iptablesã®è¨å®å 容確èªã¨è¨å®ä¾
iptablesã®è¨å®å 容確èª
iptablesã®è¨å®ãè¡ãåã«ç¾ç¶ã®è¨å®å 容ã確èªããããã«ä¸è¨ã®ã³ãã³ããå®è¡ãã¾ãã
iptables --list
ãããå®è¡ããã¨ç¾ç¶ã®ãã£ã«ã¿ãªã³ã°ã«ã¼ã«ã確èªãããã¨ãã§ããä¸è¨ã®ããã«è¡¨ç¤ºãããã¨æãã¾ãã(ä¸è¨ã®è¡¨ç¤ºçµæã¯ubuntu12.04ã®å ´åã§ã)
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
target port opt source destination
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
target port opt source destination
Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
target port opt source destination
ä¸è¨ã®ãããªçµæã表示ãããå ´åã¯ãpolicy ACCEPTã¨æ¸ããã¦ãããã¨ãããå ¨ã¦ã®ãã±ããã«å¯¾ãã¦å ¥ã£ã¦ãããã¨ãåºã¦ãããã¨ã許å¯ããã¦ããç¶æ ã«ãªãã¾ãããªãããããã§ã«ãªã«ãããã«ã¼ã«ãè¨å®ããã¦ããå ´åã¯ãä¸è¨ã®ã³ãã³ããå®è¡ãããã¨ã§å ¨ã¦ã®ã«ã¼ã«ãåæåï¼å ¨åé¤ï¼ãããã¨ãã§ãã¾ãã
iptables --flush
iptablesã«ã«ã¼ã«ã追å ãã¦ãã®ã«ã¼ã«ã®å¹æã確èªããä¸ã§ã¯ãä¸åº¦åæåãã¦éæã«ã¼ã«ã追å ãã¦ããã¨æ¤è¨¼ããããã¨æãã¾ãããã ããå½ç¶ãªããã«ã¼ã«ãåæåããã¨å ¨ã¦ã®ãã±ãããåãå ¥ãããã¨ã«ãªãããã»ãã¥ãªãã£ãååèæ ®ããç°å¢ã§è¡ã£ã¦ä¸ãããã¡ãªã¿ã«ãiptablesã®è¨å®å 容ãããç´°ãã確èªãããå ´åã¯ä¸è¨ã®ã³ãã³ããå®è¡ããã¨è¯ãããããã¾ããã
iptables -nvL
ä¸è¨ã®ã³ãã³ãã¯ã--numeric
ã--verbose
ã--list
ãªãã·ã§ã³ãããããç¥è¨å½¢å¼ã§å®è¡ããã³ãã³ãã§ãããä¸è¨ãå®è¡çµæã«ãªãã¾ãã--list
ã ãã§è¡¨ç¤ºããçµæã«æ¯ã¹ã¦ãpkts
ãbytes
ãin
ãout
ã追å 表示ããããã¨ãåããã¾ãã
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target port opt in out source destination
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target port opt in out source destination
Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target port opt in out source destination
--numeric
ã¯ãæ°å¤ã§è¡¨ç¤ºãããã¨ãæ示ãããªãã·ã§ã³ã§ããã--verbose
ã¯ã¤ã³ã¿ãã§ã¼ã¹ãã«ã¼ã«ãªãã·ã§ã³ã表示ãããã¨ãæ示ãããªãã·ã§ã³ã§ãã詳細ã¯ä¸è¨URLã®iptablesãã¥ã¼ããªã¢ã«ãåç
§ãã¦ä¸ããã
iptablseãã¥ã¼ããªã¢ã«
iptablesã®è¨å®ä¾
以ä¸ã«iptablesã®ç°¡åãªè¨å®ä¾ãããã¤ãè¼ãã¾ãã
ä¾ï¼ï¼ç¹å®ã®ã¤ã³ã¿ãã§ã¼ã¹ã«å ¥ã£ã¦ãããã±ãããå ¨ã¦å»æ£ãã
eth0ã«å ¥ã£ã¦ãããã±ãããå ¨ã¦å»æ£ãã¾ãã
iptables --table filter --append INPUT --in-interface eth0 --jump DROP
ä¸è¨ã®ã³ãã³ãã¯åã³ãã³ãã®ç¥è¨ã使ããã¨ã§ä¸è¨ã®ããã«ã表ãã¾ãã
iptables -t filter -A INPUT -i eth0 -j DROP
以éã§ã¯å
¨ã¦ç¥è¨ã使ãã¾ããã¡ãªã¿ã«ã-t
ã使ãããã¼ãã«ãæå®ããªãã£ãå ´åã¯ãããã©ã«ãã§filterãã¼ãã«ãæå®ããããã¨ã«ãªãã¾ãããªã®ã§ãfilterãã¼ãã«ãæå®ããå ´åã¯-t filter
ã¯ç¡ãã¦ãåãã§ãã
ä¾ï¼ï¼ãã¹ããã·ã³ããã®éä¿¡ã«å¯¾ããç¸æã®å¿çéä¿¡ã許å¯ãã
eth0ã«å
¥ã£ã¦ãããã±ããã®ãã¡ããã¹ããã·ã³ã«å¯¾ããå¿çéä¿¡ã§ãããã±ããã¯ééã許å¯ãã¾ãã
--match state --state ESTABLISHED,RELATED
ã®é¨åã«ãã£ã¦å¿çéä¿¡ã§ãããã±ããã«éå®ãã¦ãã¾ãã
--match
ã¯ã¢ã¸ã¥ã¼ã«åãæå®ãã¦ã¢ã¸ã¥ã¼ã«ã使ãããã®ãªãã·ã§ã³ã§ãã--match state
ã«ãããstate
ã¢ã¸ã¥ã¼ã«ã®ä½¿ç¨ãæå®ãã¦ãã¾ããstate
ã¢ã¸ã¥ã¼ã«ã使ç¨ãã¦ESTABLISSEDãRELATED
ãæå®ãããã¨ã§ãå¿çãã±ããã«éå®ãã¦ãã¾ãã
iptables -t filter -A INPUT -i eth0 --match state --state ESTABLISHED,RELATED -j ACCEPT
â»iptablesã®æ³¨æç¹
iptablesã§ã¯ã«ã¼ã«ã«åªå é ä½ãåå¨ãã¾ããå ·ä½çã«ã¯ãã«ã¼ã«ã¯åºæ¬çã«ã«ã¼ã«ã追å ããé ã«é«ãåªå é ä½ãã¤ããããiptablesã§ã¯é«ãåªå é ä½ã®ã«ã¼ã«ããé çªã«å¦çããã¦ããã¾ããä¾ãã°ãä¸è¨ã®ã³ãã³ããé çªã«å®è¡ãã¦ã¿ã¾ãã
itables -t filhljsA INPUT -i eth0 -j DROP
iptables -t filter -A INPUT -i eth0 --match state --state ESTABLISHED,RELATED -j ACCEPT
å®è¡å¾ãiptables --list
ã«ãã£ã¦ã«ã¼ã«å
容ã確èªããã¨ãä¸è¨ã®ããã«ãªãã¾ãã
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
target port opt source destination
DROP all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
target port opt source destination
Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
target port opt source destination
iptablesã§ã¯åãã§ã¤ã³ã®ä¸çªä¸ã®ã«ã¼ã«ããé çªã«é©ç¨ãã¦ããã¾ããããã¦ä¸è¨ã®å ´åã¯ãINPUTãã§ã¤ã³ã®ä¸çªä¸ã®ã«ã¼ã«ãDROPã§ãããã¤ãã®å¯¾è±¡ãå
¨ãã±ããã§ããããã次ã®ACCEPTãé©ç¨ããããã¨ã¯ããã¾ãããããªãã¡ãiptablesã§ã¯ãã«ã¼ã«ã®é çªãéè¦ã§ããããã±ããã®å¯¾è±¡ç¯å²ãå°ããã«ã¼ã«ããé çªã«é©ç¨ãããããã«ã¼ã«ãè¨è¿°ãããã¨ãéè¦ã«ãªãã¾ãããªããã«ã¼ã«ã®é çªã¯è¿½å ããé çªã¨åãã«ãªãã¾ããã--replace
ã--insert
ãªã©ã®ã«ã¼ã«æä½ã³ãã³ãã使ããã¨ã§ã«ã¼ã«ã®é çªãæä½ã§ãã¾ããï¼iptablesã®æ¦è¦ã¡ã¢ãåç
§ï¼
ä¾ï¼ï¼ç¹å®ã®éä¿¡å IPã¢ãã¬ã¹ã®ãã±ããã®å®å IPã¢ãã¬ã¹ã¨å®å ãã¼ãçªå·ãå¤æãã
éä¿¡å IPã¢ãã¬ã¹ã192.168.101.0/24ã§ãããã¤å®å ãã¼ãçªå·ã80çªã§ãããã±ããã®å®å IPã¢ãã¬ã¹ã192.168.101.101ãå®å ãã¼ãçªå·ã3128çªã«å¤æãã
iptables -t nat -A PREROUTING -s 192.168.101.0/24 -p tcp --dport 80 -j DNAT --to 192.168.101.101:3128
ä¾ï¼ï¼ç¹å®ã®ã¤ã³ã¿ãã§ã¼ã¹ã«å ¥ã£ã¦ãããã±ããã®å®å ãã¼ãçªå·ãå¤æãã
ã¤ã³ã¿ãã§ã¼ã¹eth0ã«å ¥ã£ã¦ãããã±ããã®å ãå®å ãã¼ãçªå·ã80çªã§ãããã±ããã®å®å ãã¼ãçªå·ã3128çªã«å¤æãã
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 3128
iptablesã®è¨å®ä¿åæ¹æ³
ããã¾ã§ã«è¨å®ããã«ã¼ã«ã¯iptablesãåä½ãããã¹ããã·ã³ãåèµ·åããã¨æ¶ãã¦ç¡å¹ã«ãªã£ã¦ãã¾ãã¾ããããã§ãåèµ·åå¾ãè¨å®ããã«ã¼ã«ãç¶ç¶ãã¦æå¹ã«ããããã«iptables-save
ãiptables-restore
ã³ãã³ãã使ãæ¹æ³ãããã¾ãã
è¨å®ããã«ã¼ã«ãä»»æã®ãã¡ã¤ã«ã«æ¸ãåºãã³ãã³ãã¨ãã¦iptables-save
ããããä¸è¨ã®ããã«ãã¡ã¤ã«åãæå®ãã¦ä½¿ãã¾ãã
iptables-save > ãã¡ã¤ã«å
iptables-save
ã«ãã£ã¦è¨å®ãæ¸ãåºãã¦ããããã¹ããã·ã³ãåèµ·åå¾ãæ¸ãåºãã¦ããããã¡ã¤ã«ãä¸è¨ã®ã³ãã³ãã«ããåèªã¿è¾¼ã¿ããã¨ãæ¸ãåºãããã«ã¼ã«ãæ¹ãã¦è¨å®ããã¾ãã
iptables-restore < ãã¡ã¤ã«å
2013/10/7 追è¨
è¯ã使ãiptablesã®éç¨ç®¡çæ¹æ³ï¼ã¤ãã¡ã¢ã«iptablesã®éç¨ç®¡çæ¹æ³ã¨ãã¦ãiptables-saveãiptables-restoreã使ã£ãæ¹æ³ã¨ã·ã§ã«ã¹ã¯ãªããã使ã£ãæ¹æ³ã®ï¼ã¤ãã¡ã¢ãã¾ãããiptablesã®éç¨ç®¡çã«ã¤ãã¦ã¯ãã¡ãã®æ¹ãæ å ±ãå¤ãã¨æãã®ã§ãè¯ããã°ãåç §ä¸ããã
é¢é£è¨äº
- å ¬éæ¥ï¼2013/10/06 æ´æ°æ¥ï¼2013/10/06
è¯ã使ãiptablesã®éç¨ç®¡çæ¹æ³ï¼ã¤ãã¡ã¢
iptablesã®ã«ã¼ã«ãç·¨éããã«ã¼ã«ãPCèµ·åã¨åæã«èªåè¨å®ããã¦éç¨ãããããã®æ¹æ³ã¨ãã¦ãiptables-saveãiptables-restoreã使ã£ãæ¹æ³ã¨ã·ã§ã«ã¹ã¯ãªããã使ã£ãæ¹æ³ã®ï¼ã¤ãã¡ã¢ãã¾ãã
- å ¬éæ¥ï¼2013/03/18 æ´æ°æ¥ï¼2013/03/18
iptablesã®æ¦è¦ã¡ã¢
iptablesã¯å¤ãã®Linuxã«æ¨æºã§ã¤ã³ã¹ãã¼ã«ããã¦ãããã¡ã¤ã¢ã¦ã©ã¼ã«ã½ããã¦ã§ã¢ã§ãããç¹å®ã®éä¿¡ãéé/é®æãããããã±ããã®éä¿¡å IPã¢ãã¬ã¹ãå®å ã¢ãã¬ã¹ãå¥ã®ã¢ãã¬ã¹ã«å¤æãããããæ©è½ãæä¾ãã¦ãã¾ããiptablesã¯Linuxã使ã£ã¦ããã¨åºä¼ãå ´é¢ãå¤ãã®ã§ããã®æ¦è¦ã«ã¤ãã¦ã¡ã¢ãã¾ãã
éçºã¢ããª
æ¯æ¥ã®å°ããªåºæ¥äºããªãã§ãè¨é²ãã¦ããã°ã¨ãã¦æ®ãããã®ã©ã¤ããã°ã¢ããªã§ãã