Cishe wonke umsebenzisi wobuntu obusezingeni eliphezulu unentshisekelo ekuqinisekiseni ukuphepha kwinethiwekhi yawo. Ngaphezu kwalokho, abaningi basebenzisa izinsiza ezithile zenethiwekhi ezizosebenza kahle ngemuva kokwenza imithetho ethile kwi-firewall. Namuhla sifuna ukukhuluma ngokulungiselela i-firewall esibonelweni se-UFW (i-firewall elula). Leli yithuluzi elilula kakhulu lokusebenzisa imithetho ye-firewall, ngakho-ke kunconyelwa abasebenzisi be-novice nalabo abangagculiseki ngokusebenza okuyinkimbinkimbi kakhulu kwe-Ippeble. Asinyathelo ngesinyathelo ngesinyathelo, cabanga ngayo yonke inqubo yokusetha, hlanganisa zonke izinyathelo ngobuningi kakhulu ngangokunokwenzeka.
Lungiselela i-UFW e-Ubuntu
Awudingi ukufaka i-UFW ohlelweni lokusebenza ngoba ikhona lapho ngokuzenzakalelayo. Kodwa-ke, ngefomu elijwayelekile, alisebenzi futhi alinamithetho nakancane. Okokuqala, sizobhekana nokwenza kusebenze, bese sibheka izenzo eziphambili. Kodwa-ke, okubaluleke kakhulu kufanele kuhlolwe nge-syntax, futhi kuvame ukukhathazeka labo basebenzisi abahlela ukusebenzisa lesi sicishamlilo ngokuqhubekayo.Isinyathelo 1: Ukutadisha i-Syntax
Njengoba wazi, i-UFW iyisisetshenziswa se-console, okusho ukuthi kwenziwa nge- "terminal" ejwayelekile noma omunye umsebenzisi. Ukuxhumana kwalolu hlobo kwenziwa ngosizo lwemiyalo efakwe ngokukhethekile. Zonke zihlala zisezincwadini, kepha akunangqondo ukufunda inqwaba yezinto zokwakha, ikakhulukazi esimweni sensimbi yanamuhla. Umgomo wokufaka ubukeka kanjena: Amapharamitha wesenzo se-Sudo UFW. I-Sudo ibhekele ukugijima egameni leSuperuser, i-UFW yingxabano ejwayelekile ekhombisa uhlelo olubizwa ngokuthi yi-imeyili, nemishwana esele futhi ichaze imithetho efakiwe. Kungenxa yabo ukuthi sifuna ukuma ngemininingwane eminingi.
- Nika amandla i-parameter ejwayelekile ebhekele ukuvula i-firewall. Kulokhu, kuzongezwa ngokuzenzakalela ku-autoad.
- Khubaza - ukhubaza i-UFW futhi uwususe kusuka ku-autoload.
- Layisha kabusha - Kusetshenziselwa ukuqala kabusha i-firewall. Ikakhulu esebenza ngemuva kokufaka imithetho emisha.
- Okuzenzakalelayo - Kusho ukuthi inketho elandelayo izofakwa ngokuzenzakalelayo.
- Ukungena ngemvume - kusebenze ukudalwa kwamafayela we-log lapho yonke imininingwane eyisisekelo esenzweni yesicishamlilo izogcinwa.
- Setha kabusha - Setha kabusha wonke izilungiselelo kuze kufinyelele ezijwayelekile.
- Isimo - Sisetshenziselwa ukubuka isimo samanje.
- Khombisa - ukubukwa okusheshayo kwemibiko ye-firewall. Izinketho ezengeziwe zisebenza kule pharamitha, kepha sizokhuluma ngabo esinyathelweni esihlukile.
- Vumela ukuhileleka lapho wengeza imithetho evumayo.
- I-Deny iyafana, kepha isetshenziswa ukwenqabela.
- Yenqaba - Ingeza umthetho wokulahla.
- Umkhawulo - ukufaka imithetho ekhawula.
- Susa - Ususa umthetho obekiwe.
- Faka - Ifaka umthetho.
Njengoba ubona, awekho amaqembu amaningi. Bangaphansi ngokunembile kunamanye ama-firewall atholakalayo, futhi ungakhumbula i-syntax ngemuva kwemizamo eminingana yokusebenzisana ne-UFW. Ihlala kuphela ukubhekana nesibonelo sokucushwa, okuzohlinzekwa izinyathelo ezilandelayo zanamuhla.
Isinyathelo 2: Nika amandla / khubaza / Setha kabusha Izilungiselelo
Sinqume ukugqamisa izikhathi eziningana zokucushwa esigabeni esisodwa, ngoba zixhumeke ngokwengxenye futhi zifana nokuqalisa ukusebenza. Njengoba usuvele uyazi, i-UFW ekuqaleni isesimweni esinqunyiwe, ngakho-ke ake sisebenze ngokusebenzisa umyalo owodwa kuphela.
- Vula iphaneli ngezicelo bese usebenzisa i- "terminal". Ungavula ikhonsoli bese enye indlela elungele wena.
- Ngaphambi kokwenza kusebenze, hlola, mhlawumbe ngaphambi kwesikhathi wena noma isicelo sesivele sisebenze i-firewall. Lokhu kwenziwa ngokungena kwi-Sudo Ufw Status Command.
- Faka iphasiwedi ukuthola amalungelo amakhulu bese ucindezela u-Enter. Qaphela ukuthi ngasikhathi sinye, izinhlamvu zendlela yokufaka azikhonjiswa emugqeni wokuphepha.
- Kumugqa omusha uzothola imininingwane ngesimo samanje se-UFW.
- Ukucupha kwe-firewall kwenziwa ngepharamitha esevele ishiwo ngenhla, futhi wonke umyalo ubukeka kanjena: Sudo Ufw Vumela.
- Uzokwazisa ukuthi i-firewall inikwe amandla futhi izohambisana nohlelo lokusebenza.
- Sebenzisa i-sudo ufw Khubaza ukuvala phansi.
- Ukusebenza kungazisa cishe umyalezo ofanayo.
- Ngokuzayo, uma udinga ukusetha kabusha imithetho noma udinga ukwenza lokhu manje, faka i-Sudo Ufw Reset Command bese ucindezela inkinobho ethi Enter.
- Qinisekisa ukusetha kabusha ngokukhetha impendulo efanele.
- Uzobona imigqa eyisithupha ehlukene ngamakheli wesipele. Ungahambisa nganoma yisiphi isikhathi kule ndawo ukubuyisela amapharamitha.
Manje uyazi ukuthi hlobo luni lwamaqembu abangela ukuphatha ukusebenza okujwayelekile kwesicishamlilo esibhekwayo. Zonke ezinye izinyathelo zizogxila kuphela ekucushweni, futhi amapharamitha ngokwawo anikezwa njengesibonelo, okungukuthi, kufanele uwashintshe, ukuphindisela ezidingweni zakho.
Isinyathelo 3: Ukubeka Imithetho Ezenzakalelayo
Empeleni, faka imithetho ezenzakalelayo ezoxhumana ngayo yonke imibhalo engenayo naphumayo engashiwo ngokwahlukile. Lokhu kusho ukuthi konke ukuxhumana okungenayo okungakhonjiswanga ngesandla kuzovinjwa, futhi okuphumayo kuyaphumelela. Lonke uhlelo lwenziwa ngale ndlela elandelayo:
- Qalisa iseshini entsha ye-console bese ufaka umphumela wokuzenzakalelayo we-sudo ufw uphike umyalo ongenayo. Yenza kusebenze ngokucindezela ukhiye we-ENTER. Uma usuvele wazijwayela ngemithetho ye-syntax echazwe ngenhla, uyazi ukuthi lokhu kusho ukuvimba konke ukuxhumana okungenayo.
- Ngokuphoqelekile, uzodinga ukufaka iphasiwedi ye-superuser. Uzocacisa ngaso sonke isikhathi lapho uqala iseshini entsha yekhonsoli.
- Ngemuva kokusebenzisa umyalo, uzokwaziswa ukuthi umthetho ozenzakalelayo wangena kuwo.
- Ngokuvumelana nalokhu, uzodinga ukusetha umyalo wesibili ozoxazulula izinhlanganisela eziphumayo. Kubukeka ngathi lokhu: I-Sudo UFW Default Vumela okuphumayo.
- Futhi umyalezo uvela ekusetshenzisweni komthetho.
Manje awukwazi ukukhathazeka ngeqiniso lokuthi noma yimiphi imizamo yokuxhuma engenayo engaziwa izophumelela futhi othile uzokwazi ukufinyelela inethiwekhi yakho. Uma ungavimbi ngokuphelele yonke imizamo yokuxhumeka engenayo, yeqa umthetho ongenhla bese udlulela ekwakhiweni kwakho, njengoba ufunde isinyathelo esilandelayo ngokuningiliziwe.
Isinyathelo 4: Ukungeza imithetho yakho ye-firewall
Imithetho ye-Firewall - inketho esemqoka eguqukayo abasebenzisi futhi basebenzise i-UFW. Sizocubungula isibonelo semvume yokufinyelela, futhi ungakhohlwa ngokuvinjwa kwamachweba manje, bheka ithuluzi le-OpenSH. Okokuqala, udinga ukukhumbula imiyalo eyengeziwe ye-syntax ebhekele ukwengeza imithetho:
- UFW Vumela_name_
- UFW uvumele imbobo
- UFW Vumela iPort / Protocol
Ngemuva kwalokho, ungaqala ngokuphepha ukudala imithetho evumayo noma evimbayo. Ake sibhekane nohlobo ngalunye lwezepolitiki ngokulandelana.
- Sebenzisa i-sudo ufw Vumela i-OpenSsh ukuvula ukufinyelela kumachweba wesevisi.
- Uzokwaziswa ukuthi imithetho ibuyekeziwe.
- Ungavula ukufinyelela ngokucacisa itheku, hhayi igama legama lenkonzo, obukeka kanjena: I-Sudo UFW Vumela 22.
- Into efanayo yenzeka ngePort / Protocol - Sudo Ufw Vumela 22 / TCP.
- Ngemuva kokwenza imithetho, hlola uhlu lwezicelo ezitholakalayo ngokufaka uhlu lohlelo lokusebenza lwe-Sudo UFW. Uma konke kusetshenziswe ngempumelelo, insizakalo edingekayo izovela komunye wemigqa elandelayo.
- Ngokuqondene nezimvume futhi kwenqabela ukudluliswa kwethrafikhi ngaphezulu kwamachweba, lokhu kwenziwa ngokufaka i-UFW vumela indlela ye-syntax. Kulesi sikrini, bese ubona isibonelo sokuxazululwa kwethrafikhi ephumayo ePort (Sudo Ufw Vumela ama-80 / TCP), kanye nokuvimbela izinqubomgomo zesiko elifanayo engxenyeni (sudo ufw Deny in 80 / TCP).
- Uma unesibonelo esibonelweni sokungeza inqubomgomo ngokufaka ukuqokwa kwe-synntax ebanzi, sebenzisa i-UFW vumela uhlelo lwe-proto protocol oluvela ku-IP_nage Port_name_.
Isinyathelo 5: Ukufaka Imithetho Emikhawulo
Silethe isihloko sokufakwa kwemithetho emibi esiteji esihlukile, ngoba kuzodingeka ukuthi sikhulume kabanzi ngalokhu. Lo mthetho ukhawulela inani lamakheli e-IP axhunyiwe ethekwini elilodwa. Ukusetshenziswa okusobala kakhulu kwale pharamitha ukuvikela ekuhlaselweni okuhlose amaphasiwedi. Ukufakwa kwezinqubomgomo ezijwayelekile ezinje:
- Ku-Console, Sudo Ufw Limig SSH / TCP bese uqhafaza ku-ENTER.
- Faka iphasiwedi kusuka ku-akhawunti yakho ye-Superuser.
- Uzokwaziswa ukuthi ukuvuselelwa kwemithetho kudlulile ngempumelelo.
Ngendlela efanayo, izinqubomgomo zemikhawulo nezinye izinhlelo zisunguliwe. Sebenzisa leli gama lenkonzo, i-Port noma iPort / Protocolol.
Isinyathelo 6: Buka isimo se-UFW
Kwesinye isikhathi udinga ukubuka isimo samanje se-firewall hhayi kuphela ngokuya ngomsebenzi, kodwa futhi nemithetho esunguliwe. Kulokhu, kuneqembu elihlukile esilishilo phambilini, futhi manje sizoyibheka ngemininingwane eminingi.
- Isimo seSunday Sudo Ufw ukuthola imininingwane ejwayelekile.
- Imigqa emisha izokhombisa zonke izinqubomgomo ezisethiwe kumakheli, ama-protocols kanye namagama wensizakalo. Kwesokudla kukhombisa isenzo nezinkomba.
- Imininingwane ethe xaxa iboniswa lapho usebenzisa impikiswano eyengeziwe, futhi umyalo uthola uhlobo lwe-Sudo Ufw Status Verbose.
- Uhlu lwayo yonke imithetho ngokungaqondakali kwabaqalayo bomsebenzisi kukhonjiswa ngo-Sudo Ufw Show RAW.
Kukhona ezinye izinketho ezibonisa imininingwane ethile mayelana nemithetho ekhona nesimo se-firewall. Masigijime kafushane kubo bonke:
- I-Raw - ikhombisa yonke imithetho esebenzayo esebenzisa ifomethi yokungenisa i-IPT.
- Ukuyakhelwa - kufaka phakathi imithetho eyengeziwe kuphela njengezenzakalelayo.
- Ngaphambi kwemithetho - Imithetho - Ibonisa izinqubomgomo ezenziwa ngaphambi kokwamukela iphakethe emthonjeni wangaphandle.
- Imithetho yomsebenzisi - ngokulandelana, ikhombisa inqubomgomo engezwe ngumsebenzisi.
- Ngemuva kwemithetho kuyafana nemithetho-imithetho, kepha kufaka phakathi leyo mithetho esetshenzisiwe ngemuva nje kokwenza amaphakheji.
- Imithetho yokungena ngemvume - Ibonisa imininingwane mayelana nemicimbi engena ngemvume.
- Ukulalela - Kusetshenziselwa ukubuka amachweba asebenzayo (alalele).
- Ingezwe - abathintekayo lapho ubukwa imithetho engeziwe engeziwe.
Ngesikhathi osidingayo kuwe, ungasebenzisa noma yiziphi zalezi zinketho ukuthola imininingwane oyifunayo bese uyisebenzisela izinhloso zakho.
Isinyathelo 7: Susa Imithetho Ekhona
Abanye abasebenzisi, lapho bethole imininingwane edingekayo mayelana nemithetho ekhona, bafisa ukususa abanye babo ukusungula ukuxhumana noma ukusetha izinqubomgomo ezintsha. I-Firewall ebhekene ivumela ukuthi wenze lokhu nganoma yisiphi isikhathi esitholakalayo, esenziwa kanjena:
- Faka ukususa i-Sudo Ufw Susa Vumela umyalo we-80 / TCP. Izosusa ngokuzenzakalela umthetho ovumela ukuxhumana okuphumayo ngePort / Protocol 80 / TCP.
- Uzokwaziswa ukuthi le nqubomgomo isuswa ngempumelelo kwe-IPv4 ne-IPv6.
- Okufanayo kusebenza ekuxhumaneni okuvinjelwe, ngokwesibonelo, Susa uFW Delete Depete Devy ku-80 / TCP.
Sebenzisa izinketho zokubuka kwesimo ukukopisha imithetho edingekayo bese uzisuse ngendlela efanayo njengoba kuboniswe esibonelweni.
Isinyathelo 8: Ukuvula Ukungena ngemvume
Isigaba sokugcina sesihloko sanamuhla sisho kusebenze inketho yokuthola ngokuzenzakalelayo ezonga imininingwane yokuziphatha ye-UFW kufayela elihlukile. Kuyadingeka hhayi bonke abasebenzisi, kepha kusebenza kanjena:
- Bhala ukungena ngemvume kwe-sudo ufw bese ucindezela u-Enter.
- Lindela isaziso sokuthi ilogi lizosindiswa manje.
- Ungafaka enye inketho, ngokwesibonelo, i-Sudo UFW Logging Medium. Kusekhona ophansi (wonga imininingwane kuphela mayelana namaphakheji avinjelwe) kanye ne-High (kusindisa yonke imininingwane). Inketho ephakathi ebhalela umagazini ekhiyiwe futhi yavumela amaphakethe.
Ngaphezulu ufunde izinyathelo eziyisishiyagalombili, ezisetshenziselwa ukumisa i-Firewall ye-UFW kuhlelo olusebenzayo lwe-Ubuntu. Njengoba ukwazi ukubona, lokhu kuyi-firewall elula kakhulu, elungele nabasebenzisi be-novice ngenxa yokubuya kokuhlola i-synntax. I-UFW isengaba nesibindi sokubiza i-Eptables Evetement ofplate ofplatement IPT uma ingakufaneli.