CentOS 7 firewalld+geoip

   Á¶È¸ 6806   Ãßõ 0    

https://www.ehostidc.co.kr/cscenter/notice.php (294)
https://www.ehostidc.co.kr/cscenter/consulting.php (277)


1) maxmind 회원 가1077;

https://www.maxmind.com/en/geolite2/signup 회원가1077;

가1077;.108; 계1221;1004;/196; /196;그1064; 후 라1060;선스Ȗ12; 0156;급

  • 0156;급0155;1008; 라1060;선스 Ȗ12; 1221;보lj16; 1회 확1064; 후 확1064;1060; 안 .104;니 따/196; 1200;1109; 필요


2) 필수 패Ȗ12;1648; 설치

[root@master ~]# yum install gcc gcc-c++ make automake unzip zip kernel-devel-`uname -r` iptables-devel perl-CPAN wget libmnl* perl-NetAddr-IP perl-Text-CSV_XS


3) xtables-addons 다운/196;드

[root@master ~]# wget http://downloads.sourceforge.net/project/xtables-addons/Xtables-addons/xtables-addons-2.13.tar.xz 

[root@master ~]# tar xvf xtables-addons-2.13.tar.xz


4) xtables-addons 설치

[root@master xtables-addons-2.13]# vi mconfig => build_TARPIT=m 1452;석 처리

[root@master xtables-addons-2.13]# ./configure

[root@master xtables-addons-2.13]# make && make install


5) GeoLite2xtables  라1060;브러리 다운

[root@master ~]# cd

[root@master ~]# git clone https://github.com/mschmitt/GeoLite2xtables

[root@master ~]# cd GeoLite2xtables/

[root@master GeoLite2xtables]# mv geolite2.license.example geolite2.license

[root@master GeoLite2xtables]# vi geolite2.license => 0156;급0155;1008; 라1060;선스Ȗ12;/196; 수1221;


6) geoip database를 다운/196;드 0143; CSV 파1068; 변환

[root@master GeoLite2xtables]# ./00_download_geolite2

[root@master GeoLite2xtables]# ./10_download_countryinfo

[root@master GeoLite2xtables]# ll /tmp/

[root@master GeoLite2xtables]# mkdir /usr/share/xt_geoip

[root@master GeoLite2xtables]# cat /tmp/GeoLite2-Country-Blocks-IPv{4,6}.csv |./20_convert_geolite2 /tmp/CountryInfo.txt > /usr/share/xt_geoip/GeoIP-legacy.csv


7) geoip 모듈 csv 파1068; 1201;용

[root@master GeoLite2xtables]# cd

[root@master ~]# ./xtables-addons-2.13/geoip/xt_geoip_build -D /usr/share/xt_geoip/ /usr/share/xt_geoip/GeoIP-legacy.csv


8) geoip 모듈 csv 파1068; 1201;용

  • 특1221; 국가 차단

[root@master ~]# firewall-cmd --direct --add-rule ipv4 filter INPUT 0 -m geoip --src-cc [국가코드] -j DROP

  • 특1221; 국가 1228;외 1204;체 차단

[root@master ~]# firewall-cmd --direct --add-rule ipv4 filter INPUT 0 -m geoip ! --src-cc [국가코드] -j DROP




 


https://www.aiocp.co.kr/ ( 딥러닝,머신러닝 서버 판매 ,컨설팅) https://bigbangcloud.co.kr/ ( GPU 클라우드 서비스) ::: AI 서버의 모든것 ::: 인공지능의 시작~ (주)이호스트ICT


Á¦¸ñPage 1/26
2011-01   22156   ¾ÈÇü°ï
2013-12   14577   ±èÀ±¼ú
2017-04   32233   ä¼±ÀÏ
2019-03   11431   ±ô¹Ú±ô¹Ú°¡
2019-07   23862   ½ºÄµl¹ÎÇö±â
2020-07   6919   »ßµ¹À̽½ÇÄÀÌ
2020-12   9665   È­Á¤Å¥»ï
2021-04   11023   µö·¯´×¼­¹ö
2021-07   8419   ¹Ú¹®Çü
2021-12   10556   µö·¯´×¼­¹ö
2022-03   11682   µö·¯´×¼­¹ö
2022-06   27665   µö·¯´×¼­¹ö
2022-11   36099   µö·¯´×¼­¹ö
2023-03   38788   µö·¯´×¼­¹ö
2011-08   12069   ÀüÁ÷P¿¬±¸¿ø
2014-06   30052   ȲÁø¿ì
2018-08   16422   ±èÇö¸°
2019-03   8917   »ïÀ°°ø¾ßµå
2019-07   14980   ½ºÄµl¹ÎÇö±â
2020-04   17111   ½ºÄµl¹ÎÇö±â