Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article?
çµç·¯ ãããVPS ãæ°ãã©ã³ã«ãªã£ãããæ§ãã©ã³ãã移è¡ããã ãã£ããã ããã¾ã ãã¾ã触ã£ã¦ãªã CentOS 7 ã«ããã ãã£ããã ããProvisioning Tool ã¨ã㦠Itamae ã使ã£ã¦ã¿ãã user ã¯ç°¡åã«ã§ããï¼ãã¦æ¬¡ã¯ iptables ãCentOS 7 ã£ã¦ firewalld ã使ãã®ã Itamae ã® iptables plugin ãªããã ã firewalld ã®æä½ã ãã³ãã³ãç´æ¸ãã¨ããæãããã execute 'firewalld-cmd --permanent --add-service my-ssh' execute 'firewalld-cmd --permanent --remove-service dhcpv6-client' ãã£ããã ããä½ãã 使ãæ¹ README ã«ãããã¾ãã service 'firewalld
æè¿ã®CentOS7ãFedoraãªã©ã¯ããã©ã«ãã§firewalldãæå¹ã«ãªã£ã¦ãããåºæ¬çã«ãã¼ãã¯å¡ãã£ã¦ããã ãµã¼ãã¹ãæä¾ããã«ã¯ãé©åã«è¨å®ããããµã¼ãã¢ããªã±ã¼ã·ã§ã³ã¨é©åãªãã¼ãéæ¾ãå¿ è¦ã¨ãªããä¾ãã°webãµã¼ãã®å ´åapacheãªã©ãè¨å®ãèµ·åããã®å¾firewalldã®è¨å®ãè¡ã80çªã®ãã¼ããéæ¾ããå¿ è¦ãããã ãã®ãã¼ã¸ã§ã¯CentOSã®ãã¼ã解æ¾ã«ã¤ãã¦ãä¼ããããã ãããããã¼ãã¨ã¯ï¼ 念ã®ãããç´¹ä»ãã¦ãããã TCPãUDPã§éä¿¡ãè¡ãã¨ãã¯ãã³ã³ãã¥ã¼ã¿åä½ã§ã¯ãªããããã»ã¹ãã¹ã¬ããåä½ãã§éä¿¡ãè¡ãããããã®æã®éä¿¡ã®çªå£ããã¼ãã§ããã ãããã¯ã¼ã¯éã§ããåããããæ å ±ã®åºç¤ã¯ããããã³ã«ãã¨ãã¢ãã¬ã¹ãã¨ããã¼ãçªå·ããã®ä¸ã¤ã主軸ã«ãªã£ã¦ããã æ¥æ¬èªã«ãã¨ãããã¨ãã©ã®ãããªæ¹æ³ã(ãããã³ã«)ã§ãã©ãã(ã¢ãã¬ã¹)ã®ãä½å·å®¤ã(ã
ææ°çã¯ä»¥ä¸ã¨ãªãã¾ãã https://dev.classmethod.jp/etc/ec2-tcp-port-check-command-2018/ ããã«ã¡ã¯ã³ã«ã³ã¼ã©å¥½ãã®æ¢¶ã§ãã EC2ã§ã¯è²ã ãªOSãæ§ç¯ã§ãã¾ããããæ§ç¯å¾ã®é信確èªã¯ã©ã®ããã«å®æ½ãã¦ã¾ããï¼ åOSã§ä»ã®ã¤ã³ã¹ã¿ã³ã¹ã¸TCPé信確èªã®ããã«ããã¼ã«ãã¤ã³ã¹ãã¼ã«ããããICMPãªã©ã®å¥ãªãããã³ã«ã§ç¢ºèªããããã«Security Groupãä¸æ解æ¾ãã¦ãã¾ãããï¼ æ§ç¯ç´å¾ã®ç¶æ ã§ãç°¡åã«TCPãã¼ãçé確èªå¯è½ãªã³ãã³ãããç´¹ä»ãã¾ãã Amazon Linux,Ubuntu,Windows2012R2,CentOSã«ã¤ãã¦èªåãå¿ããããã®ã§ã¾ã¨ãã¦ã¿ã¾ããã ã©ãªããã®ãå½¹ã«ç«ã¦ãã°å¹¸ãã§ãã Amazon Linux åä½ç¢ºèªAMI:amzn-ami-hvm-2014.09.2.x86_64-eb
# éãã¦ãããã¼ãã¨ä½¿ç¨ãã¦ããããã»ã¹ï¼IPv4ï¼ $ sudo netstat -ltup4 sudo netstat -ltup4 Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 0.0.0.0:mysql 0.0.0.0:* LISTEN 2015/mysqld tcp 0 0 localhost:smtp 0.0.0.0:* LISTEN 2282/master tcp 0 0 0.0.0.0:10022 0.0.0.0:* LISTEN 1274/sshd udp 0 0 localhost:323 0.0.0.0:* 658/chronyd # ä¸è¨ãæ°å¤ã§ sudo nets
# æå¹ãªè¨å®ãç¢ºèª >>> firewall-cmd --list-services --zone=public --permanent dhcpv6-client # è¨å®è¿½å (sshã¨mysqlã追å ) firewall-cmd --add-service=ssh --zone=public --permanent firewall-cmd --add-service=mysql --zone=public --permanent # è¨å®åé¤(sshãåé¤) firewall-cmd --remove-service=ssh --zone=public --permanent # è¨å®ä¸è¦§ã表示 ls -lta /usr/lib/firewalld/services/ # åè¨å®æ¯ã®å å®¹ç¢ºèª cat /usr/lib/firewalld/services/ssh.xml # è¨å®ã
CentOS 7 ãã¡ã¤ã¢ã¦ã©ã¼ã«Â¶ ç®æ¬¡CentOS 7 ãã¡ã¤ã¢ã¦ã©ã¼ã«æä½ã¡ã¢ãã¼ãã®è¿½å ãã¼ã3000ãéããããã¼ã80ï¼httpï¼ãéããã æä½ã¡ã¢Â¶ ãã¼ãã®è¿½å ¶ ãã¼ã3000ãéãã㶠ä¸æçã«éã # firewall-cmd --add-port=3000/tcp æ°¸ç¶çã«éã # firewall-cmd --permanent --add-port=3000/tcp ä¸æçã«éãã³ãã³ããå®è¡ããã«ãæ°¸ç¶çã«éãã³ãã³ãã ããå®è¡ããå ´åããã¡ã¤ã¢ã¦ã©ã¼ã«ã«è¨å®ãåèªã¿è¾¼ã¿ããã¾ãã # firewall-cmd --reload ãã¼ã80ï¼httpï¼ãéãã㶠ä¸æçã«éã # firewall-cmd --add-service=http æ°¸ç¶çã«éã # firewall-cmd --add-service=http --permanent ãã¼ã
firewall-cmd --add-port=22/tcp --zone=public --permanent ãããªæãã§éæ¾ã§ãã¾ãã ãã®ä»ã¯ä»¥ä¸ã®ãããªæãã # 許å¯ããã¦ãããµã¼ãã¹ããã¼ãã®ä¸è¦§ã表示 firewall-cmd --list-all --zone=public firewall-cmd --list-services --zone=public firewall-cmd --list-ports --zone=public # 許å¯ãããµã¼ãã¹ã®è¿½å ã¨åé¤ firewall-cmd --add-service=ssh --zone=public --permanent firewall-cmd --remove-service=ssh --zone=public --permanent # 許å¯ãããã¼ãã®è¿½å ã¨åé¤ firewall-cmd --add-p
å½ãµã¤ãã§CentOS7.1 64bitã¸ã®ã¤ã³ã¹ãã¼ã«æ¹æ³ãç´¹ä»ãã¦ããããã±ã¼ã¸ã«é¢ããfirewalldã®è¨å®ãã以ä¸ã«ç¤ºãã¾ãã firewalldã§ã¯ãã¢ã¯ã»ã¹å¶å¾¡ã®è¨å®ãã¾ã¼ã³å¥ã«è¡ãããã«ãªã£ã¦ããããããã¯ã¼ã¯ã¤ã³ã¿ã¼ãã§ã¤ã¹ã«ã¾ã¼ã³ãå²ãå½ã¦ããã¨ã§ãã¢ã¯ã»ã¹å¶å¾¡ã®ä½¿ãåããã§ããããã«ãªã£ã¦ãã¾ãã ããã§ã¯ãããã©ã«ãã®ã¾ã¼ã³ã¨ãªãpublicã¾ã¼ã³ã«å¯¾ãã¦ãã¢ã¯ã»ã¹å¶å¾¡ãè¡ã£ã¦ããã¾ãã 以ä¸ã®åã³ãã³ãã§ãããã³ãããã#ãã§éå§ãã¦ãããã®ã¯rootã¦ã¼ã¶ã¼ã§ã®å®è¡ãã$ãã§éå§ãã¦ãããã®ã¯ä¸è¬ã¦ã¼ã¶ã¼ã§ã®å®è¡ã¨ãªãã¾ãã firewalldã®ã¤ã³ã¹ãã¼ã« firewalldã®ã¤ã³ã¹ãã¼ã« firewalldã¯CentOS7.1 64bitã®ã¤ã³ã¹ãã¼ã«ããCentOS-7-x86_64-Minimal-1503-01.isoãããè¡ã£ãå ´åã¯ãããã©ã«ãã§ã¤
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}