利用iptables加固服务器

利用iptables加固服务器
  1. 设置默认规则
/sbin/iptables --policy INPUT DROP
/sbin/ip6tables --policy INPUT DROP
  1. 确保已经建立的链接不会被断开
/sbin/iptables -A INPUT -m state --state ESTABLISHED -j ACCEPT
  1. 设置服务器白名单(方便管理)
/sbin/iptables -A INPUT -s xx.xx.0.0/1x -j ACCEPT
  1. 设置应用白名单
/sbin/iptables -A INPUT -p tcp --dport 443 -j ACCEPT
  1. 设置SSH敲门协议
    5.1 --length 116,则表示敲门的icmp包大小为88(88+28=116),如果使用ping,则可以使用
    ping -s 88 来激活
    5.2 如果使用mtr,则指定-s 116来激活
    5.3 --seconds 60,表示激活后60秒内有效
    5.4 连接成功后,不断开就一直可以,如果seconds设置比较小,可以一直ping到SSH连接成功
/sbin/iptables -A INPUT -p icmp --icmp-type 8 -m length --length 127 -m recent --set --name SSHOPEN --rsource -j ACCEPT
/sbin/iptables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --name SSHOPEN --rsource -j ACCEPT
  1. 特殊的应用
    6.1 如果服务器使用mtr,则需要增加一个例外规则
/sbin/iptables -A INPUT -p icmp --icmp-type 11 -j ACCEPT

Comments

Anonymous said…
Matched Betting 2021: How To Do It | stillcasino.com
Matched 카지노사이트 Betting 2021: How To Do It matchpoint | stillcasino.com. Is Matched Betting Legal in link 12bet Canada? What Is Matched Betting?
Anonymous said…
Slots Empire has earned a reputation for itself as one of many 카지노사이트 prime on-line slots casinos and it isn't exhausting to see why. From its unbelievable look and feel to its nice game variety, Slots Empire is worthy of being referred to as one of the best on-line slots casinos out there. Our favourite game at Slots.lv was Arrogant Pirates, not only end result of|as a end result of} it’s foolish and enjoyable — however end result of|as a end result of} its rather frequent payouts won’t let your “pirate ship” sink immediately. This means you’ll get to enjoy more playtime with much less cash, and naturally — the likelihood to win 500x your stake if you get lucky. Understanding RNG will assist you to immensely in recognizing how on-line slots work. We can look at at|have a look at} the Random Number Generator as an integral half of} every slot machine.