Nhasi, neichi chikamu chekupedzisira uye chechinomwe cheiyi nhevedzano yezvinyorwa pakushandiswa kwepamberi kweiyo terminal, kwatakafukidza mimwe mirairo yakakosha inoshandiswa neServer uye System Administrators pasi peGNU/Linux, isu tichavhara iyi nhevedzano nekuongorora iyo yekupedzisira 2 "Linux Commands" zvinotevera: iptables uye firewalld.
nekudaro, kupedzisa dzidziso yedu-inoshanda kune avo avhareji GNU/Linux vashandisi vanogara vachitsvaga kudzidza zvishoma yakawedzera komputa komputa, kuti vakwanise kuzvibata ivo vakanyanya kukosha ivo pachavo. kutonga uye kugadzirisa matambudzikokumba uye muhofisi.
Asi, usati watanga iyi positi nezve mashandisiro anoshanda evamwe "Linux Commands", tinokurudzira kuti iwe wobva waongorora yapfuura inoenderana posvo yenyaya dzino dzakatevedzana:
Linux Mirairo - Chikamu Chinomwe: iptables uye firewalld
Kushandisa kushandiswa kwemirairo yeLinux
iptables
Kuraira "iptables" uye ip6tables murairo weLinux inopa manejimendi chishandiso cheIPv4/IPv6 uye NAT packet kusefa. Kureva, ivo vanoshandiswa kugadzirisa, kuchengetedza uye kuongorora iyo yekusefa mutemo matafura eIPv4 uye IPv6 mapaketi muLinux kernel. Uye kuita izvi, zvinokutendera kuti utsanangure akati wandei matafura. Ipo tafura yega yega ine nhevedzano yetambo dzakavakirwa-mukati uye inogona zvakare kuve-yakatsanangurwa nemushandisi tambo. Nenzira iyi, cheni imwe neimwe rondedzero yemitemo inogona kuenderana neseti yemapakiti. Uye mutemo wega wega unotsanangura zvinogona kuitwa nepaketi inofanana nayo. Iyo inonzi "nzvimbo", ndiko kuti, kusvetukira kune-inotsanangurwa cheni mutafura imwechete. manpages
Mirairo Yekushandisa Mienzaniso iptables
- Wona tambo, mitemo, uye packet/byte counters yetafura yekusefa: $ sudo iptables -vnL
- Isa mutemo wemitemo weketani: $ sudo iptables -P [tambo] [mutemo]
- Wedzera mutemo kune chain policy ye IP: $ sudo iptables -A [tambo] -s [ip] -j [rule]
- Delete chain rule: $ sudo iptables -D [tambo] [rule_line_nhamba]
- Sevha zvigadziriso kufaira: $ sudo iptables-save -t [TafuraName] > [nzira /ku/faira]
- Dzosera gadziriso kubva mufaira: $ sudo iptables-kudzorera <[nzira /ku/faira]
Kuti uone mimwe mienzaniso yekushandisa uye tsananguro yezvainobatanidzwa sarudzo kana ma paramita, tinya pano.
firewall
Kuraira "firewall" inopa ine simba Firewall maneja, ndiko kuti, inopa yakapusa, iri nyore kushandisa firewall inovhara yakajairika makesi ekushandisa kune akawanda mamiriro. Naizvozvo, zvinobatsira kwazvo kuchengetedza michina kubva kune chero isingadikanwi traffic inouya kubva kunze kwetiweki. manpages
Mirairo Yekushandisa Mienzaniso iptables
- Tanga Firewalld: $systemctl unmask firewalld
- Tanga Firewall: $ systemctl kutanga firewalld
- Seta kuti utange otomatiki kana OS bhutsu: $systemctl inogonesa firewalld
- Misa Firewalld: $ systemctl stop firewalld
- Gadzirisa kuitira kuti irege kutanga otomatiki paunotanga OS: $ systemctl kudzima firewalld
Kuti uone mimwe mienzaniso yekushandisa uye tsananguro yezvainobatanidzwa sarudzo kana ma paramita, tinya pano.
chitsamba: Kana iwe uchida kudzidza zvishoma nezve musoro wanhasi, isu tinokurudzirawo kuongorora iwo murairo nft (nfttables), iyo inoshandiswa kune izvo zviitiko apo zvinodikanwa kugadzirisa yakaoma uye inoshanda-yakakosha firewalls.
Resumen
Muchidimbu, tinovimba kuti nhevedzano iyi yese yakatopera akawanda anonyanya kukosha "Linux command» izvo zvinowanzo tarisirwa pamwero weServer uye System Administrators kugadzirisa matambudziko etiweki (SysAdmins), batsira vamwe vashandisi vekombuta kuti vagone zvakanyanya sezvinobvira, iyo ine simba Linux Terminal. Uye kana wakamboshandisa chero ipi zvayo yemirairo iyi nhasi, uye iwe uchida kupa chimwe chinhu pamusoro payo, tinokukoka iwe kuti uite saizvozvo. kuburikidza nemashoko.
Pakupedzisira, yeuka kugovera aya mashoko anobatsira navamwe, mukuwedzera kukushanyira musha wedu «website» kuti udzidze zvimwe zvirimo zvazvino, uye ubatane nechiteshi chedu chepamutemo che teregiramu kuti uongorore dzimwe nhau, zvidzidzo uye Linux updates. West boka, kuti uwane rumwe ruzivo nezve musoro wanhasi.