Ukuxhumana okuphephile kwezindawo zenethiwekhi nokushintshaniswa kwemininingwane phakathi kwazo kuhlobene ngqo namachweba avulekile. Ukuxhuma kanye nokudluliselwa kwethrafikhi kwenziwa ngechweba elithile, futhi uma livaliwe ohlelweni, ngeke bakwazi ukwenza inqubo enjalo. Ngenxa yalokhu, abanye abasebenzisi banesifiso sokudlulisa inombolo eyodwa noma eziningi zokusetha ukusebenzisana kwedivayisi. Namuhla sizokhombisa ukuthi umsebenzi wenziwa kanjani ezinhlelweni ezisebenzayo ngokusetshenziselwa i-Linux kernel.
Sivula amachweba eLinux
Yize ukusatshalaliswa okuningi kunethuluzi lokuphathwa kwenethiwekhi elakhelwe ngaphakathi ngokuzenzakalelayo, izixazululo ezinjalo ngokuvamile azikuvumeli ukuthi ulungiselele ngokuphelele ukuvulwa kwamachweba. Imiyalo ekule ndatshana izosuselwa ohlelweni olwengeziwe olubizwa ngokuthi ama-Iptables, isisombululo sokuhlela izilungiselelo zomlilo usebenzisa amalungelo aphezulu. Kuyo yonke i-OS eyakhelwa kwi-Linux, isebenza ngokufanayo, ngaphandle kokuthi umyalo wokufaka uhlukile, kepha sizokhuluma ngalokhu ngezansi.
Uma ufuna ukwazi ukuthi imaphi amachaphaza asevele evulekile kukhompyutha yakho, ungasebenzisa insiza eyakhelwe ngaphakathi noma eyengeziwe yokusiza ikhonsoli. Uzothola imiyalo eningiliziwe yokuthola ulwazi oludingekayo kwesinye isihloko sethu ngokuchofoza kusixhumanisi esilandelayo, futhi sizoqala ukuhlaziywa kwesinyathelo ngesinyathelo kwamachweba okuvula.
Funda Okuningi: Ukubuka Amachweba Okuvula ku-Ubuntu
Isinyathelo 1: Faka ama-iptables futhi ubuke imithetho
Ukusetshenziswa kwe-Iptables akufakiwe ekuqaleni ohlelweni olusebenzayo, yingakho udinga ukuyifaka ngokwakho kusuka endaweni yokugcina esemthethweni, bese kuphela usebenza nemithetho uyishintshe ngazo zonke izindlela. Ukufaka akuthathi isikhathi esiningi futhi kwenziwa nge-console ejwayelekile.
- Vula imenyu bese uqala "Isiginali". Ungakwenza futhi lokhu usebenzisa i-hotkey ejwayelekile. I-Ctrl + Alt + T.
- Ukusatshalaliswa okususelwa ku-Debian noma Ubuntu, bhala
faka amathebula wothando
ukusebenzisa ukufakwa, naku-Fedora okusekwe ku-Fedora -sudo yum ukufaka iptables
. Ngemuva kokungena, cindezela ukhiye Ngena. - Yenza kusebenze amalungelo aphezulu ngokubhala iphasiwedi ye-akhawunti yakho. Uyacelwa ukuthi uqaphele ukuthi izinhlamvu aziboniswa ngesikhathi sokufaka, lokhu kwenziwa ukuqinisekisa ukuphepha.
- Lindela ukufakwa ukuqeda futhi ungaqinisekisa umsebenzi wethuluzi ngokubheka uhlu olujwayelekile lwemithetho olusebenzisayo
izihlokwana ze-sudo -L
.
Njengoba ukwazi ukubona, ukusatshalaliswa manje kunomyaloiptables
unesibopho sokuphatha ukusetshenziswa kwegama elifanayo. Siyaphinda futhi, siyakhumbula ukuthi leli thuluzi lisebenza njengempande, ngakho-ke umugqa kufanele uqukethe isiqalosudo
, futhi yilapho kuphela amanye amanani nama-agumenti asele.
Isinyathelo 2: Vumela Ukuxhumana
Awekho amachweba azosebenza ngokujwayelekile uma ukusetshenziswa kwenqabela ukushintshwa kwemininingwane ezingeni lemithetho yayo yomlilo. Ngaphezu kwalokho, ukuntuleka kwemithetho edingekayo ngokuzayo kungadala amaphutha ahlukahlukene ngesikhathi sokuthumela, ngakho-ke sincoma ngokuqinile ukuthi ulandele lezi zinyathelo:
- Qiniseka ukuthi ayikho imithetho kwifayela yokucushwa. Kungcono ukubhala ngokushesha umyalo wokuwasusa, kepha kubukeka kanjena:
izihlokwana ze-sudo -F
. - Manje singeza umthetho wedatha yokufaka kukhompyutha yendawo ngokufaka ulayini
ama-iphuzu we-sudo -I-INPUT -i lo -j ACCEPT
. - Mayelana nomyalo ofanayo -
izimfanelo zothando -I-OUTPUT -o lo -j ACCEPT
- unesibopho somthetho omusha wokuthumela imininingwane. - Kuhlala kuphela ukuqinisekisa ukusebenzisana okujwayelekile kwale mithetho engenhla ukuze iseva ithumele amaphakethe emuva. Ukuze wenze lokhu, udinga ukwenqabela ukuxhumana okusha, kanye nokudala ukuze ukuvumele. Lokhu kwenziwa
ama-iphuzu we-sudo -I-INPUT -m state - state ESTABLISHED, RELATED -j ACCEPT
.
Ngenxa yamapharamitha angenhla, uqinisekisile ukuthumela nokwamukela idatha efanele, okuzokuvumela ukuthi uxhumane kalula neseva noma enye ikhompyutha. Kusalokhu kuvulwa amachweba lapho lokhu kusebenzisana kuzokwenziwa.
Isinyathelo 3: Ukuvula amachweba adingekayo
Usujwayelene nomgomo lapho imithetho engezwe yenezelwa kuwo ukucushwa kwe-Iptables. Kunokuphikisana okuningi ukuvula amachweba athile. Ake sibheke le nqubo sisebenzisa isibonelo samachweba athandwayo abhalwe u-22 no-80.
- Hola ikhonsoli bese ufaka imiyalo emibili elandelayo elandelayo:
ama-iphuzu we-sudo -A INPUT -p tcp --dport 22 -j ACCEPT
.
ama-iphuzu we-sudo -A INPUT -p tcp --dport 80 -j ACCEPT - Manje hlola uhlu lwemithetho ukuze uqiniseke ukuthi amachweba athunyelwe ngempumelelo. Kusetshenziselwe lomyalo osuvele usuwazi
izihlokwana ze-sudo -L
. - Ungayinika ukubukeka okufundekayo futhi ubonise yonke imininingwane usebenzisa i-agumenti eyengeziwe, khona-ke umugqa uzofana nalokhu:
ama-sudo iptables -nvL
. - Guqula inqubomgomo ibe yjwayelekile
ama-iphuzu we-sudo -P INPUT DROP
futhi ungaqala ngokuphepha umsebenzi phakathi kwezindawo.
Esimweni lapho umphathi wekhompyutha esengenile imithetho yakhe ithuluzi, wahlela ukulahla amaphakethe lapho esondela ephuzwini, ngokwesibonelo, ngokusebenzisaama-iphuzu we-sudo -AINPUT -j DROP
udinga ukusebenzisa omunye umyalo we-sudo iptables:-I-INPUT -p tcp --dport 1924 -j ACCEPT
kuphi 1924 - Inombolo echwebeni. Ingeza imbobo edingekayo ekuqaleni kweciko, bese amaphakethe engalahli.
Ngemuva kwalokho ungabhala umugqa ofanayoizihlokwana ze-sudo -L
futhi uqiniseke ukuthi yonke into ihlelwe kahle.
Manje usuyazi ukuthi amachweba athunyelwa kanjani kuzinhlelo zokusebenza ze-Linux zisebenzisa ukusetshenziswa okwengeziwe kweptables njengesibonelo. Sikucebisa ukuthi ulandele imigqa evela ku-console lapho ufaka imiyalo, lokhu kuzosiza ekutholeni noma imaphi amaphutha ngesikhathi futhi uwaqede ngokushesha.