ipchain |
±Û ¾´ ÀÌ |
linux |
³¯ Â¥ |
2003³â 01¿ù 02ÀÏ 17½Ã 35ºÐ 57ÃÊ |
º» ¹® |
--------------------------------------------------------------------------------
¾²½Å ºÐ : º¯Ã¢¼ö 122 ¹ø° °Ô½Ã¹°, Á¶È¸ : 88, ÁÙ¼ö : 71
ipchains
±âº» ÇüÅÂ
ipchains -A input -s host¸í -p ÇÁ·ÎÅäÄݸí -j ³»Àå¸ñÇ¥
ipchains -A input -s 0.0.0.0/0 -d 192.168.0.2 -j DENY
# 192.168.0.2 ¿¡ µé¾î¿À´Â ¸ðµç ÆÐŶÀ» °ÅºÎ ÇÑ´Ù.
ipchains -D input 1
# äÀÎ ¸ñ·Ï Áß Ã³À½ °ÍÀ» Áö¿î´Ù.
ipchains -A input -s 192.168.0.7 -p icmp -j DENY
# 192.168.0.7 ¿¡¼ µé¿À´Â ÆÐÅ°Áß icmp ÇÁ·Î°íÄÝÀ» ¸·´Â´Ù.
ipchains -A input -p icmp -j DENY
# ÀԷµǴ ¸ðµç icmp ¸¦ ¸·´Â´Ù.
ipchains -A input -p tcp -s 192.168.0.2 -j DENY
# 192.168.0.2 ¿¡¼ ¿À´Â tcp ÇÁ·ÎÅäÄÝÀ» ¸·´Â´Ù.
ipchains -A input -p tcp -s 192.168.0.2 -d 192.168.0.7 ! 23 -j DENY
# 192.168.0.2 ¿¡¼ 192.168.0.7 ·Î °¡´Â ÆÐŶ Áß 23¹ø Æ÷Æ®¸¦ Á¦È¸ÇÑ
#Æ÷Æ® °ÍÀº ¸·´Â´Ù.
echo "1" >/proc/sys/net/ipv4/ip_forward
/sbin/ipchains -P forward DENY
/sbin/ipchains -A forward -s 192.168.0.0/32 -j MASQ
/etc/rc.d/rc.firewall
ÆÄÀÏÀ» »ý¼º ÈÄ
ÀÌ ÆÄÀÏÀ»
/etc/r.cd/rc.local
¿¡ rc.firewall ¸¦ Ãß°¡ ÇÑ´Ù.
/sbin/ipchains -P forward deny
/sbin/ipchains -A forward -s 192.168.0.2/32 -j MASQ
/sbin/ipchains -A forward -s 192.168.0.8/32 -j MASQ
/sbin/modprobe ip_masq_ftp
ipchains -A input -p TCP -s 0/0 -d 192.168.0.1 23 -j DENY
msn ¸Þ½ÅÀú ¸·±â (1863 Æ÷Æ® »ç¿ë )
ipchains -A input -p tcp -s 0/0 -d 0/0 1863 -j DENY
2001/12/21 (02:17)
--------------------------------------------------------------------------------
|
|
|
|