CentOS7 Firewall »ç¿ë¹ý
http://ehostidc.co.kr/colocation/colocation.php (422)http://ehostidc.co.kr/cscenter/consulting.php (394)
1. firewalld160;설치 확1064; 0143; 설치 0169;법
(1). firewalld160;설치 확1064;
# rpm -qa | grep firewalld
(2).160;설치가 .104;Ǻ12; 1080;1648; 않다면 설치 1652;행
# yum install -y firewalld
2. firewalld160;시1089; 0143; 1473;1648;,160;시1089; መ1;/197;,160;1221;책 확1064; 0169;법
(1). firewalld160;시1089;
# systemctl start firewalld
(1452;1032;사항)
데몬1012; 시1089;Ȣ16;면160;22번 포트(SSH)160;와160;dhcpv6-client160;만 허용.104;므/196; 서비스 1473;1064;
포트가 1080;다면160;3번(firewalld160;포트 0143;160;IP160;허용,160;차단,160;삭1228;,160;설1221; 1201;용 0169;법)160;명/161;1004;/196; 포트 허용한 후,160;위 명/161;Ǻ12; 1077;/141;해야 합니다.
(2). firewalld160;1473;1648;
# systemctl stop firewalld
(3).160;서버 ǥ12;ᔚ1; 시160;firewalld160;데몬 1088;ᇼ1; 시1089; 설1221;
# systemctl enable firewalld
(4). firewalld160;설1221; 1221;보 확1064;
# firewall-cmd --zone=public --list-all
// vi160;를 통해 /etc/firewalld/zones/public.xml160;1217;속 후,160;1221;책 확1064;도 가능합니다.
3. firewalld160;포트 0143;160;IP160;허용,160;차단,160;삭1228;,160;설1221; 1201;용 0169;법
(1).160;특1221; 포트 허용 0169;법
# firewall-cmd --permanent --zone=public --add-port=포트번호/tcp
(포트번호에 원Ȣ16;lj16; 서비스 포트번호/196; 1077;/141;, UDP1032; ᅆ1;우에160;tcp를160;udp/196; 변ᅆ1;)
(2).160;모든 서비스에 대해 특1221;160;IP160;허용 0169;법
# firewall-cmd --permanent --add-source=IP1452;소
(3).160;특1221; 포트에 대해 특1221;160;IP1452;소 허용
# firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="IP1452;소" port protocol="tcp" port="포트번호"160;accept"
-1077;/141; 1204;
-1077;/141; 후
(4).160;특1221;160;IP160;차단 0169;법
# firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="IP1452;소"160;drop"
(5).160;특1221; 포트에 대해 특1221;160;IP1452;소 차단
# firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="IP1452;소"port protocol="tcp" port="포트번호"160;drop"
(6).160;1221;책 삭1228; 0169;법
# firewall-cmd --permanent --remove-port=포트번호/tcp
(포트번호 0143;160;tcp1032; ᅆ1;우,160;መ1;/197;.104;Ǻ12; 1080;lj16; 설1221;대/196; 1077;/141;)
(7). firewall160;설1221; 1201;용 0169;법
# firewall-cmd R11;reload
(1452;1032;사항)
설1221; 변ᅆ1; 후에160;reload160;Ȣ16;1648; 않1012; ᅆ1;우,160;1201;용.104;1648; 않습니다.
(예시) HTTP(TCP 80)160;포트 허용.
# firewall-cmd --permanent --zone=public --add-port=80/tcp
# firewall-cmd R11;reload
# firewall-cmd --zone=public --list-all //0169;화ǣ17; 설1221; 확1064;
|