{"id":2311,"date":"2020-01-11T17:42:27","date_gmt":"2020-01-11T09:42:27","guid":{"rendered":"https:\/\/ailog.tw\/lifelog\/?p=2311"},"modified":"2020-01-11T17:42:27","modified_gmt":"2020-01-11T09:42:27","slug":"ubuntu-firewall","status":"publish","type":"post","link":"https:\/\/ailog.tw\/lifelog\/2020\/01\/11\/ubuntu-firewall\/","title":{"rendered":"Ubuntu 18 \u9632\u706b\u7246\u7c21\u6613\u8a2d\u5b9a"},"content":{"rendered":"<p>Ubuntu\u4e5f\u662f\u67b6\u8a2dServer\u5e38\u7528\u7684Linux\u4f5c\u696d\u7cfb\u7d71\uff0c\u5feb\u8ddf\u8457\u5c0f\u7de8\u4e00\u8d77\u4f86\u4e86\u89e3\u5982\u4f55\u8a2d\u5b9a\u5167\u5efa\u7684\u9632\u706b\u7246\u8edf\u9ad4\u5427!<!--more--><\/p>\n<p>[1]\u3001\u5b89\u88dd\u9632\u706b\u7246\u8edf\u9ad4(\u4e00\u822c\u4f86\u8aaa\u9810\u8a2d\u90fd\u662f\u6709\u5b89\u88dd\u7684)<br \/>\nsudo apt-get install ufw<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2322\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-000.png\" alt=\"\" width=\"434\" height=\"73\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-000.png 434w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-000-300x50.png 300w\" sizes=\"auto, (max-width: 434px) 100vw, 434px\" \/><\/p>\n<p>[2]\u3001\u4e0d\u9650\u5236IP\u4f86\u6e90\u7684\u72c0\u6cc1\u4e0b\u958b\u653e\u670d\u52d9Port<br \/>\nsudo ufw allow ssh<br \/>\nsudo ufw allow http<br \/>\nsudo ufw allow https<br \/>\nsudo ufw allow 5432<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2312\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-001.png\" alt=\"\" width=\"399\" height=\"241\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-001.png 399w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-001-300x181.png 300w\" sizes=\"auto, (max-width: 399px) 100vw, 399px\" \/><\/p>\n<p>[3]\u3001\u9650\u5236\u4f86\u6e90IP\u4e26\u5141\u8a31\u4efb\u4f55Port<br \/>\nsudo ufw allow from 192.168.0.1\/32<br \/>\nsudo ufw allow from 192.168.1.200\/32<br \/>\nsudo ufw allow from 192.168.3.11\/32<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2313\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-002.png\" alt=\"\" width=\"558\" height=\"137\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-002.png 558w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-002-300x74.png 300w\" sizes=\"auto, (max-width: 558px) 100vw, 558px\" \/><\/p>\n<p>[4]\u3001\u9650\u5236\u4f86\u6e90IP\u4e26\u5141\u8a31\u7279\u5b9aPort<br \/>\nsudo ufw allow from 192.168.33.55 to any port 22<br \/>\nsudo ufw allow from 192.168.7.5 to any port 80<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2320\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-008.png\" alt=\"\" width=\"675\" height=\"96\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-008.png 675w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-008-300x43.png 300w\" sizes=\"auto, (max-width: 675px) 100vw, 675px\" \/><\/p>\n<p>[5]\u3001\u555f\u52d5\u9632\u706b\u7246<br \/>\nsudo ufw enable<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2314\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-003.png\" alt=\"\" width=\"415\" height=\"116\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-003.png 415w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-003-300x84.png 300w\" sizes=\"auto, (max-width: 415px) 100vw, 415px\" \/><\/p>\n<p>[6]\u3001\u95dc\u9589\u9632\u706b\u7246<br \/>\nsudo ufw disable<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2321\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-010.png\" alt=\"\" width=\"496\" height=\"66\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-010.png 496w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-010-300x40.png 300w\" sizes=\"auto, (max-width: 496px) 100vw, 496px\" \/><\/p>\n<p>[7]\u3001\u67e5\u770b\u9632\u706b\u7246\u8a2d\u5b9a\u72c0\u614b<br \/>\nsudo ufw status<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2315\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-004.png\" alt=\"\" width=\"534\" height=\"299\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-004.png 534w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-004-300x168.png 300w\" sizes=\"auto, (max-width: 534px) 100vw, 534px\" \/><\/p>\n<p>\u5e36\u51fa\u9632\u706b\u7246\u8a2d\u5b9a\u72c0\u614b\u4e26\u5e36\u51fa\u7de8\u865f\u7684\u6307\u4ee4<br \/>\nsudo ufw status numbered<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2316\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-005.png\" alt=\"\" width=\"580\" height=\"298\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-005.png 580w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-005-300x154.png 300w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" \/><\/p>\n<p>[8]\u3001\u522a\u9664\u9632\u706b\u7246\u7b2c3\u689d\u898f\u5247<br \/>\nsudo ufw delete 3<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2317\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-006.png\" alt=\"\" width=\"364\" height=\"119\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-006.png 364w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-006-300x98.png 300w\" sizes=\"auto, (max-width: 364px) 100vw, 364px\" \/><\/p>\n<p>[9]\u3001\u522a\u9664\u6240\u6709\u9632\u706b\u7246\u8a2d\u5b9a<br \/>\nsudo ufw reset<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2318\" src=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-007.png\" alt=\"\" width=\"727\" height=\"167\" srcset=\"https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-007.png 727w, https:\/\/ailog.tw\/lifelog\/wp-content\/uploads\/2020\/01\/Ubuntu-FW-007-300x69.png 300w\" sizes=\"auto, (max-width: 727px) 100vw, 727px\" \/><\/p>\n<p>[10]\u3001\u9632\u706b\u7246\u9810\u8a2d\u898f\u5247\u662f\u5c01\u9396\u9084\u662f\u653e\u884c\u8a2d\u5b9a(\u5176\u5be6\u5c31\u662f\u6b63\u5411\u8868\u5217\u8ddf\u8ca0\u5411\u8868\u5217\u7684\u7528\u9014)<br \/>\n10.1\u3001\u8a2d\u5b9a\u70ba\u9810\u8a2d\u653e\u884c<br \/>\nsudo ufw default allow<br \/>\n\u5099\u8a3b\u8aaa\u660e\uff1a\u4f7f\u7528\u5728\u8ca0\u5411\u8868\u5217\u7684\u60c5\u5883\uff0c\u898f\u5247\u4e2d\u90fd\u662f\u8a2d\u5b9a\u300c\u62d2\u7d55\u9023\u7dda\u300d\u7684\u689d\u5217\uff0c\u4e0d\u5728\u898f\u5247\u5b9a\u7fa9\u7684\uff0c\u901a\u901a\u90fd\u662f\u300c\u5141\u8a31\u300d\u3002<\/p>\n<p>10.2\u3001\u8a2d\u5b9a\u70ba\u9810\u8a2d\u5c01\u9396<br \/>\nsudo ufw default deny<br \/>\n\u5099\u8a3b\u8aaa\u660e\uff1a\u4f7f\u7528\u5728\u6b63\u5411\u8868\u5217\u7684\u60c5\u5883\uff0c\u898f\u5247\u4e2d\u90fd\u662f\u8a2d\u5b9a\u300c\u5141\u8a31\u300d\u9023\u7dda\u7684\u689d\u5217\uff0c\u4e0d\u5728\u898f\u5247\u5b9a\u7fa9\u7684\uff0c\u901a\u901a\u90fd\u662f\u300c\u62d2\u7d55\u9023\u7dda\u300d\u3002<\/p>\n<p>[11]\u3001\u8a2a\u706b\u7246\u8a2d\u5b9a\u898f\u5247\u88dc\u5145<br \/>\n\u4e0a\u8ff0\u7684\u6240\u6709\u9632\u706b\u7246\u898f\u5247\u8a2d\u5b9a\u53ea\u8981\u6709\u300callow\u300d\u8ddf\u300cdeny\u300d\u7684\u5730\u65b9\u90fd\u53ef\u4ee5\u4e92\u63db\uff0c\u5c31\u770b\u60c5\u5883\u7684\u9700\u6c42\u662f\u4ec0\u9ebc\uff0c\u9019\u500b\u5c31\u8b93\u5927\u5bb6\u81ea\u5df1\u52d5\u52d5\u8166\u6402!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ubuntu\u4e5f\u662f\u67b6\u8a2dServer\u5e38\u7528\u7684Linux\u4f5c\u696d\u7cfb\u7d71\uff0c\u5feb\u8ddf\u8457\u5c0f\u7de8\u4e00\u8d77\u4f86\u4e86\u89e3\u5982\u4f55\u8a2d\u5b9a\u5167\u5efa\u7684\u9632\u706b\u7246\u8edf\u9ad4\u5427!<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,379],"tags":[167,740,751],"class_list":["post-2311","post","type-post","status-publish","format-standard","hentry","category-itinfo","category-linux","tag-firewall","tag-ubuntu-18","tag-ufw"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/posts\/2311","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/comments?post=2311"}],"version-history":[{"count":2,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/posts\/2311\/revisions"}],"predecessor-version":[{"id":2323,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/posts\/2311\/revisions\/2323"}],"wp:attachment":[{"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/media?parent=2311"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/categories?post=2311"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ailog.tw\/lifelog\/wp-json\/wp\/v2\/tags?post=2311"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}