麻豆小视频在线观看_中文黄色一级片_久久久成人精品_成片免费观看视频大全_午夜精品久久久久久久99热浪潮_成人一区二区三区四区

首頁 > 系統(tǒng) > FreeBSD > 正文

FreeBSD ipfw 防火墻基礎(chǔ)指南

2024-07-26 00:29:23
字體:
供稿:網(wǎng)友

本文告訴你如何快速上手FreeBSD的ipFW防火墻

一、內(nèi)核配置
/usr/src/sys/i386/conf/HQ_SuperServer

代碼:
options IPFIREWALL
options IPFIREWALL_DEFAULT_TO_ACCEPT
options IPDIVERT # IPDIVERT enables the divert IP sockets, used by ''ipfw divert''
options IPFIREWALL_VERBOSE
options IPFIREWALL_VERBOSE_LIMIT=30

#options IPFILTER #ipfilter support
#options IPFILTER_LOG #ipfilter logging

# traffic shaper, bandwidth manager and delay emulator
options DUMMYNET # enables the "dummynet" bandwidth limiter. You need IPFIREWALL as well.
# Statically Link in accept filters for a web server on this box
options ACCEPT_FILTER_DATA
options ACCEPT_FILTER_HTTP
options ICMP_BANDLIM # D.O.S. PRotection
options IPSTEALTH #To hide firewall from traceroute
options TCP_DROP_SYNFIN #To hide from nmap OS fingerprint, remove if create web server




二、rc.conf配置
/etc/rc.conf

代碼:
firewall_enable="YES"
firewall_logging="YES"
firewall_script="/etc/rc.firewall"
firewall_quiet="NO" #change to YES once happy with rules
firewall_logging_enable="YES"

#extra firewalling options
log_in_vain="YES"
#This option prevents something known as OS fingerprinting, must have TCP_DROP_SYNFIN compiled into kernel to use
tcp_drop_synfin="NO" #change to NO if create webserver
tcp_restrict_rst="YES"
icmp_drop_redirect="YES"



三、ipfw使用

代碼:
ipfw add allow tcp from to in recv


添加和除去規(guī)則例子:
代碼:
$ sudo ipfw add deny tcp from 61.49.203.115 to 61.49.203.114 22 in recv fxp0
$ sudo ipfw -t list
$ sudo ipfw delete 00100


禁止icmp
代碼:
$ sudo ipfw add deny icmp from any to any in recv fxp0


顯示rules
代碼:
$ sudo ipfw show


按照序號顯示規(guī)則
代碼:
$ sudo ipfw -t list


列出信息包的數(shù)目,和與它們相對應(yīng)的規(guī)則匹配
代碼:
$ sudo ipfw -a list



四、/etc/ipfw.rules規(guī)則文件
代碼:
allow 00010 udp from any to me 67 in via $iif
allow 00020 udp from me 68 to any out via $iif


五、/etc/rc.firewall腳本

代碼:
# mv /etc/rc.firewall /etc/rc.firewall.orig
# touch /etc/rc.firewall
# chmod u=+rx,og=-rwx /etc/ipfw.rules


/etc/rc.firewall

代碼:
#!/bin/sh

# This will flush the existing rules - sudo ipfw -f flush
# You can execute this script without dropping existing connections/states

fwcmd="/sbin/ipfw -q"
extif="fxp0"
myip="10.1.8.114"
mybcast="10.1.8.119"
mynetwork="10.1.8.112/29"
dns_server="10.1.8.1"

# Reset all rules in case script run multiple times
${fwcmd} -f flush

${fwcmd} add 200 check-state

# Block RFC 1918 networks - the , syntax only works in ipfw2
${fwcmd} add 210 deny all from 0.0.0.0/7,1.0.0.0/8,2.0.0.0/8,5.0.0.0/8,10.0.0.0/8,23.0.0.0/8,/
27.0.0.0/8,31.0.0.0/8,67.0.0.0/8,68.0.0.0/6,72.0.0.0/5,80.0.0.0/4,96.0.0.0/3,127.0.0.0/8,/
128.0.0.0/16,128.66.0.0/16,169.254.0.0/16,172.16.0.0/12,191.255.0.0/16,192.0.0.0/16,/
192.168.0.0/16,197.0.0.0/8,201.0.0.0/8,204.152.64.0/23,224.0.0.0/3,240.0.0.0/8 to any

# Allow all via loopback to loopback
${fwcmd} add 220 allow all from any to any via lo0

# Allow from me to anywhere
${fwcmd} add 240 allow tcp from ${myip} to any setup keep-state
${fwcmd} add 260 allow udp from ${myip} to any keep-state
${fwcmd} add 280 allow icmp from ${myip} to any

# Allow local LAN to connect to us
${fwcmd} add 300 allow ip from ${mynetwork} to ${mynetwork}

# Allow INCOMING SSH,SMTP,HTTP from anywhere on the internet
${fwcmd} add 320 allow log tcp from any to ${myip} 22,25,80 in keep-state setup

# Disable icmp
${fwcmd} add 340 allow icmp from any to any icmptype 0,3,11

# Block all other traffic and log in
${fwcmd} add 360 deny log all from any to any

# End of /etc/rc.firewall




六、 ipfw日志紀(jì)錄配置


/etc/syslog.conf
代碼:
!ipfw
*.* /var/log/ipfw.log


代碼:
$ sudo touch /var/log/ipfw.log
$ sudo killall -HUP syslogd


發(fā)表評論 共有條評論
用戶名: 密碼:
驗(yàn)證碼: 匿名發(fā)表
主站蜘蛛池模板: 欧美精品一区二区三区在线 | av在线等 | 免费a视频| 国产一级性生活视频 | 欧美成人免费一级 | 成人不卡在线观看 | 最新91在线视频 | 色综合精品 | 嗯~啊~弄嗯~啊h高潮视频 | 手机在线看片国产 | 日韩欧美精品电影 | 性欧美xxxx极品摘花 | 九九热免费视频在线观看 | 在线看免电影网站 | 免费欧美一级视频 | 色诱亚洲精品久久久久久 | 欧洲成人一区二区 | 久久影院免费观看 | 国产免费一区二区三区视频 | 在线a亚洲视频播放在线观看 | 欧美一级黄色录相 | 成人免费视频视频在线观看 免费 | 日本羞羞的午夜电视剧 | 96视频在线免费观看 | 日韩av电影在线免费观看 | 日本成人一区二区 | chinese-xvideos | 日本s级毛片免费观看 | 欧美毛片 | 国产精品视频在线观看免费 | 日本网站一区 | 最近日本电影hd免费观看 | 得得啪在线视频 | 黄色特级片黄色特级片 | 久久久国产精品免费观看 | 一级大片久久 | 麻豆视频在线免费观看 | 日韩精品99久久久久久 | 鲁丝一区二区二区四区 | 国产视频导航 | 91免费视频版 |