Sesha futhi ufake amashayeli we-laptop ye-ASUS X550C

Ukuxhumeka okuphephile kwama-network nodes nokushintshaniswa kolwazi phakathi kwabo kuhlobene ngokuqondile namachweba avulekile. Ukuxhumeka nokudluliselwa kwezimoto kwenziwa ngechweba elithile, futhi uma kuvaliwe ohlelweni, akunakwenzeka ukwenza inqubo enjalo. Ngenxa yalokhu, abanye abasebenzisi banesithakazelo ekudluliseni inombolo eyodwa noma ngaphezulu ukulungisa ukusebenzisana kwamadivayisi. Namuhla sizobonisa indlela umsebenzi owenziwa ngayo kuzinhlelo zokusebenza ezisuselwe ku-kernel ye-Linux.

Vula amachweba ku-Linux

Nakuba kusakazwa okuningi, ngokuzenzakalelayo, kukhona ithuluzi lokuphatha inethiwekhi eyakhelwe ngaphakathi, kodwa izixazululo ezinjalo ngokuvamile azikuvumeli ukuba wenze ngokwezifiso ukuvula kwamapayipi. Imiyalo kulesi sihloko izosekelwa kwesicelo esengeziwe esibizwa ngokuthi i-Iptables - isisombululo sokuhlela izilungiselelo zomlilo usebenzisa ama-superuser. Kuzo zonke izakhiwo ze-OS ku-Linux, isebenza okufanayo, ngaphandle kokuthi umyalo wokufaka uhlukile, kodwa sizoxoxa ngakho ngezansi.

Uma ufuna ukwazi ukuthi yimaphi amachweba asevele evuliwe kwikhompyutha yakho, ungasebenzisa isakhiwo esakhelwe ngaphakathi noma esengeziwe se-console. Imiyalo eningiliziwe yokuthola ulwazi oludingekile ingatholakala kwenye i-athikili yethu ngokuchofoza isixhumanisi esilandelayo, futhi sizoqhubeka nokuhlaziywa kwesinyathelo ngesinyathelo sokuvula kwamaports.

Funda kabanzi: Buka amachweba avulekile ku-Ubuntu

Isinyathelo 1: Faka iptables futhi ubuke imithetho

Ukusetshenziswa kwe-iptables akuyona ingxenye yesistimu yokusebenza, yingakho udinga ukuyifaka ngokwakho kusuka ehhovisi elisemthethweni, bese usebenza nemithetho bese uyishintsha ngazo zonke izindlela. Ukufakwa akuthathi isikhathi esiningi futhi kwenziwa nge-console ejwayelekile.

  1. Vula imenyu bese ugijima "Isikhumbuzo". Lokhu kungenziwa futhi ngokusebenzisa i-hotkey ejwayelekile. I-Ctrl + Alt + T.
  2. Kusakazwa ngokusekelwe ohlwini lweDebian noma Ubuntusudo apt ukufaka iptablesukuqala ukufakwa, futhi ku-Fedora-based builds -sudo yum ufake iptables. Ngemva kokufaka ucindezela ukhiye Ngena.
  3. Yenza kusebenze amalungelo angaphezu kwamandla amakhulu ngokubhala iphasiwedi ye-akhawunti yakho. Sicela wazi ukuthi abalingiswa ababoniswa ngesikhathi sokufaka, lokhu kwenziwa ngokuphepha.
  4. Lindela ukufakwa ukuqedela futhi uqiniseke ukuthi ithuluzi lisebenza ngokubuyekeza uhlu olujwayelekile lwemithetho, okuvumelai-sudo iptables -L.

Njengoba ubona, umyalo manje ubonakala ekusakazeniiptablesonomthwalo wokuphatha ukusetshenziswa kwegama elifanayo. Siphinde sikhumbule ukuthi leli thuluzi lisebenza emalungelweni amakhulu, ngakho-ke ucingo kufanele luqukathe isiqalosudo, futhi kuphela kuphela amanani asele kanye nezimpikiswano.

Isinyathelo sesi-2: Nika amandla ukwabiwa kwedatha

Awekho amachweba azosebenza ngendlela evamile uma insizakalo ivimbela ukushintshaniswa kolwazi ezingeni lemithetho yalo yomlilo. Ngaphezu kwalokho, ukungabi nemithetho edingekayo esikhathini esizayo kungabangela ukubonakala kwamaphutha ahlukahlukene ngesikhathi sokudlulisela phambili, ngakho-ke sineluleka ngokuqinile ukuthi ulandele lezi zinyathelo:

  1. Qinisekisa ukuthi ayikho imithetho efonini yokucushwa. Kungcono ukubhalisa ngokushesha umyalo wokuwasusa, futhi kubonakala kanje:i-sudo iptables -F.
  2. Manje sengeza umyalo wedatha yokufaka kukhompyutha yendawo ngokufaka umugqasudo iptables -I-INPUT -i lo -j YAMAMELA.
  3. Mayelana nomyalo ofanayo -i-sudo iptables -I-OUTPUT -o lo -j YAMUKELA- unesibopho somthetho omusha wokuthumela ulwazi.
  4. Ihlala kuphela ukuqinisekisa ukusebenzisana okujwayelekile kwemithetho engenhla ukuze iseva ingabuyisa amaphakethe. Ngalokhu udinga ukuvimbela ukuxhuma okusha, nabakudala - ukuvumela. Lokhu kwenziwa ngokusebenzisai-sult iptables -I-INPUT -m state - okukhona okuqinisekisiwe, okuvunyelwe -j ukuvuma.

Ngenxa yemingcele engenhla, unikeze ukuthumela nokuthola idatha efanele, okuzokuvumela ukuba usebenze kalula ne-server noma enye ikhompyutha. Kuhlala kuphela ukuvula amarekhodi lapho khona ukuxhumana kuzokwenziwa khona.

Isinyathelo sesi-3: Ukuvula amachweba adingekayo

Usuvele ujwayelene nendlela imithetho emisha enziwe ngayo ukulungiselelwa kwe-iptables. Kunezimpikiswano eziningana zokuvula amarekhodi athile. Ake sihlaziye le nqubo besebenzisa isibonelo samachweba athandwayo anenani lama-22 no-80.

  1. Qala i-console bese ufaka imiyalo emibili elandelayo ngomunye:

    i-sult iptables -I-INPUT -p tcp - thumela i-22 -j Yamukela
    i-sudo iptables -I-INPUT -p tcp - thumela i-80 -j Yamukela
    .

  2. Manje hlola uhlu lwemithetho ukuze uqiniseke ukuthi amabhulogi athunyelwe ngempumelelo. Isetshenziselwe lo myalo osevele ujwayelekile.i-sudo iptables -L.
  3. Ungayinika ukubukeka okufundwayo futhi ubonise yonke imininingwane usebenzisa ukuphikisana okwengeziwe, khona-ke umugqa uzofana nalokhu:i-sudo iptables -nvL.
  4. Shintsha inqubomgomo ukuze usebenzise nge-standardi-sudo iptables -P INPUT DROPfuthi ukhululeke ukuqala umsebenzi phakathi kwama-node.

Uma kwenzeka umqondisi wekhompiyutha esebenzile imithetho yakhe, wahlela ukuwa kwamaphakethe ekufinyeleleni kwephuzu, isibonelo, ngokusebenzisai-sudo iptables -I-INPUT -j i-DROP, udinga ukusebenzisa enye imilayezo ye-sudo iptables:-I INPUT -p tcp - faka 1924 -j YAMAMELAkuphi 1924 - inombolo yefoni. Yanezela ichweba elidingekayo ekuqaleni kwesifunda, bese amaphakethe awashiywa.

Khona-ke ungabhala yonke into efanayoi-sudo iptables -Lfuthi qinisekisa ukuthi konke kuhlelwe kahle.

Manje uyazi ukuthi amathrekhi asezintweni zokusebenza ze-Linux adluliselwa kanjani ngesibonelo se-Iptables ezisebenzayo ezengeziwe. Sikukwazisa ukuthi ugcine amehlo emigqeni ebonakala ku-console uma ufaka imiyalo, lokhu kuzosiza ukuthola noma yikuphi amaphutha futhi ususe ngokushesha.