éçºç¨ãµã¼ãã®è¨å®ããããããã£ã¦ãã¦ãåãCentOS6ãªããããããã®VPSã¨ã®éããçºè¦ããããã¾ããã»ãã¥ãªãã£ã®ããã«sshã®ãã¼ãçªå·ãå¤æ´ãã¦sshã§ã¤ãªããªããªã£ãããapacheã®ã¤ã³ã¹ãã¼ã«ããã¦åãè¨å®ãããã¯ããªã®ã«ãã©ã¦ã¶ããã¢ã¯ã»ã¹ã§ããªãã£ãããçµé¨ä¸ãªãã¨ãªãçç±ã¯æ³åã¤ãã®ã ãã©â¦ã
sshã®ãã¼ãçªå·å¤æ´ãã¦ã¤ãªãããªããªã£ã¦ã¨è¨ã£ã¦ããéãããã¼ããåé¡ã§ãããã¼ããéãã¦ããªãã®ã§å¤é¨ããã¢ã¯ã»ã¹åºæ¥ã¾ããããããã®VPSã¯ãªãã¢ã¯ã»ã¹ã§ãããã¨ããã°ãå¤åãã®é¨åã§ã®ã客ããããã®åãåãããæ¸ãããã«å
¨ãã¼ãéæ¾ãã¦ãµã¼ãã渡ãã¦ããã®ã ã¨æãã¾ããã ãããããã¯ã¡ããã¨è¨å®ããªãã¨ã»ãã¥ãªãã£ãçããªã£ããããã®ã§æ³¨æã§ãã
ãã¦ãéçºç¨ãµã¼ãã§ã¯å¤é¨ããã¢ã¯ã»ã¹ã§ããããã«ãã»ãã¥ãªãã£ã®ããã«å¿
è¦ãªãã¼ãã ãéæ¾ãããã¨æãã¾ããå¤åå
ããéæ¾ããã¦ãããã¼ãã¯ããã©ã«ãã®sshã®ãã¼ãã®22çªã ãã¨æãã¾ããããããsshã®ãã¼ããå¤æ´ãããã®çªå·ã¨ãapacheã¨ãããCentOSã§ã¯httpdç¨ã®80çªãã¼ããéæ¾ãããã¨æãã¾ãããã¨ã¯å¿
è¦ã«å¿ãã¦ãã¼ããéãã¦ãã ããããµã¼ã管çã§ä½ããã£ãã¨ãã«ã¡ã¼ã«ãå±ãããã«ããããã«smtpãã¼ãã®25çªããhttpsã¨ããsslã§ã®ãã©ã¦ã¶ã¢ã¯ã»ã¹ã®443çªããã¨ã¯ãã¼ã¿ãã¼ã¹ãµã¼ãã¨ãã¦å¤é¨ããã¤ãªããã3306çªãã¼ã辺ããåè£ã«ãªãããããã¾ããã
ãã¼ãéæ¾ã¯ã³ãã³ãã§ããã®ãæ®éãããã®ã§ãããæåã«CentOSã触ã£ãæã«ããããã¾ãã§ããªãã£ããã¨ããã£ã¦ä»¥æ¥ãåã¯ãã¡ã¤ã«ãç´æ¥æ¸ãæãã¦ãã¾ãã対象ãã¡ã¤ã«ã¯/etc/sysconfig/iptablesã§ãã
vi /etc/sysconfig/iptables
ãã¡ã¤ã«ç·¨éã³ãã³ãã§ãã
-A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
ä¸è¨é¨åã22çªãã¼ããéãã¦ããè¨è¿°ã§ããã¡ã¤ã«ã®ä¸éãããã«ãããã¨æãã¾ããããã¨åãè¨è¿°ã§22ã®æ°åé¨åãéããããã¼ãçªå·ã«ãã¦æ¬¡ã®è¡ã«è¿½å ãã¦ãã ããã
-A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
apacheã¨ãããhttpdãªãä¸è¨ã®ããã«ãªãã¾ãã
ãã¡ã¤ã«ãå¤æ´ãããiptablesã®åèµ·åãå¿
è¦ã«ãªãã¾ãã
/etc/init.d/iptables restart
ã¨ã©ã¼ãã§ãªããã°æåã§ããsshããã©ã¦ã¶ããã®ä»ã®ã¯ã©ã¤ã¢ã³ãããã¢ã¯ã»ã¹ãã¦ç¢ºèªãã¦ãã ãããä»ã«ãå¤é¨ãããã¼ãã空ãã¦ããã確èªãã¦ãããwebãµã¼ãã¹ãªãããåå¨ãã¾ãã対象IPããã¹ãåã調ã¹ãããã¼ããå
¥åãã¦ä½¿ãã¾ããä¸è¨ã®ã¢ãã¬ã¹ãããã«ãªãã¾ãããæ»æããããã«èª¿ã¹ãã¨ãæªç¨ã¯ããã¾ãããã
http://www.cman.jp/network/support/port.html