èæ¯ ãã¡ã¤ã³ç§»ç®¡ã®é¢ä¿ã§CloudFrontã®DNSã¬ã³ã¼ããDNSimpleããRoute53ã¸ç§»ããã¨ãã¦ããã®ã§ãããå®å ¨ãªç§»ç®¡æç¶åã«Route53å´ã®ã¬ã³ã¼ãã§ã¨ãã¸ãµã¼ãã«ã¡ããã¨ã¢ã¯ã»ã¹ã§ããã確èªããå¿ è¦ãããã¾ããã digã®NSæå®ã使ãã°ã¨ãã¸ãµã¼ãã®IPã¯ç¢ºèªã§ãã¾ãããCloudFrontãç´IPæå®ã§ã¢ã¯ã»ã¹ãã¦ã403ãè¿ãã ãã§ãã ããã§curlã®resolvãªãã·ã§ã³ã使ããã¨ã§ãIPãæå®ãã¤ã¤ãã¡ã¤ã³åã§ã¢ã¯ã»ã¹ããããã«ãã¾ããã ç°å¢ curl 7.54.0 (x86_64-apple-darwin17.0) æé ã¨ãã¸ãµã¼ãã®IPãåå¾ ã¾ãCloudFrontã®ã¨ãã¸ãµã¼ããè¦ã¤ãã¾ãã $ dig awa.fm @ns-1032.awsdns-01.org ; <<>> DiG 9.10.6 <<>> awa.fm @ns-1032.a
ãªã¾ã«ãã¯DNSã«ããã¦ãDNSã«ãã¹ãåã®IPã¢ãã¬ã¹ãæ¤ç´¢ããã®éãä¾é ¼ããã¯ã©ã¤ã¢ã³ãå´ã®ããã°ã©ã ã§ãã ãªã½ã«ãã¯OSã®æ©è½ã¨ãã¦æä¾ãããã¢ããªã±ã¼ã·ã§ã³ã®åå解決ããµãã¼ããã¾ãã ð resolv.confresolv.confã¯ãªã¾ã«ãã®è¨å®ãè¨è¿°ãã¾ããåºæ¬çã«ã¯æ¬¡ã®å 容ãè¨è¿°ãã¾ãã domaindomainã«xxx.comã¨è¨å®ããå ´åãtelnet hogeã¨ããã¨æåã«hoge.xxx.comã®IPã¢ãã¬ã¹ãæ¤ç´¢ãã¾ãã è¦ã¤ãããªããã°ãhogeã®IPã¢ãã¬ã¹ãæ¤ç´¢ãã¾ããããã§ãè¦ã¤ãããªãå ´åã¯ã¨ã©ã¼ãè¿ãã¾ãã searchsearch yyy.ne.jp zzz.orgã¨è¨å®ããã¨ãtelnet hogeãå®è¡ãããã hoge.xxx.com (domainã®è¨å®) hoge.yyy.ne.jp (searchã®è¨å®) hoge.zzz.org (
ãã¹ãåãå©ç¨ãã¦éä¿¡ã確ç«ããã«ã¯ãhosts ãã¡ã¤ã«ã使ã£ãæ¹æ³ã¨ãDNSã«ããåå解決ã®2éãããã â» ãã ããhosts ãã¡ã¤ã«ã使ã£ãæ¹æ³ã¯ãLANå é¨ã§ç®¡çããã±ã¼ã¹ã«éãã /etc/hosts è¨è¿°ä¾ 192.168.11.6 foo foo.example.co.jpãã®å ´åã192.168.11.6ãã®ãã·ã³ã¸ãfooãã¨ããååã§ã¢ã¯ã»ã¹ã§ããããã«ãªã etc/resolv.conf nameserver 192.168.11.1 IPã¢ãã¬ã¹ã192.168.11.1ãã®DNSãµã¼ããå©ç¨ãã ãªããè¤æ°ã®DNSãµã¼ããæå®ãããã¨ãå¯è½ etc/nsswitch.conf hosts, resolv.conf ã¨2種é¡ã®åå解決ã®åªå é ä½ããã®ãã¡ã¤ã«ã§æå®ãã #hosts: db files nisplus nis dns hosts: files d
Webã¹ã¯ã¬ã¤ãã³ã°ããããã®ã ãã©ãVPNããããã·ã¼ã§ä¸çªè¯ããµã¼ãã¹ã¯ãªãã ãããï¼ï¼ Linuxã§ä½¿ãããã¹ããªVPNãµã¼ãã¹ãæãã¦ã»ããï¼ â¦ã¨ããå½¢ã«ãæé©ãªãã©ã¯ãã£ã¹ããç´¹ä»ãã¾ãã ã¨ãããã¨ã§ãããã«ã¡ã¯ï¼ Webãµã¤ããèªåã§åå¾ãããWebã¹ã¯ã¬ã¤ãã³ã°ããããä¸ã§ãå¿ ãããã¯ã¨ãªãã®ãã¢ã¯ã»ã¹ããIPã¢ãã¬ã¹ã®åé¡ã§ãã ã¹ã¯ã¬ã¤ãã³ã°ãã対象ã®ãµã¼ãã¹ã®å¶æ¥å¦¨å®³ã«ãªããªãç¯å²ã§ã¹ã¯ã¬ã¤ãã³ã°ããã®ã¯è¨ãã¾ã§ããªãå½ç¶ã®è©±ã§ãããWebãµã¤ãã«ãã£ã¦ã¯ãå°ãã®ã¢ã¯ã»ã¹ã§ãä¸æ£ãªã¢ã¯ã»ã¹ã¨èªèãã¦IPã¢ãã¬ã¹ãã¨ãããã¯ãã¦ãã¾ããã¨ãããã¾ãã ãããåé¿ããããã«ã¯ãå®æçãªIPã¢ãã¬ã¹å¤æ´ãªã©ã®å¯¾å¿ãå¿ è¦ã§ãã ä¸è¬çã«ã¯ããããåé¡ã¯ãããã·ã¼ãVPNãµã¼ãã¹ã使ã£ã¦åé¿ãããã¨ã«ãªãã¾ãããå ·ä½çã«ã¯ã©ããããè¯ãã®ã§ãããï¼ çµè«ãè¨ãã¾ãã¨ããNor
--verbose --verboseãªãã·ã§ã³ãã¤ããã¨ãªã¯ã¨ã¹ãããããã¬ã¹ãã³ã¹ããããhttpsãªãTLS handshakeã®æ§åçãåºåãããããã«ãªãã¾ãããªã®ã§ã--verboseãã¤ããã¨ããããè¦ãã¾ãã ã¾ãããã®"verboseãª"æ å ±ã¯æ¨æºã¨ã©ã¼åºåã«åºåãããã®ã§ããããã ãè¦ãããã¨è¨ãæã¯æ¨æºåºåã¯/dev/nullã«æ¨ã¦ã¡ããã¨ããæãã«è¦ããããªãã¾ãã $ curl --verbose http://increments.co.jp/ 1> /dev/null * About to connect() to increments.co.jp port 80 (#0) * Trying 75.101.145.87... % Total % Received % Xferd Average Speed Time Time Time Current Dloa
ããã«ã¡ã¯ãã«ããã«æ¥ã¦1å¹´å¼±ã§ããããã¾ã ã«"how are you?"ã«ã¢ã¤ã ãã¡ã¤ã³ã»ã³ãã¥ã¼ã¨è¿ãã¦ãã¾ãå ¨ç¶è±èªãä¸éãã¦ãªãèè³¢ã§ãã ã¤ã³ãã©ã¨ã³ã¸ãã¢ãªãã¿ããªå¤§å¥½ãtopã³ãã³ãããããããã¨ã³ãã®ä¸ã§ã¯ãµã¼ãéç¨ã®ä¸ã§æåã«è¦ããã³ãã³ããããªãã§ããããã å®ã¯çµæ§å¥¥ãæ·±ãã³ãã³ãã§ããããªãã¨ãã§ããã®ã§ãããã¾ã§ãã¤é¡ã§ããããªãã¨ãã§ããããã§ãã¨ä¸å¸ã®å¨å³ããããã¨ãå 輩ã¨ãã¦ã®çµé¨ãå¾é²ã«ä¼ãã¦ããã®ã§ããç§ãæè¿ã«ãªã£ã¦åãã¦ç¥ã£ãè¶ ä¾¿å©ãªä½¿ãæ¹ãç´¹ä»ãããã¨æãã¾ãã ã¡ãã£ã¨é·ãã§ãããä»ãåããã ããã æ®éã«topã³ãã³ããå®è¡ããã¨ä»¥ä¸ã®ãããªç»é¢ã表示ããã¾ã çµæ§ããã ãã§ããµã¼ãéç¨ã«ã¯éè¦ãªæ å ±ãè©°ã¾ã£ã¦ããã®ã§ãããtopã³ãã³ãã®è¦æ¹ãªã©ã¯ä»ã§ãè²ã ã¨ç´¹ä»ããã¦ããã¨æãã®ã§ä»åã¯å²æãã¾ã ä»åã¯ãã®topã³ãã³ãã®è¡¨ç¤ºãæçµçã«ã
scpã³ãã³ãèªä½ãä¹ ãã¶ãã«ä½¿ãã¨æ¸å¼ãå¿ããã¡ã§ããã ã¯ã¤ã«ãã«ã¼ããï¼ãã使ã£ã¦è»¢éãããã¡ã¤ã«ãè¤æ°é¸æãããã¨ãã§ãã¾ãã
æè¿ã®CentOS7ãFedoraãªã©ã¯ããã©ã«ãã§firewalldãæå¹ã«ãªã£ã¦ãããåºæ¬çã«ãã¼ãã¯å¡ãã£ã¦ããã ãµã¼ãã¹ãæä¾ããã«ã¯ãé©åã«è¨å®ããããµã¼ãã¢ããªã±ã¼ã·ã§ã³ã¨é©åãªãã¼ãéæ¾ãå¿ è¦ã¨ãªããä¾ãã°webãµã¼ãã®å ´åapacheãªã©ãè¨å®ãèµ·åããã®å¾firewalldã®è¨å®ãè¡ã80çªã®ãã¼ããéæ¾ããå¿ è¦ãããã ãã®ãã¼ã¸ã§ã¯CentOSã®ãã¼ã解æ¾ã«ã¤ãã¦ãä¼ããããã ãããããã¼ãã¨ã¯ï¼ 念ã®ãããç´¹ä»ãã¦ãããã TCPãUDPã§éä¿¡ãè¡ãã¨ãã¯ãã³ã³ãã¥ã¼ã¿åä½ã§ã¯ãªããããã»ã¹ãã¹ã¬ããåä½ãã§éä¿¡ãè¡ãããããã®æã®éä¿¡ã®çªå£ããã¼ãã§ããã ãããã¯ã¼ã¯éã§ããåããããæ å ±ã®åºç¤ã¯ããããã³ã«ãã¨ãã¢ãã¬ã¹ãã¨ããã¼ãçªå·ããã®ä¸ã¤ã主軸ã«ãªã£ã¦ããã æ¥æ¬èªã«ãã¨ãããã¨ãã©ã®ãããªæ¹æ³ã(ãããã³ã«)ã§ãã©ãã(ã¢ãã¬ã¹)ã®ãä½å·å®¤ã(ã
ææ°çã¯ä»¥ä¸ã¨ãªãã¾ãã https://dev.classmethod.jp/etc/ec2-tcp-port-check-command-2018/ ããã«ã¡ã¯ã³ã«ã³ã¼ã©å¥½ãã®æ¢¶ã§ãã EC2ã§ã¯è²ã ãªOSãæ§ç¯ã§ãã¾ããããæ§ç¯å¾ã®é信確èªã¯ã©ã®ããã«å®æ½ãã¦ã¾ããï¼ åOSã§ä»ã®ã¤ã³ã¹ã¿ã³ã¹ã¸TCPé信確èªã®ããã«ããã¼ã«ãã¤ã³ã¹ãã¼ã«ããããICMPãªã©ã®å¥ãªãããã³ã«ã§ç¢ºèªããããã«Security Groupãä¸æ解æ¾ãã¦ãã¾ãããï¼ æ§ç¯ç´å¾ã®ç¶æ ã§ãç°¡åã«TCPãã¼ãçé確èªå¯è½ãªã³ãã³ãããç´¹ä»ãã¾ãã Amazon Linux,Ubuntu,Windows2012R2,CentOSã«ã¤ãã¦èªåãå¿ããããã®ã§ã¾ã¨ãã¦ã¿ã¾ããã ã©ãªããã®ãå½¹ã«ç«ã¦ãã°å¹¸ãã§ãã Amazon Linux åä½ç¢ºèªAMI:amzn-ami-hvm-2014.09.2.x86_64-eb
# éãã¦ãããã¼ãã¨ä½¿ç¨ãã¦ããããã»ã¹ï¼IPv4ï¼ $ sudo netstat -ltup4 sudo netstat -ltup4 Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 0.0.0.0:mysql 0.0.0.0:* LISTEN 2015/mysqld tcp 0 0 localhost:smtp 0.0.0.0:* LISTEN 2282/master tcp 0 0 0.0.0.0:10022 0.0.0.0:* LISTEN 1274/sshd udp 0 0 localhost:323 0.0.0.0:* 658/chronyd # ä¸è¨ãæ°å¤ã§ sudo nets
$dig <domain> ; <<>> DiG 9.8.3-P1 <<>> ANY <domain> ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29775 ;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 4, ADDITIONAL: 4 ... ;; QUESTION SECTION: ... ;; ANSWER SECTION: ... ;; AUTHORITY SECTION: ... ;; ADDITIONAL SECTION: ... ;; Query time: 31 msec ;; SERVER: 61.122.116.147#53(61.122.116.147) ;; WHEN:
ããã«ã¡ã¯ãæè¡é¨ã®kyomoã¨ç³ãã¾ãã ä»æ¥ã¯digã³ãã³ãã®ã話ãå°ããããã¨æãã¾ãã domain information groperãç¥ãã¦digã ä¸è¨ã訳ãã¨ããã¡ã¤ã³æ å ±ãææ¢ããããã®ãã¨ãªãã¾ãã digãå訳ããã¨ãæãããªã®ã§ ããã¡ã¤ã³ã®æ å ±ãæãããã«æ¢ãããdigã£ã¦ã³ãã³ããªãã ãªã¼ãªãã»ã©ãªã¼ã ã¨åéããã¦ããã¾ãããæ¥ããããã å æ¥CentOS7ã®ãµã¼ããå人çã«ä½æããéã«digã³ãã³ãã使ããªãã£ãã®ã§ ã¡ãã£ã¨ãã®æã®ã話ãæ¸ãã¾ããã ä½æ°ãªãã«ãã®CentOS7ã®ãµã¼ãã§digã§æ å ±ãå¼ããã¨æã£ããå¼ãã¾ããã§ããã # dig google.com -------------- -------------- -------------- -bash: dig:command not found -------------- ----
Chris's Wiki :: blog/linux/ReplacingNetstatNotBad ãã¯ã Linux 㧠ifconfig ã netstat ã¨ãã£ãæããããï¼ã¤ã¾ã Unix ç±æ¥ã®ï¼ãããã¯ã¼ã¯ãã¼ã«ãéæ¨å¥¨ã«ãã¦ãss ã ip ã¨ãã£ããã®ã«ç½®ãæãã¦ããã¨ãã話ãã¯ã¿ã·ãç¥ã£ãã®ã¯â¦â¦è¨æ¶ã辿ãã¨ãã©ããã山形浩ççµç±ãããã ãã®æ¹éã«å¯¾ããå¤æã®ã·ã¹ãã 管çè ã«ã¯ããªãã§å®å®ãã¦åãã¦ãããã®ãç½®ãæããªããã°ãªããªãã®ãã¨ã¤ã©ã¤ã©ããåããããã®ã ãããããå¿ è¦ãªçç±ã«ã¤ãã¦è§£èª¬ãã¦ããã ã¾ãä¸ã¤ã«ã¯ã/proc é ä¸ã®ããããªãã¡ã¤ã«ãèªã ifconfig ã netstat ã¯ãiproute2 ã®ä¸é¨ã§ãã netlink ã½ã±ãããå©ç¨ãã ss ã ip ãããã³ãã³ãã®å®è¡ãéå¹çã¨ããã®ããããããã大è¦æ¨¡ãªã·ã¹ãã ã ã¨åé¡ã«ãªãã¨ã
æ¦è¦ 大éªæ¬ç¤¾ã¨äº¬é½æ¯ç¤¾ã§åå¥ã«æ§ç¯ããã¦ããLANããã¤ã³ã¿ã¼ãããVPNã使ã£ã¦ æ¥ç¶ããå©ä¾¿æ§ãåä¸ããããã¨ã«ãã¾ãã大ã¾ããªè¦ä»¶ã¯ä»¥ä¸ã®éãã 両æ¹ã¨ãåçã°ãã¼ãã«IPã§ã¤ã³ã¿ã¼ãããã«æ¥ç¶ Windowsã®ãã¡ã¤ã«å ±æãã§ãã NetMeetingã«ãããããªä¼è°ãã§ãã Age of Empireã§éã¹ã æ°è¦ã«å¿ è¦ãªãã®ãããããã®ã§ããã°ã Persolã®BSR14 ã¨ãã Linksysã®BEFSR41C-JP ãããã2å°è²·ã£ã¦ãã¦IPSecã§æ¥ç¶ããã®ãç°¡åã§ãããããã§ã¯å³æ°ãªã ã®ã§ãæ¢åã®Linuxãã·ã³ã使ã£ã¦VPNãæ§ç¯ãã¾ãã VPNæè¡ã®æ¯è¼ããã両端ãåçIPã§ãæ¥ç¶ã§ããOpenVPNã使ããã¨ã«ãã¾ãã ãããã¯ã¼ã¯ä»æ§ 大éªæ¬ç¤¾ LAN 1192.168.110.0/255.255.255.0 ã«ã¼ã¿ã¼ 1 (Linux) eth0 : 19
ä½ã®è©±ãã¨ãã㨠RHEL7/CentOS7ã§ã¯æå°æ§æã§ã¤ã³ã¹ãã¼ã«ããã¨ãifconfigãrouteãnetstatãarpãªã©ã®ãããã¯ã¼ã¯é¢é£ã®ã³ãã³ãã使ãã¾ãããããã¯ã次ã®ã³ãã³ãã§ãnet-toolsãããã±ã¼ã¸ãå°å ¥ããã¨è§£æ±ºãã¾ãã # yum -y install net-tools ããããªããï¼ RHEL7/CentOS7ã§ã¯ãnet-toolsããdeprecatedï¼å»æ¢äºå®ï¼ãã¨ãã¦ãããä»å¾ã¯ãiproute2ããã±ã¼ã¸ã«å«ã¾ãããipããssããªã©ã®ã³ãã³ãã使ç¨ãããã¨ãæ¨å¥¨ããã¦ãã¾ãã ã»ã客ããã®RHEL7ãµã¼ãã¼ã®ã¡ã³ããé ¼ã¾ãããnet-toolsãå ¥ã£ã¦ãªãã£ãï¼ ã»ããã¼ãã¾ã ifconfigã¤ãã£ã¦ãã®ã¼ããã¨è¥ãååã«å·ããç®ã§è¦ãããï¼ ã»ãªã©ãªã© ã¨ãã£ãäºæ ã«åãã¦ãRHEL7/CentOS7ãå°å ¥ããéã«ã¯ãiproute2
CentOS7.2 64bitã®ã¤ã³ã¹ãã¼ã«å¾ã«ãVirtualBoxã®ãããã¯ã¼ã¯ã®ã¢ããã¿ã¼ãNATã¨ãã¹ããªã³ãªã¼ã¢ããã¿ã¼ã«å¤æ´ããå ´åã®ãããã¯ã¼ã¯ã®è¨å®ã«ã¤ãã¦ã以ä¸ã«ç¤ºãã¾ãã â»VirtualBoxã§ã®NATããã¹ããªã³ãªã¼ã¢ããã¿ã¼ã®è¨å®ã«ã¤ãã¦ã¯ãå½ãµã¤ãã®VirtualBox CentOS7 64bitã§NATããã¹ããªã³ãªã¼ã¢ããã¿ã¼ã使ç¨ã®ãã¼ã¸ãã覧ãã ããã â»CentOS7 64bitã®ã¤ã³ã¹ãã¼ã«æã«VirtualBoxã§NATããã¹ããªã³ãªã¼ã¢ããã¿ã¼ã使ç¨ããå ´åã®ãããã¯ã¼ã¯ã®è¨å®ã«ã¤ãã¦ã¯ãå½ãµã¤ãã®CentOS7 64bit ã¤ã³ã¹ãã¼ã«æã«VirtualBoxã§NATããã¹ããªã³ãªã¼ã¢ããã¿ã¼ã使ç¨ããå ´åã®ãããã¯ã¼ã¯ã®è¨å®ã®ãã¼ã¸ãã覧ãã ããã CentOS7 64bitã®ã¤ã³ã¹ãã¼ã«å¾ã«NATã¨ãã¹ããªã³ãªã¼ã¢ããã¿ã¼ã«å¤æ´ããå ´åã®ã
å æ¥Twitterã«æ¬¡ã®ãããªæ¸ãè¾¼ã¿ãããã¨ããæã£ãããåå¿ãè¯ãã£ãã®ã§ã詳細ã®è¨å®ãç´¹ä»ãã¾ãã UDP53çªãTCP443çªãUDP123çªã¨ãã¼ããããã³ã°ãããã¨TCP443çªã«10ç§ã ãsshdãç¾ãããã¨ããä¸äºç å ¨éã®è¨å®ããããçæ§ã«ããå§ãããããâ hnw (@hnw) 2017å¹´3æ26æ¥ ã¨ãã£ã¦ãç¹æ®ãªãã¨ãããããã§ã¯ãªããknockdã§ãã¼ããããã³ã°ã®è¨å®ãè¡ããiptablesã¨çµã¿åããã¦å®ç¾ãã¾ããã ãã¼ããããã³ã°ã¨ã¯ ãã¼ããããã³ã°ã¨ããã®ã¯ã決ãããããã¼ãã決ããããé çªã§å©ããã¨ã§ãã¡ã¤ã¢ã¼ã¦ã©ã¼ã«ã«ç©´ã空ãããããããªä»çµã¿ã®ãã¨ã§ãããã¼ããããã³ã°ã使ãã°ãTCPã®7000çªã8000çªã9000çªã®3ãã¼ãã«ãã±ãããéãã¤ããã¨22çªãã¼ã (SSH) ã¸ã®ã¢ã¯ã»ã¹ã許å¯ããããã¨ãã£ãè¨å®ãã§ãã¾ãã ãã¼ããããã³ã°ã®
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}