firewall lwenziwa yincwadana okanye ngokuzenzekelayo. Umzekelo, ezinye izicelo ezongeziweyo zinokufikelela kwesi sixhobo, ukutshintsha imigaqo-nkqubo ethile. Nangona kunjalo, uninzi lwezenzo ezisele zenziwa ngesandla. Ukujonga uluhlu lwayo yonke imithetho yangoku iyafumaneka nge-SUDO

Veza uluhlu lwazo zonke iiMgaqo zokuSebenzisa i-Centos 7

Kumphumo obonisiweyo kuya kubakho ulwazi kumakhonkco amathathu: "Igalelo", "Iziphumo" kunye "ne" phambili "- engenayo, ngaphandle kunye nokudlulisela phambili.

Jonga lolu luhlu lwazo zonke iiMithetho zeZimvo ze-Centos 7

Ungachaza imeko yawo onke amakhonkco ngokufaka i-sudo izipho -s.

Ukubonisa uluhlu lweesekethe ze-IPEACE

Ukuba imigaqo ebonisiweyo ayoneliseki kunye nawe, basuswe nje. Olu luhlu luphela lucacile ngolu hlobo: Sudo Heades -F. Emva kokuba isebenze, umthetho uza kucinywa ngokupheleleyo kuwo onke amakhonkco amathathu.

Uluhlu olucacileyo lwazo zonke iiMigaqo iZaziso ze-IPOSES 7

Xa kufuneka uchaphazele kuphela imigaqo-nkqubo evela kwikhonkco elinye, impikiswano eyongezelelweyo yongezwa kumgca:

I-Sudo I-Igalelo -F igalelo

Imveliso ye-sudo

I-Sudo Icks -f phambili

Cacisa uluhlu lwemithetho ye-IPICO ekhethekileyo eCentos 7

Ukungabikho kwayo yonke imithetho kuthetha ukuba akukho seto lokukhala kwezothutho alusetyenziswa kuyo nayiphi na inxenye. Okulandelayo, umphathi wenkqubo uya kucacisa ngokuzimela iiparameter ezintsha zisebenzisa i-console enye, umyalelo kunye neengxoxo ezahlukeneyo.

Ukufumana kunye nokulahla ithroti kumakhonkco

I-chain nganye ilungiselelwe ngokwahlukeneyo ukuze ifumane okanye ivimba itrafikhi. Ngokumisela intsingiselo ethile, inokufezekiswa ukuba, umzekelo, zonke iindlela ezingenayo ziya kuvalwa. Ukwenza oku, umyalelo kufuneka ube sudo izipho-zehlelo lokufaka, apho igalelo ligama le-chain, kunye nehlayo lixabiso lokukhupha.

Hlela iNgxelo engenayo kwiPusieds

Ngokuchanekileyo iiparameter ezifanayo zimiselwe ezinye iisekethe, umzekelo, i-sudo izipho-zehlelo lehlelo. Ukuba ufuna ukumisela ixabiso lokufumana itrafikhi, emva koko ihla iguqukile kwi-yamkela kwaye ijika i-SUDO I-SUDO I-SUREICS

Isisombululo sePort kunye nokutshixa

Njengoko uyazi, zonke iinkqubo zenethiwekhi kunye neenkqubo zisebenza kwizibuko elithile. Ngokuthintela okanye ukusombulula iidilesi ezithile, unokujonga ukufikelela kuzo zonke iinjongo zenethiwekhi. Masihlalutye amachweba phambili ngomzekelo ka-80. Kwisiphelo sendlela, kuya kwanela ukungena kwi-Sudo Ippeds-I-IPPP -P ye-SCP -p i-SCP -P-JO-Igalelo elitsha I-chain, -I-IPROCOC Ingcaciso kule meko, i-TCP, i-o -dport yindawo ekuyiwa kuyo.

Umthetho wokuvula iPort 80 kwiPubles Straist eCennto 7

Kanye kanye umthetho ofanayo nako kuyasebenza nakwiiNkonzo zeSSH: Sudo Ippebles -A Igalelo -p TCP -DPOS 22 -U yamkelekile.

UMGAQO-NKQUBO WOKUVULA IINGXAKI ZEEMPAHLA KWI-CENTOS 7

Ukuvimba izibuko elichaziweyo, umtya usetyenziswa ngokuchanekileyo, kuphela ekupheleni kokutshintsha kweenguqu zokuhla. Ngenxa yoko, kuyavela, umzekelo, i-sudo medo i-igalelo

UMGAQO-NKQUBO WOKUXELWA KWE-PROOST KWI-CENTOS 7

Yonke le mithetho ingeniswa kwifayile yoqwalaselo kwaye ungabajonga nangaliphi na ixesha. Siyakukhumbuza, senziwa nge-sudo ives -l. Ukuba ufuna ukuvumela idilesi ye-IP yenethiwekhi kunye nezibuko kunye nezibuko, umtya uguquliwe kancinane-emva kokuba i-TPC yongezwa-i-TPC yongezwa-idilesi ngokwayo. I-Sudo I-Igalelo -P ye-TCP -s 12.12.12.1224:422 --9,32 - I-SPREP 22 -JONAL, Apho i-12.12.12.122 yidilesi efanelekileyo ye-IP.

Umthetho wokwamkela iidilesi ze-IP kunye nezibuko kwi-IPEGES KWI-CENTOS 7

Ukuvinjwa kwenzeka kumgaqo ofanayo ngokutshintsha ekuphelisweni kwexabiso lokwamkela ukwehla. Emva koko kuya kuvela, umzekelo, i-sudo i-sudo i-igalelo-le-tcp -s 12.12.12.0/224 --dport 22 -Jhlise.

UMGAQO-NKQUBO WOKUGQIBELA I-IP kunye nezibuko kwi-IPEGES KWI-CENTOS 7

I-ICMP Bloung

I-ICMP Umzekelo, xa iseva eceliweyo ayifumaneki, esi sixhobo senza imisebenzi yenkonzo. Isixhobo sokusebenza se-IPTEY siyakuvumela ukuba uyithintele kwi-firewall, kwaye ungayenza isebenzise i-sudo i-subles-i-ICMP -P ye-ICMMMMMMMMMMMMMMMMMMMP Kuya kuthintela izicelo ezivela kwiseva yakho nakwiseva yakho.

Umgaqo wokuqala ukuvimba i-ipydings i-cerks 7

Izicelo ezingenayo zivinjelwe kancinci. Emva koko kufuneka ufake i-sudo ivels -i I-IPMP -P ye-ICMMMMMMMMMMMMMMMMMMMMMMP Emva kokuvula le migaqo, umncedisi akayi kuphendula kwizicelo zePing.

UMGAQO WESITHATHU UKUZE UVULE UKUVUKA KWI-POGYS KWI-CENTOS 7

Thintela isenzo esingagunyaziswanga kwiseva

Ngamanye amaxesha iiseva ziphantsi kohlaselo lwe-DDOS okanye ezinye iintshukumo ezingagunyaziswanga kubangeneleli. Uhlengahlengiso oluchanekileyo lwe-firewall luya kukuvumela ukuba uzikhusele kolu hlobo lokukhosela. Ukuqala, sicebisa ukubeka imithetho enjalo:

  1. Sibhala kwi-IPEYS-I-IPPP -P ye-TCP -DPOP 80 -M-Mfutshane-Mfutshane-Jam-Jam-Jam . Unokuchaza iyunithi yemilinganiselo yakho, umzekelo, / yesibini, / umzuzu, / iyure, / usuku. Inombolo ye-GALIIT Onke amaxabiso abonakaliswa ngokukodwa ngokommiselo obalulekileyo woMlawuli.
  2. Umthetho wokhuseleko ovela kwi-DDOS kwi-IPEYS KWI-CENTOS 7

  3. Okulandelayo, ungathintela iskena samazibuko avulekileyo ukuze ususe enye yezizathu ezinokubangela. Ngenisa i-Sudo yokuqala ye-SUDO I-Vib-Nations.
  4. Umgaqo wokuqala wokuvala ama-Inpeys eCenntos 7

  5. Emva koko khankanya i-sudoicks-ibhloko-i-Skena -p TCP -TCP-IFLCP Syn, Ack, Fin -M Umda we-1 / s-s-s-s-s Under-gesit.
  6. Umgaqo wesibini wokuvala i-Impleys eCenntos 7

  7. Umyalelo wesithathu wokugqibela: Ibhlokhi yokubonisa ibhloko kwezi meko - igama lesekelo elisetyenzisiweyo.
  8. Umgaqo wesithathu wokuthintela izibuko leskena kwi-centos 7

Useto olubonisiweyo namhlanje sisiseko somsebenzi kwisixhobo sokulawula umlilo. Kumaxwebhu asemthethweni osetyenzisoyi kufumana inkcazo yazo zonke iimpikiswano ezikhoyo kunye nokukhetha kwaye unokucwangcisa i-firewall ngokukodwa izicelo zakho. Ngaphezulu kwemithetho yezokhuseleko esemgangathweni, ehlala isetyenziswa kwaye kwiimeko ezininzi ziyafuneka.

Funda ngokugqithisileyo