网上学习资料一大堆,但如果学到的知识不成体系,遇到问题时只是浅尝辄止,不再深入研究,那么很难做到真正的技术提升。
一个人可以走的很快,但一群人才能走的更远!不论你是正从事IT行业的老鸟或是对IT行业感兴趣的新人,都欢迎加入我们的的圈子(技术交流、学习资源、职场吐槽、大厂内推、面试辅导),让我们一起学习成长!
开放TCP协议22端口,以便能ssh,如果你是在有固定ip的场所,可以使用 -s 来限定客户端的ip
/sbin/iptables -A INPUT -p tcp --dport 22 -j ACCEPT
开放TCP协议80端口供web服务
/sbin/iptables -A INPUT -p tcp --dport 80 -j ACCEPT
10.241.121.15是另外一台服务器的内网ip,由于之间有通信,接受所有来自10.241.121.15的TCP请求
/sbin/iptables -A INPUT -p tcp -s 10.241.121.15 -j ACCEPT
接受ping
/sbin/iptables -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
这条规则参看:http://www.netingcn.com/iptables-localhost-not-access-internet.html
/sbin/iptables -A INPUT -m state --state ESTABLISHED -j ACCEPT
屏蔽上述规则以为的所有请求,不可缺少,否则防火墙没有任何过滤的功能
/sbin/iptables -P INPUT DROP
可以使用 iptables -L -n 查看规则是否生效
至此防火墙就算配置好,但是这是临时的,当重启iptables或重启机器,上述配置就会被清空,要想永久生效,还需要如下操作:
/etc/init.d/iptables save
或
service iptables save
执行上述命令可以在文件 /etc/sysconfig/iptables 中看到配置
以下提供一个干净的配置脚本:
/sbin/iptables -P INPUT ACCEPT
/sbin/iptables -F
/sbin/iptables -X
/sbin/iptables -Z
/sbin/iptables -A INPUT -i lo -j ACCEPT
/sbin/iptables -A INPUT -p tcp --dport 22 -j ACCEPT
/sbin/iptables -A INPUT -p tcp --dport 80 -j ACCEPT
/sbin/iptables -A INPUT -p tcp -s 10.241.121.15 -j ACCEPT
/sbin/iptables -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
/sbin/iptables -A INPUT -m state --state ESTABLISHED -j ACCEPT
/sbin/iptables -P INPUT DROP
最后执行 service iptables save ,先确保ssh连接没有问题,防止规则错误,导致无法连上服务器,因为没有save,重启服务器规则都失效,否则就只有去机房才能修改规则了。也可以参考:ubuntu iptables 配置脚本来写一个脚本。
最后再次提醒,在清空规则之前一定要小心,确保Chain INPUT (policy ACCEPT)。
**补充阿里云的linux\_drop\_port.sh**
#!/bin/bash
#########################################
#Function: linux drop port
#Usage: bash linux_drop_port.sh
#Author: Customer Service Department
#Company: Alibaba Cloud Computing
#Version: 2.0
#########################################
check_os_release()
{
while true
do
os_release=
(
g
r
e
p
"
R
e
d
H
a
t
E
n
t
e
r
p
r
i
s
e
L
i
n
u
x
S
e
r
v
e
r
r
e
l
e
a
s
e
"
/
e
t
c
/
i
s
s
u
e
2
>
/
d
e
v
/
n
u
l
l
)
o
s
r
e
l
e
a
s
e
2
=
(grep "Red Hat Enterprise Linux Server release"/etc/issue 2>/dev/null) os_release_2=
(grep"RedHatEnterpriseLinuxServerrelease"/etc/issue2>/dev/null)osrelease2=(grep “Red Hat Enterprise Linux Server release”/etc/redhat-release 2>/dev/null)
if [ “KaTeX parse error: Expected 'EOF', got '&' at position 15: os_release" ] &̲& [ "os_release_2” ]
then
if echo “KaTeX parse error: Expected 'EOF', got '&' at position 42: …5" >/dev/null2>&̲1 then os_r…os_release”
elif echo “KaTeX parse error: Expected 'EOF', got '&' at position 42: …6">/dev/null 2>&̲1 then os_r…os_release”
else
os_release=“”
echo “
o
s
r
e
l
e
a
s
e
"
f
i
b
r
e
a
k
f
i
o
s
r
e
l
e
a
s
e
=
os_release" fi break fi os_release=
osrelease"fibreakfiosrelease=(grep “Aliyun Linux release” /etc/issue2>/dev/null)
os_release_2=
(
g
r
e
p
"
A
l
i
y
u
n
L
i
n
u
x
r
e
l
e
a
s
e
"
/
e
t
c
/
a
l
i
y
u
n
−
r
e
l
e
a
s
e
2
>
/
d
e
v
/
n
u
l
l
)
i
f
[
"
(grep "Aliyun Linux release" /etc/aliyun-release2>/dev/null) if [ "
(grep"AliyunLinuxrelease"/etc/aliyun−release2>/dev/null)if["os_release” ] && [ “
o
s
r
e
l
e
a
s
e
2
"
]
t
h
e
n
i
f
e
c
h
o
"
os_release_2" ] then if echo "
osrelease2"]thenifecho"os_release”|grep “release 5” >/dev/null2>&1
then
os_release=aliyun5
echo “
o
s
r
e
l
e
a
s
e
"
e
l
i
f
e
c
h
o
"
os_release" elif echo "
osrelease"elifecho"os_release”|grep “release 6”>/dev/null 2>&1
then
os_release=aliyun6
echo “
o
s
r
e
l
e
a
s
e
"
e
l
s
e
o
s
r
e
l
e
a
s
e
=
"
"
e
c
h
o
"
os_release" else os_release="" echo "
osrelease"elseosrelease=""echo"os_release”
fi
break
fi
os_release=
(
g
r
e
p
"
C
e
n
t
O
S
r
e
l
e
a
s
e
"
/
e
t
c
/
i
s
s
u
e
2
>
/
d
e
v
/
n
u
l
l
)
o
s
r
e
l
e
a
s
e
2
=
(grep "CentOS release" /etc/issue 2>/dev/null) os_release_2=
(grep"CentOSrelease"/etc/issue2>/dev/null)osrelease2=(grep “CentOS release” /etc/*release2>/dev/null)
if [ “KaTeX parse error: Expected 'EOF', got '&' at position 15: os_release" ] &̲& [ "os_release_2” ]
then
if echo “KaTeX parse error: Expected 'EOF', got '&' at position 42: …5" >/dev/null2>&̲1 then os_r…os_release”
elif echo “KaTeX parse error: Expected 'EOF', got '&' at position 42: …6">/dev/null 2>&̲1 then os_r…os_release”
else
os_release=“”
echo “
o
s
r
e
l
e
a
s
e
"
f
i
b
r
e
a
k
f
i
o
s
r
e
l
e
a
s
e
=
os_release" fi break fi os_release=
osrelease"fibreakfiosrelease=(grep -i “ubuntu” /etc/issue 2>/dev/null)
os_release_2=
(
g
r
e
p
−
i
"
u
b
u
n
t
u
"
/
e
t
c
/
l
s
b
−
r
e
l
e
a
s
e
2
>
/
d
e
v
/
n
u
l
l
)
i
f
[
"
(grep -i "ubuntu" /etc/lsb-release2>/dev/null) if [ "
(grep−i"ubuntu"/etc/lsb−release2>/dev/null)if["os_release” ] && [ “
o
s
r
e
l
e
a
s
e
2
"
]
t
h
e
n
i
f
e
c
h
o
"
os_release_2" ] then if echo "
osrelease2"]thenifecho"os_release”|grep “Ubuntu 10” >/dev/null2>&1
then
os_release=ubuntu10
echo “
o
s
r
e
l
e
a
s
e
"
e
l
i
f
e
c
h
o
"
os_release" elif echo "
osrelease"elifecho"os_release”|grep “Ubuntu 12.04”>/dev/null 2>&1
then
os_release=ubuntu1204
echo “
o
s
r
e
l
e
a
s
e
"
e
l
i
f
e
c
h
o
"
os_release" elif echo "
osrelease"elifecho"os_release”|grep “Ubuntu 12.10”>/dev/null 2>&1
then
os_release=ubuntu1210
echo “
o
s
r
e
l
e
a
s
e
"
e
l
s
e
o
s
r
e
l
e
a
s
e
=
"
"
e
c
h
o
"
os_release" else os_release="" echo "
osrelease"elseosrelease=""echo"os_release”
fi
break
fi
os_release=
(
g
r
e
p
−
i
"
d
e
b
i
a
n
"
/
e
t
c
/
i
s
s
u
e
2
>
/
d
e
v
/
n
u
l
l
)
o
s
r
e
l
e
a
s
e
2
=
(grep -i "debian" /etc/issue 2>/dev/null) os_release_2=
(grep−i"debian"/etc/issue2>/dev/null)osrelease2=(grep -i “debian” /proc/version 2>/dev/null)
if [ “KaTeX parse error: Expected 'EOF', got '&' at position 15: os_release" ] &̲& [ "os_release_2” ]
then
if echo “KaTeX parse error: Expected 'EOF', got '&' at position 40: …6" >/dev/null2>&̲1 then os_r…os_release”
else
os_release=“”
echo “
o
s
r
e
l
e
a
s
e
"
f
i
b
r
e
a
k
f
i
o
s
r
e
l
e
a
s
e
=
os_release" fi break fi os_release=
osrelease"fibreakfiosrelease=(grep “openSUSE” /etc/issue 2>/dev/null)
os_release_2=
(
g
r
e
p
"
o
p
e
n
S
U
S
E
"
/
e
t
c
/
∗
r
e
l
e
a
s
e
2
>
/
d
e
v
/
n
u
l
l
)
i
f
[
"
(grep "openSUSE" /etc/*release 2>/dev/null) if [ "
(grep"openSUSE"/etc/∗release2>/dev/null)if["os_release” ] && [ “
o
s
r
e
l
e
a
s
e
2
"
]
t
h
e
n
i
f
e
c
h
o
"
os_release_2" ] then if echo "
osrelease2"]thenifecho"os_release”|grep"13.1" >/dev/null 2>&1
then
os_release=opensuse131
echo “
o
s
r
e
l
e
a
s
e
"
e
l
s
e
o
s
r
e
l
e
a
s
e
=
"
"
e
c
h
o
"
os_release" else os_release="" echo "
osrelease"elseosrelease=""echo"os_release”
fi
break
fi
break
最全的Linux教程,Linux从入门到精通
======================
-
linux从入门到精通(第2版)
-
Linux系统移植
-
Linux驱动开发入门与实战
-
LINUX 系统移植 第2版
-
Linux开源网络全栈详解 从DPDK到OpenFlow
第一份《Linux从入门到精通》466页
====================
内容简介
====
本书是获得了很多读者好评的Linux经典畅销书**《Linux从入门到精通》的第2版**。本书第1版出版后曾经多次印刷,并被51CTO读书频道评为“最受读者喜爱的原创IT技术图书奖”。本书第﹖版以最新的Ubuntu 12.04为版本,循序渐进地向读者介绍了Linux 的基础应用、系统管理、网络应用、娱乐和办公、程序开发、服务器配置、系统安全等。本书附带1张光盘,内容为本书配套多媒体教学视频。另外,本书还为读者提供了大量的Linux学习资料和Ubuntu安装镜像文件,供读者免费下载。
本书适合广大Linux初中级用户、开源软件爱好者和大专院校的学生阅读,同时也非常适合准备从事Linux平台开发的各类人员。
需要《Linux入门到精通》、《linux系统移植》、《Linux驱动开发入门实战》、《Linux开源网络全栈》电子书籍及教程的工程师朋友们劳烦您转发+评论
网上学习资料一大堆,但如果学到的知识不成体系,遇到问题时只是浅尝辄止,不再深入研究,那么很难做到真正的技术提升。
一个人可以走的很快,但一群人才能走的更远!不论你是正从事IT行业的老鸟或是对IT行业感兴趣的新人,都欢迎加入我们的的圈子(技术交流、学习资源、职场吐槽、大厂内推、面试辅导),让我们一起学习成长!