<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>firewalld &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/firewalld/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Mon, 07 Aug 2023 07:04:53 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>在Ubuntu Linux安裝Firewalld防火牆套件</title>
		<link>https://ailog.tw/lifelog/2023/03/29/ubuntu-firewalld/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Wed, 29 Mar 2023 07:26:10 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[firewalld]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=15409</guid>

					<description><![CDATA[小編今天要來介紹在Ubuntu Linux中如何使用Firewalld做為Server防火牆。 1、停用Ubu &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2023/03/29/ubuntu-firewalld/" class="more-link">閱讀全文<span class="screen-reader-text">〈在Ubuntu Linux安裝Firewalld防火牆套件〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva; font-size: 14pt;">小編今天要來介紹在Ubuntu Linux中如何使用Firewalld做為Server防火牆。</span><br />
<span id="more-15409"></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong>1、停用Ubuntu內建的防火牆套件</strong></span><br />
sudo ufw disable<br />
<img decoding="async" class="alignnone wp-image-15412 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-01.png" alt="" width="584" height="82" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-01.png 584w, https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-01-300x42.png 300w" sizes="(max-width: 584px) 100vw, 584px" /><br />
</span></p>
<p><strong><span style="font-family: verdana, geneva; font-size: 14pt; color: #0000ff;">2、安裝Firewalld防火牆套件</span></strong><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">sudo apt update<br />
<img fetchpriority="high" decoding="async" class="alignnone wp-image-15413 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-02.png" alt="" width="946" height="246" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-02.png 946w, https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-02-300x78.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-02-768x200.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">sudo apt install firewalld<br />
<img decoding="async" class="alignnone wp-image-15414 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-03.png" alt="" width="629" height="351" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-03.png 629w, https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-03-300x167.png 300w" sizes="(max-width: 629px) 100vw, 629px" /></span></p>
<p><span style="color: #0000ff;"><strong><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
3、設定開機啟動Firewalld服務</span></strong></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">sudo systemctl enable firewalld<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-15416 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-04.png" alt="" width="576" height="99" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-04.png 576w, https://ailog.tw/lifelog/wp-content/uploads/2023/03/ubuntu-firewalld-04-300x52.png 300w" sizes="auto, (max-width: 576px) 100vw, 576px" /><br />
</span></p>
<p><span style="color: #0000ff;"><strong><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
4.其他常用指令</span></strong></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">(1)、啟動Firewalld服務</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">sudo systemctl start firewalld</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(2)、停止Firewalld服務</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">sudo systemctl stop firewalld</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(3)、重新啟動Firewalld服務</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">sudo systemctl restart firewalld</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(4)、查看Firewalld服務狀態</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">sudo systemctl status firewalld</span></p>
<p><span style="color: #0000ff;"><strong><span style="font-size: 14pt; font-family: verdana, geneva;">5、防火牆設定</span></strong></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">請參考「<a href="https://ailog.tw/lifelog/2023/03/28/linux-firewalld">https://ailog.tw/lifelog/2023/03/28/linux-firewalld</a>」這一篇文章。</span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Linux透過firewalld指令設定防火牆規則</title>
		<link>https://ailog.tw/lifelog/2023/03/28/linux-firewalld/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Tue, 28 Mar 2023 06:05:06 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[FIREWALL-CMD]]></category>
		<category><![CDATA[firewalld]]></category>
		<category><![CDATA[Oracle Linux]]></category>
		<category><![CDATA[Red Hat]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=15379</guid>

					<description><![CDATA[在CentOS 7 / Oracle Linux 7 / Red Hat7版本開始內建了firewalld這個 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2023/03/28/linux-firewalld/" class="more-link">閱讀全文<span class="screen-reader-text">〈Linux透過firewalld指令設定防火牆規則〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva; font-size: 14pt;">在CentOS 7 / Oracle Linux 7 / Red Hat7版本開始內建了firewalld這個防火牆管理的指令，比過往的Iptables使用上更為簡單，快來了解如何設定吧!</span></p>
<p><span id="more-15379"></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong>一、停止iptables服務</strong></span><br />
(1)、暫停iptables功能：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl stop iptables
</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(2)、停用iptables功能：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl mask iptables</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
<span style="color: #0000ff;"><strong>二、安裝firewalld套件</strong></span><br />
(1)、安裝firewalld套件：<br />
</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">sudo yum install firewalld</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(2)、設定開機自動執行firewalld：<br />
</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl enable firewalld</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(3)、檢查 firewalld 服務狀態：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl status firewalld</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(4)、啟動 firewalld 服務：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl start firewalld</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(5)、停止 firewalld 服務：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl stop firewalld</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(6)、重新啟動 firewalld 服務：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">service firewalld restart</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(7)、重新載入 firewalld 設定：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --reload</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong><br />
三、查詢設定狀態</strong></span><br />
(1)、查詢現有區域：<br />
</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --get-zones</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(2)、查詢「public」區域的設定：</span></p>
<pre><span style="font-size: 12pt; font-family: verdana, geneva;">firewall-cmd --zone=public --list-all</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(3)、查詢「public」的永久設定值：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --list-all --permanent</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(4)、查詢目前預設的區域：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --get-default-zone</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(5)、更改 firewalld 的預設區域為「office」：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --set-default-zone=office</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(6)、查詢各個網路介面所屬的區域：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --get-active-zones</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(7)、更改網路卡所屬的區域：<br />
將ens160網路卡<span style="color: #ff0000;">永久</span>設定為public區域的範例語法如下：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">sudo firewall-cmd --permanent --zone=public --change-interface=ens160</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(8)、查詢系統內建服務名稱：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --get-services</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(9)、查詢防火牆目前所有規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --list-all</span></pre>
<p>&nbsp;</p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong>四、設定防火牆規則</strong></span><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(1)、查詢各個網路介面所屬的區域：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --get-active-zones</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(2)、在public區域中「新增」<span style="color: #00ff00;">暫時</span>開放https服務規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --add-service=https</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(3)、在public區域中「新增」<span style="color: #ff0000;">永久</span>開放https服務規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --permanent --add-service=https</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(3)、在public區域中「新增」<span style="color: #ff0000;">永久</span>開放TCP 8080 Port規則：</span></p>
<pre><span style="font-size: 12pt; font-family: verdana, geneva;">firewall-cmd --zone=public --permanent --add-port=8080/tcp</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(4)、在public區域中「新增」<span style="color: #ff0000;">永久</span>開放192.168.6.111這個IP可以連線mysql(3306)服務規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --add-rich-rule 'rule family="ipv4" source address="192.168.6.111/32" service name="mysql" accept' --permanent</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(6)、在public區域中「新增」<span style="color: #ff0000;">永久<span style="color: #000000;">阻擋192.168.6.222這個IP連線的規則</span></span>：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --add-rich-rule 'rule family="ipv4" source address="192.168.6.222/32" reject' --permanent</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong><br />
五、移除防火牆規則</strong></span><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(1)、在public區域中「刪除」<span style="color: #ff0000;">暫時</span>開放https服務規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --remove-service=https</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(2)、在public區域中「刪除」<span style="color: #ff0000;">永久</span>開放https服務規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --permanent --remove-service=https</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(3)、在public區域中「刪除」<span style="color: #ff0000;">永久</span>開放TCP 8080 Port</span><span style="font-family: verdana, geneva; font-size: 14pt;">規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --permanent --remove-port=8080/tcp</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(4)、在public</span><span style="font-family: verdana, geneva; font-size: 14pt;">區域中「刪除」特定永久開放</span><span style="font-family: verdana, geneva; font-size: 14pt;">規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --remove-rich-rule 'rule family="ipv4" source address="192.168.6.111/32" service name="mysql" accept' --permanent</span></pre>
<p>&nbsp;</p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong>六、查看系統內建服務樣板</strong></span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(1)、查看系統預設防火牆服務樣板：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">ls /usr/lib/firewalld/services</span></pre>
<p>※如無適合的樣板，可以透過既有的樣板產生一個客製化的設定</p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(2)、建立客製化防火牆服務</span><span style="font-family: verdana, geneva; font-size: 14pt;">樣板：</span></p>
<pre>cd /usr/lib/firewalld/services
cp mysql.xml oracle.xml
vim oracle.xml</pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-16440 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/03/linux-firewalld-6-02.png" alt="" width="637" height="154" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/03/linux-firewalld-6-02.png 637w, https://ailog.tw/lifelog/wp-content/uploads/2023/03/linux-firewalld-6-02-300x73.png 300w" sizes="auto, (max-width: 637px) 100vw, 637px" /></span></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CentOS 8/Oracle Linux 8使用iptables防火牆</title>
		<link>https://ailog.tw/lifelog/2022/08/30/ol8-iptables/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Tue, 30 Aug 2022 14:09:12 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Centos 8]]></category>
		<category><![CDATA[firewalld]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[Oracle Linux 8]]></category>
		<category><![CDATA[指定網卡]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=13382</guid>

					<description><![CDATA[小編在Linux系統使用iptables已經很多年了，但新版的Linux預設是採用firewalld，難免還是 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2022/08/30/ol8-iptables/" class="more-link">閱讀全文<span class="screen-reader-text">〈CentOS 8/Oracle Linux 8使用iptables防火牆〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva; font-size: 14pt;">小編在Linux系統使用iptables已經很多年了，但新版的Linux預設是採用firewalld，難免還是有些不習慣，如果你跟小編一樣是懷舊的人，那就不可錯過這一篇在新版Linux啟用iptables的文章。<span id="more-13382"></span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set01、停用firewalld服務</strong></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">語法：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">systemctl stop firewalld<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13386 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-01.png" alt="" width="643" height="95" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-01.png 643w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-01-300x44.png 300w" sizes="auto, (max-width: 643px) 100vw, 643px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set02、關閉firewalld服務</strong><br />
語法：<br />
systemctl mask firewalld<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13387 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-02.png" alt="" width="934" height="126" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-02.png 934w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-02-300x40.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-02-768x104.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set03、安裝iptables套件</strong><br />
語法：<br />
yum install -y iptables<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13388 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-03.png" alt="" width="880" height="103" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-03.png 880w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-03-300x35.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-03-768x90.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set04、更新iptables套件</strong><br />
語法：<br />
yum update iptables<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13389 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-04.png" alt="" width="629" height="160" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-04.png 629w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-04-300x76.png 300w" sizes="auto, (max-width: 629px) 100vw, 629px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set05、安裝iptables服務套件</strong><br />
語法：<br />
yum install -y iptables-services<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13391 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-05.png" alt="" width="813" height="100" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-05.png 813w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-05-300x37.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-05-768x94.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set06、設定開機啟動iptables服務</strong><br />
語法：<br />
systemctl enable iptables.service<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13393 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-06.png" alt="" width="776" height="128" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-06.png 776w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-06-300x49.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-06-768x127.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set07、檢查iptables狀態</strong></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">語法：<br />
service iptables status<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13394 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-07.png" alt="" width="638" height="200" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-07.png 638w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-07-300x94.png 300w" sizes="auto, (max-width: 638px) 100vw, 638px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set08、設定預設規則</strong></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">語法：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">iptables -p input accept</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">iptables -p output accept</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">iptables -p forward accept<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13400 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-08.png" alt="" width="772" height="138" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-08.png 772w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-08-300x54.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-08-768x137.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
<span style="color: #ff0000;">※注意語法的大小寫</span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set09、清除防火牆相關規則</strong></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">(1)、清除防火牆規則<br />
語法：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">iptables -F</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">iptables -X<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13401 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-09.png" alt="" width="552" height="116" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-09.png 552w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-09-300x63.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(2)、清除mangle規則<br />
語法：<br />
iptables -F -t mangle<br />
iptables -t mangle -X<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13402 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-10.png" alt="" width="687" height="110" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-10.png 687w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-10-300x48.png 300w" sizes="auto, (max-width: 687px) 100vw, 687px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(3)、清除NAT規則<br />
語法：<br />
iptables -F -t nat<br />
iptables -t nat -X<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13403 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-11-e1661867066782.png" alt="" width="641" height="96" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-11-e1661867066782.png 641w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-11-e1661867066782-300x45.png 300w" sizes="auto, (max-width: 641px) 100vw, 641px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set11、查詢iptables目前規則</strong><br />
語法：<br />
iptables -L -v -n | more<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13405 size-large" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-12-1024x290.png" alt="" width="525" height="149" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-12-1024x290.png 1024w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-12-300x85.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-12-768x218.png 768w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-12.png 1114w" sizes="auto, (max-width: 525px) 100vw, 525px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set10、設定允許192.168.8.15透過TCP協定連入主機，其他主機的TCP協定拒絕連線</strong><br />
語法：<br />
iptables -A INPUT -p tcp -s 192.168.8.15 -j ACCEPT<br />
iptables -A INPUT -p tcp -j DROP<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13407 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-13.png" alt="" width="1014" height="120" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-13.png 1014w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-13-300x36.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-13-768x91.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><strong>Set10、指定網路卡設定防火牆規則<br />
語法：<br />
</strong><span style="font-size: 12pt;">iptables -A INPUT -i ens224 -p tcp -s 192.168.5.69 -j ACCEPT<br />
iptables -L -v -n | more<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13409 size-large" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-14-1024x334.png" alt="" width="525" height="171" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-14-1024x334.png 1024w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-14-300x98.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-14-768x250.png 768w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/ol8-iptables-14.png 1148w" sizes="auto, (max-width: 525px) 100vw, 525px" /></span></span></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
