Ukusetha kwe-UFW ku-Ubuntu

Anonim

Ukusetha kwe-UFW ku-Ubuntu

Cishe wonke umsebenzisi wobuntu obusezingeni eliphezulu unentshisekelo ekuqinisekiseni ukuphepha kwinethiwekhi yawo. Ngaphezu kwalokho, abaningi basebenzisa izinsiza ezithile zenethiwekhi ezizosebenza kahle ngemuva kokwenza imithetho ethile kwi-firewall. Namuhla sifuna ukukhuluma ngokulungiselela i-firewall esibonelweni se-UFW (i-firewall elula). Leli yithuluzi elilula kakhulu lokusebenzisa imithetho ye-firewall, ngakho-ke kunconyelwa abasebenzisi be-novice nalabo abangagculiseki ngokusebenza okuyinkimbinkimbi kakhulu kwe-Ippeble. Asinyathelo ngesinyathelo ngesinyathelo, cabanga ngayo yonke inqubo yokusetha, hlanganisa zonke izinyathelo ngobuningi kakhulu ngangokunokwenzeka.

Lungiselela i-UFW e-Ubuntu

Awudingi ukufaka i-UFW ohlelweni lokusebenza ngoba ikhona lapho ngokuzenzakalelayo. Kodwa-ke, ngefomu elijwayelekile, alisebenzi futhi alinamithetho nakancane. Okokuqala, sizobhekana nokwenza kusebenze, bese sibheka izenzo eziphambili. Kodwa-ke, okubaluleke kakhulu kufanele kuhlolwe nge-syntax, futhi kuvame ukukhathazeka labo basebenzisi abahlela ukusebenzisa lesi sicishamlilo ngokuqhubekayo.

Isinyathelo 1: Ukutadisha i-Syntax

Njengoba wazi, i-UFW iyisisetshenziswa se-console, okusho ukuthi kwenziwa nge- "terminal" ejwayelekile noma omunye umsebenzisi. Ukuxhumana kwalolu hlobo kwenziwa ngosizo lwemiyalo efakwe ngokukhethekile. Zonke zihlala zisezincwadini, kepha akunangqondo ukufunda inqwaba yezinto zokwakha, ikakhulukazi esimweni sensimbi yanamuhla. Umgomo wokufaka ubukeka kanjena: Amapharamitha wesenzo se-Sudo UFW. I-Sudo ibhekele ukugijima egameni leSuperuser, i-UFW yingxabano ejwayelekile ekhombisa uhlelo olubizwa ngokuthi yi-imeyili, nemishwana esele futhi ichaze imithetho efakiwe. Kungenxa yabo ukuthi sifuna ukuma ngemininingwane eminingi.

  • Nika amandla i-parameter ejwayelekile ebhekele ukuvula i-firewall. Kulokhu, kuzongezwa ngokuzenzakalela ku-autoad.
  • Khubaza - ukhubaza i-UFW futhi uwususe kusuka ku-autoload.
  • Layisha kabusha - Kusetshenziselwa ukuqala kabusha i-firewall. Ikakhulu esebenza ngemuva kokufaka imithetho emisha.
  • Okuzenzakalelayo - Kusho ukuthi inketho elandelayo izofakwa ngokuzenzakalelayo.
  • Ukungena ngemvume - kusebenze ukudalwa kwamafayela we-log lapho yonke imininingwane eyisisekelo esenzweni yesicishamlilo izogcinwa.
  • Setha kabusha - Setha kabusha wonke izilungiselelo kuze kufinyelele ezijwayelekile.
  • Isimo - Sisetshenziselwa ukubuka isimo samanje.
  • Khombisa - ukubukwa okusheshayo kwemibiko ye-firewall. Izinketho ezengeziwe zisebenza kule pharamitha, kepha sizokhuluma ngabo esinyathelweni esihlukile.
  • Vumela ukuhileleka lapho wengeza imithetho evumayo.
  • I-Deny iyafana, kepha isetshenziswa ukwenqabela.
  • Yenqaba - Ingeza umthetho wokulahla.
  • Umkhawulo - ukufaka imithetho ekhawula.
  • Susa - Ususa umthetho obekiwe.
  • Faka - Ifaka umthetho.

Njengoba ubona, awekho amaqembu amaningi. Bangaphansi ngokunembile kunamanye ama-firewall atholakalayo, futhi ungakhumbula i-syntax ngemuva kwemizamo eminingana yokusebenzisana ne-UFW. Ihlala kuphela ukubhekana nesibonelo sokucushwa, okuzohlinzekwa izinyathelo ezilandelayo zanamuhla.

Isinyathelo 2: Nika amandla / khubaza / Setha kabusha Izilungiselelo

Sinqume ukugqamisa izikhathi eziningana zokucushwa esigabeni esisodwa, ngoba zixhumeke ngokwengxenye futhi zifana nokuqalisa ukusebenza. Njengoba usuvele uyazi, i-UFW ekuqaleni isesimweni esinqunyiwe, ngakho-ke ake sisebenze ngokusebenzisa umyalo owodwa kuphela.

  1. Vula iphaneli ngezicelo bese usebenzisa i- "terminal". Ungavula ikhonsoli bese enye indlela elungele wena.
  2. Iya ku-terminal ukuze uculiswe eminye imililo ye-UFW Firewall e-Ubuntu

  3. Ngaphambi kokwenza kusebenze, hlola, mhlawumbe ngaphambi kwesikhathi wena noma isicelo sesivele sisebenze i-firewall. Lokhu kwenziwa ngokungena kwi-Sudo Ufw Status Command.
  4. Umyalo wokuhlola isimo samanje se-Firewall ye-UFW ku-Ubuntu

  5. Faka iphasiwedi ukuthola amalungelo amakhulu bese ucindezela u-Enter. Qaphela ukuthi ngasikhathi sinye, izinhlamvu zendlela yokufaka azikhonjiswa emugqeni wokuphepha.
  6. Faka iphasiwedi ye-superuser lapho uxhumana ne-UFW e-Ubuntu

  7. Kumugqa omusha uzothola imininingwane ngesimo samanje se-UFW.
  8. Buka imininingwane ngesimo samanje se-UFW Firewall e-Ubuntu

  9. Ukucupha kwe-firewall kwenziwa ngepharamitha esevele ishiwo ngenhla, futhi wonke umyalo ubukeka kanjena: Sudo Ufw Vumela.
  10. Faka umyalo ukuze uvule i-Firewall ye-UFW e-Ubuntu

  11. Uzokwazisa ukuthi i-firewall inikwe amandla futhi izohambisana nohlelo lokusebenza.
  12. Imininingwane mayelana nokwenza okuphumelelayo kwe-Firewall ye-UFW ku-Ubuntu

  13. Sebenzisa i-sudo ufw Khubaza ukuvala phansi.
  14. Iqembu ukukhubaza ukusebenza kwe-Firewall ye-UFW ku-Ubuntu

  15. Ukusebenza kungazisa cishe umyalezo ofanayo.
  16. Isaziso se-UFW Firewall ephumelele e-Ubuntu

  17. Ngokuzayo, uma udinga ukusetha kabusha imithetho noma udinga ukwenza lokhu manje, faka i-Sudo Ufw Reset Command bese ucindezela inkinobho ethi Enter.
  18. Umyalo wokusetha kabusha izilungiselelo zamanje ze-UFW Firewall e-Ubuntu

  19. Qinisekisa ukusetha kabusha ngokukhetha impendulo efanele.
  20. Ukuqinisekiswa kwemithetho ukusetha kabusha lapho ubuyisela amapharamitha ajwayelekile we-UFW ku-Ubuntu

  21. Uzobona imigqa eyisithupha ehlukene ngamakheli wesipele. Ungahambisa nganoma yisiphi isikhathi kule ndawo ukubuyisela amapharamitha.
  22. Imininingwane mayelana nokwakha isipele ufw e-Ubuntu

Manje uyazi ukuthi hlobo luni lwamaqembu abangela ukuphatha ukusebenza okujwayelekile kwesicishamlilo esibhekwayo. Zonke ezinye izinyathelo zizogxila kuphela ekucushweni, futhi amapharamitha ngokwawo anikezwa njengesibonelo, okungukuthi, kufanele uwashintshe, ukuphindisela ezidingweni zakho.

Isinyathelo 3: Ukubeka Imithetho Ezenzakalelayo

Empeleni, faka imithetho ezenzakalelayo ezoxhumana ngayo yonke imibhalo engenayo naphumayo engashiwo ngokwahlukile. Lokhu kusho ukuthi konke ukuxhumana okungenayo okungakhonjiswanga ngesandla kuzovinjwa, futhi okuphumayo kuyaphumelela. Lonke uhlelo lwenziwa ngale ndlela elandelayo:

  1. Qalisa iseshini entsha ye-console bese ufaka umphumela wokuzenzakalelayo we-sudo ufw uphike umyalo ongenayo. Yenza kusebenze ngokucindezela ukhiye we-ENTER. Uma usuvele wazijwayela ngemithetho ye-syntax echazwe ngenhla, uyazi ukuthi lokhu kusho ukuvimba konke ukuxhumana okungenayo.
  2. Faka umyalo wokufaka imithetho ejwayelekile yokuzenzakalelayo yokuxhumeka kwe-UFW okungenayo ku-Ubuntu

  3. Ngokuphoqelekile, uzodinga ukufaka iphasiwedi ye-superuser. Uzocacisa ngaso sonke isikhathi lapho uqala iseshini entsha yekhonsoli.
  4. Ukufaka iphasiwedi ye-superuser lapho wenza izinguquko ze-UFW ziye ku-ubuntu

  5. Ngemuva kokusebenzisa umyalo, uzokwaziswa ukuthi umthetho ozenzakalelayo wangena kuwo.
  6. Isaziso sokwenza ngcono ushintsho kumapharamitha ajwayelekile wokuxhumeka kwe-UFW okuzayo ku-Ubuntu

  7. Ngokuvumelana nalokhu, uzodinga ukusetha umyalo wesibili ozoxazulula izinhlanganisela eziphumayo. Kubukeka ngathi lokhu: I-Sudo UFW Default Vumela okuphumayo.
  8. Faka umyalo wokufaka imithetho ezenzakalelayo yokuxhumeka okuphumayo e-UFW in Ubuntu

  9. Futhi umyalezo uvela ekusetshenzisweni komthetho.
  10. Imininingwane ngokusetshenziswa kwemithetho ezenzakalelayo yokuxhumana okuphumayo ku-UFW in Ubuntu

Manje awukwazi ukukhathazeka ngeqiniso lokuthi noma yimiphi imizamo yokuxhuma engenayo engaziwa izophumelela futhi othile uzokwazi ukufinyelela inethiwekhi yakho. Uma ungavimbi ngokuphelele yonke imizamo yokuxhumeka engenayo, yeqa umthetho ongenhla bese udlulela ekwakhiweni kwakho, njengoba ufunde isinyathelo esilandelayo ngokuningiliziwe.

Isinyathelo 4: Ukungeza imithetho yakho ye-firewall

Imithetho ye-Firewall - inketho esemqoka eguqukayo abasebenzisi futhi basebenzise i-UFW. Sizocubungula isibonelo semvume yokufinyelela, futhi ungakhohlwa ngokuvinjwa kwamachweba manje, bheka ithuluzi le-OpenSH. Okokuqala, udinga ukukhumbula imiyalo eyengeziwe ye-syntax ebhekele ukwengeza imithetho:

  • UFW Vumela_name_
  • UFW uvumele imbobo
  • UFW Vumela iPort / Protocol

Ngemuva kwalokho, ungaqala ngokuphepha ukudala imithetho evumayo noma evimbayo. Ake sibhekane nohlobo ngalunye lwezepolitiki ngokulandelana.

  1. Sebenzisa i-sudo ufw Vumela i-OpenSsh ukuvula ukufinyelela kumachweba wesevisi.
  2. Ukusetha imithetho yokuxhuma kwesevisi ngegama layo e-UFW in Ubuntu

  3. Uzokwaziswa ukuthi imithetho ibuyekeziwe.
  4. Imininingwane ekusetshenzisweni kwezinguquko ezethuliwe ku-UFW in Ubuntu

  5. Ungavula ukufinyelela ngokucacisa itheku, hhayi igama legama lenkonzo, obukeka kanjena: I-Sudo UFW Vumela 22.
  6. Faka umyalo ukwenza imithetho ngenombolo yetheku ku-UFW in Ubuntu

  7. Into efanayo yenzeka ngePort / Protocol - Sudo Ufw Vumela 22 / TCP.
  8. Ukufaka umyalo wokwenza imithetho ngenombolo yePort ne-Protocol ku-UFW in Ubuntu

  9. Ngemuva kokwenza imithetho, hlola uhlu lwezicelo ezitholakalayo ngokufaka uhlu lohlelo lokusebenza lwe-Sudo UFW. Uma konke kusetshenziswe ngempumelelo, insizakalo edingekayo izovela komunye wemigqa elandelayo.
  10. Bheka uhlu lwezinsizakalo ezingeziwe e-UFW Firewall e-Ubuntu

  11. Ngokuqondene nezimvume futhi kwenqabela ukudluliswa kwethrafikhi ngaphezulu kwamachweba, lokhu kwenziwa ngokufaka i-UFW vumela indlela ye-syntax. Kulesi sikrini, bese ubona isibonelo sokuxazululwa kwethrafikhi ephumayo ePort (Sudo Ufw Vumela ama-80 / TCP), kanye nokuvimbela izinqubomgomo zesiko elifanayo engxenyeni (sudo ufw Deny in 80 / TCP).
  12. Ukufaka imithetho yokuqondisa kwethrafikhi e-UFW in Ubuntu

  13. Uma unesibonelo esibonelweni sokungeza inqubomgomo ngokufaka ukuqokwa kwe-synntax ebanzi, sebenzisa i-UFW vumela uhlelo lwe-proto protocol oluvela ku-IP_nage Port_name_.
  14. Ukufaka imithetho nge-synntax ethuthukile ku-UFW in Ubuntu

Isinyathelo 5: Ukufaka Imithetho Emikhawulo

Silethe isihloko sokufakwa kwemithetho emibi esiteji esihlukile, ngoba kuzodingeka ukuthi sikhulume kabanzi ngalokhu. Lo mthetho ukhawulela inani lamakheli e-IP axhunyiwe ethekwini elilodwa. Ukusetshenziswa okusobala kakhulu kwale pharamitha ukuvikela ekuhlaselweni okuhlose amaphasiwedi. Ukufakwa kwezinqubomgomo ezijwayelekile ezinje:

  1. Ku-Console, Sudo Ufw Limig SSH / TCP bese uqhafaza ku-ENTER.
  2. Ukufaka imikhawulo ethekwini lapho kulungiselela i-UFW Firewall e-Ubuntu

  3. Faka iphasiwedi kusuka ku-akhawunti yakho ye-Superuser.
  4. Faka iphasiwedi ukufaka umkhawulo ukuxhuma e-UFW Port e Ubuntu

  5. Uzokwaziswa ukuthi ukuvuselelwa kwemithetho kudlulile ngempumelelo.
  6. Imininingwane mayelana nokuvuselela imithetho yemikhawulo e-UFW in Ubuntu

Ngendlela efanayo, izinqubomgomo zemikhawulo nezinye izinhlelo zisunguliwe. Sebenzisa leli gama lenkonzo, i-Port noma iPort / Protocolol.

Isinyathelo 6: Buka isimo se-UFW

Kwesinye isikhathi udinga ukubuka isimo samanje se-firewall hhayi kuphela ngokuya ngomsebenzi, kodwa futhi nemithetho esunguliwe. Kulokhu, kuneqembu elihlukile esilishilo phambilini, futhi manje sizoyibheka ngemininingwane eminingi.

  1. Isimo seSunday Sudo Ufw ukuthola imininingwane ejwayelekile.
  2. Umyalo wokuhlola isimo somsebenzi samanje sesikrini se-UFW ku-Ubuntu

  3. Imigqa emisha izokhombisa zonke izinqubomgomo ezisethiwe kumakheli, ama-protocols kanye namagama wensizakalo. Kwesokudla kukhombisa isenzo nezinkomba.
  4. Ibonisa imithetho eyisisekelo lapho ubuka isimo sesikrini se-UFW ku-Ubuntu

  5. Imininingwane ethe xaxa iboniswa lapho usebenzisa impikiswano eyengeziwe, futhi umyalo uthola uhlobo lwe-Sudo Ufw Status Verbose.
  6. Buka imininingwane emithethweni ekhona e-UFW in Ubuntu

  7. Uhlu lwayo yonke imithetho ngokungaqondakali kwabaqalayo bomsebenzisi kukhonjiswa ngo-Sudo Ufw Show RAW.
  8. Buka yonke imithetho endaweni esetshenzisiwe e-UFW in Ubuntu

Kukhona ezinye izinketho ezibonisa imininingwane ethile mayelana nemithetho ekhona nesimo se-firewall. Masigijime kafushane kubo bonke:

  • I-Raw - ikhombisa yonke imithetho esebenzayo esebenzisa ifomethi yokungenisa i-IPT.
  • Ukuyakhelwa - kufaka phakathi imithetho eyengeziwe kuphela njengezenzakalelayo.
  • Ngaphambi kwemithetho - Imithetho - Ibonisa izinqubomgomo ezenziwa ngaphambi kokwamukela iphakethe emthonjeni wangaphandle.
  • Imithetho yomsebenzisi - ngokulandelana, ikhombisa inqubomgomo engezwe ngumsebenzisi.
  • Ngemuva kwemithetho kuyafana nemithetho-imithetho, kepha kufaka phakathi leyo mithetho esetshenzisiwe ngemuva nje kokwenza amaphakheji.
  • Imithetho yokungena ngemvume - Ibonisa imininingwane mayelana nemicimbi engena ngemvume.
  • Ukulalela - Kusetshenziselwa ukubuka amachweba asebenzayo (alalele).
  • Ingezwe - abathintekayo lapho ubukwa imithetho engeziwe engeziwe.

Ngesikhathi osidingayo kuwe, ungasebenzisa noma yiziphi zalezi zinketho ukuthola imininingwane oyifunayo bese uyisebenzisela izinhloso zakho.

Isinyathelo 7: Susa Imithetho Ekhona

Abanye abasebenzisi, lapho bethole imininingwane edingekayo mayelana nemithetho ekhona, bafisa ukususa abanye babo ukusungula ukuxhumana noma ukusetha izinqubomgomo ezintsha. I-Firewall ebhekene ivumela ukuthi wenze lokhu nganoma yisiphi isikhathi esitholakalayo, esenziwa kanjena:

  1. Faka ukususa i-Sudo Ufw Susa Vumela umyalo we-80 / TCP. Izosusa ngokuzenzakalela umthetho ovumela ukuxhumana okuphumayo ngePort / Protocol 80 / TCP.
  2. Susa Imithetho Yokuxhumana Ephumayo e-UFW in Ubuntu

  3. Uzokwaziswa ukuthi le nqubomgomo isuswa ngempumelelo kwe-IPv4 ne-IPv6.
  4. Imininingwane mayelana nokususwa okuphumelelayo komthetho ophumayo we-UFW ophumayo ku-Ubuntu

  5. Okufanayo kusebenza ekuxhumaneni okuvinjelwe, ngokwesibonelo, Susa uFW Delete Depete Devy ku-80 / TCP.
  6. Susa Imithetho yokuvimba amachweba angenayo ngechweba e-UFW in Ubuntu

Sebenzisa izinketho zokubuka kwesimo ukukopisha imithetho edingekayo bese uzisuse ngendlela efanayo njengoba kuboniswe esibonelweni.

Isinyathelo 8: Ukuvula Ukungena ngemvume

Isigaba sokugcina sesihloko sanamuhla sisho kusebenze inketho yokuthola ngokuzenzakalelayo ezonga imininingwane yokuziphatha ye-UFW kufayela elihlukile. Kuyadingeka hhayi bonke abasebenzisi, kepha kusebenza kanjena:

  1. Bhala ukungena ngemvume kwe-sudo ufw bese ucindezela u-Enter.
  2. Umyalo wokusebenzisa i-UFW ONVEL LOG e-Ubuntu

  3. Lindela isaziso sokuthi ilogi lizosindiswa manje.
  4. Isaziso se-Log Log Log ephumelelayo yokusebenzisa i-UFW Log Log Gcina ku-Ubuntu

  5. Ungafaka enye inketho, ngokwesibonelo, i-Sudo UFW Logging Medium. Kusekhona ophansi (wonga imininingwane kuphela mayelana namaphakheji avinjelwe) kanye ne-High (kusindisa yonke imininingwane). Inketho ephakathi ebhalela umagazini ekhiyiwe futhi yavumela amaphakethe.
  6. Khetha inketho ukuze unike amandla ukungena ngemvume kwi-UFW Firewall e-Ubuntu

Ngaphezulu ufunde izinyathelo eziyisishiyagalombili, ezisetshenziselwa ukumisa i-Firewall ye-UFW kuhlelo olusebenzayo lwe-Ubuntu. Njengoba ukwazi ukubona, lokhu kuyi-firewall elula kakhulu, elungele nabasebenzisi be-novice ngenxa yokubuya kokuhlola i-synntax. I-UFW isengaba nesibindi sokubiza i-Eptables Evetement ofplate ofplatement IPT uma ingakufaneli.

Funda kabanzi