性能相关
查看磁盘读写流量
2秒钟显示一次
iostat -k -t 2
查看网络流量
2秒钟显示一次
sar -n DEV 2
cpu与内存
top
常用
删除几天前的日志
删除当前目录下一天前的文件
find ./ -type f -mtime +1 -exec rm {} \;
安全相关
防火墙设置
-
查看防火墙设置
iptables -L -n
-
修改防火墙配置
# vim /etc/sysconfig/iptables # Firewall configuration written by system-config-firewall # Manual customization of this file is not recommended. *filter :INPUT ACCEPT [0:0] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] -N whitelist -A whitelist -s 10.37.2.180 -j ACCEPT -A whitelist -s 10.37.2.182 -j ACCEPT -A whitelist -s 10.37.64.53 -j ACCEPT -A whitelist -s 10.37.64.54 -j ACCEPT -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT -A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT -A INPUT -m state --state NEW -m tcp -p tcp --dport 6432 -j whitelist -A INPUT -m state --state NEW -m tcp -p tcp --dport 5432 -j whitelist -A INPUT -m state --state NEW -m tcp -p tcp --dport 10050 -j whitelist -A INPUT -j REJECT --reject-with icmp-host-prohibited -A FORWARD -j REJECT --reject-with icmp-host-prohibited COMMIT
其中,’-A whitelist -s 10.37.2.180 -j ACCEPT’是配置白名单;’-A INPUT -m state --state NEW -m tcp -p tcp --dport 6432 -j whitelist’是配置白名单的端口号。
-
重启防火墙使配置生效
service iptables restart