Home | 简体中文 | 繁体中文 | 杂文 | Search | ITEYE 博客 | OSChina 博客 | Facebook | Linkedin | 作品与服务 | Email

第 35 章 Firewall

摘要

Linux Firewall 安装与配置

目录

35.1. TCP/IP 相关内核配置项
35.1.1. net.ipv4.ip_forward
35.1.2. net.ipv4.icmp_echo_ignore_all
35.2. iptables - administration tools for packet filtering and NAT
35.2.1. Getting Started
35.2.1.1. CentOS/Redhat TUI 工具
35.2.2. 用户自定义规则连
35.2.2.1. Chains List
35.2.2.2. Chains Refresh
35.2.2.3. Chains Admin
35.2.2.4. 重置
35.2.3. Protocols 协议
35.2.4. Interfaces 网络适配器接口
35.2.5. 源IP地址
35.2.6. Ports 端口
35.2.7. IPTables and Connection Tracking
35.2.8. NAT
35.2.8.1. Redirect
35.2.8.2. Postrouting and IP Masquerading
35.2.8.3. Prerouting
35.2.8.4. DNAT and SNAT
35.2.8.5. DMZ zone
35.2.9. Module(模块)
35.2.9.1. string
35.2.9.2. connlimit
35.2.9.3. limit
35.2.10. IPV6
35.2.11. iptables-xml - Convert iptables-save format to XML
35.2.12. access.log IP封锁脚本
35.2.13. Example
35.2.13.1. INPUT Rule Chains
35.2.13.2. OUTPUT Rule Chains
35.2.13.3. Forward
35.2.13.4. Malicious Software and Spoofed IP Addresses
35.2.13.5. /etc/sysconfig/iptables 操作系统默认配置
35.3. ulogd - The Netfilter Userspace Logging Daemon
35.4. ufw - program for managing a netfilter firewall
35.4.1. /etc/default/ufw
35.4.2. ip_forward
35.4.3. DHCP
35.4.4. Samba
35.5. Shorewall
35.5.1. Installation Instructions
35.5.1.1. Install using RPM
35.5.1.2. Install using apt-get
35.5.2. Configuring Shorewall
35.5.2.1. zones
35.5.2.2. policy
35.5.2.3. interfaces
35.5.2.4. masq
35.5.2.5. rules
35.5.2.6. params
35.6. Firewall GUI Tools
35.7. Endian Firewall
35.8. Smooth Firewall
35.9. Sphirewall

35.1. TCP/IP 相关内核配置项

checking status

$ sysctl net.ipv4.ip_forward
net.ipv4.ip_forward = 0
		

or just checking out the value in the /proc system

$ cat /proc/sys/net/ipv4/ip_forward
0
		

enable

sysctl -w net.ipv4.ip_forward=1
		

or

		
#redhat
echo 1 > /proc/sys/net/ipv4/ip_forward
#debian/ubuntu
echo 1 | sudo tee /proc/sys/net/ipv4/ip_forward;
		
		

disable

sysctl -w net.ipv4.ip_forward=0
		

or

		
echo 0 > /proc/sys/net/ipv4/ip_forward
		
		

without rebooting the system

35.1.1. net.ipv4.ip_forward

表 35.1. net.ipv4.ip_forward

userroutewan
192.168.0.2eth0:192.168.0.1 eth1:172.16.0.1172.16.0.254

			
$ sysctl net.ipv4.ip_forward
net.ipv4.ip_forward = 0
			
			

try out ping host from 192.168.0.2 to 192.168.0.1 , 172.16.0.1 and 172.16.0.254

you can access 192.168.0.1 , 172.16.0.1, but 172.16.0.254 time out

sysctl -w net.ipv4.ip_forward=1

try again ping 172.16.0.254

35.1.2. net.ipv4.icmp_echo_ignore_all

如果希望屏蔽别人 ping 你的主机,则加入以下代码:

# Disable ping requests
net.ipv4.icmp_echo_ignore_all = 1
			
comments powered by Disqus