ubuntu 防火墙_运维大神:ubuntu防火墙配置大全

4849918d32e15553908d5c564246d517.png

安装防火墙组件:

sudo apt-get install ufw -y;

开启防火墙:

sudo ufw enable;

开启拒绝访问:

sudo ufw default deny;

查看状态:

ufw status;

常用端口配置案例如下:

sudo ufw allow 80/tcp;

sudo ufw allow 25/tcp;

sudo ufw allow 8080/tcp;

sudo ufw allow 81/tcp;

sudo ufw allow 83/tcp;

sudo ufw allow 8019/tcp;

sudo ufw allow 8005/tcp;

sudo ufw allow 8009/tcp;

sudo ufw allow 8105/tcp;

sudo ufw allow 8109/tcp;

sudo ufw allow 21/tcp;

ufw allow proto tcp from 172.18.111.84 to 172.18.111.105 port 22

ufw allow proto tcp from 172.18.111.153 to 172.18.111.105 port 22

ufw allow proto tcp from 172.18.253.16 to 172.18.111.105 port 22

ufw allow proto tcp from 172.18.253.12 to 172.18.111.105 port 22

ufw allow proto tcp from 172.18.253.18 to 172.18.111.105 port 22

ufw allow proto tcp from 192.168.5.84 to 172.18.111.105 port 10050

ufw allow proto tcp from 172.18.253.0/24 to 172.18.111.105 port 22

ufw status

f1965eeb1617053fee26f67ee73b6a43.png

写成shell脚本如下:


function firewall{sudo apt-get install ufw -y;echo "please input y"sudo ufw enable;sudo ufw default deny;ufw status;#ufw version;#cat /etc/ufw/user.rules > /etc/ufw/user.rules_bak2;myip=127.0.0.1;read -p "Please input system ip :" myipsudo ufw allow 80/tcp;#sudo ufw allow 80;#sudo ufw delete allow 80/tcp#ufw allow proto tcp from 172.18.253.16 to 172.18.111.85 port 2202#ufw delete allow proto tcp from 172.18.253.16 to 172.18.111.85 port 2202#ufw allow proto tcp from 172.18.253.0/24 to 172.18.34.36 port 2202#sudo ufw allow from 192.168.254.254#sudo ufw delete allow from 192.168.254.254ufw allow proto tcp from 172.18.111.84 to $myip port 2202ufw allow proto tcp from 172.18.111.153 to $myip port 2202ufw allow proto tcp from 172.18.253.16 to $myip port 2202ufw allow proto tcp from 172.18.253.12 to $myip port 2202ufw allow proto tcp from 172.18.253.18 to $myip port 2202ufw allow proto tcp from 192.168.5.84 to $myip port 10050ufw allow proto tcp from 172.18.253.0/24 to $myip port 2202ufw status}function main{ssh;firewall;}main;
80ad5e8291c72eeb5d5dd0257b2eae3a.png

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值