|
Ubuntu Linux系统下设置shorewall防火墙
( 2008/4/29 10:51 )
网卡,一块接外网(eth0),一块接内网(eth1)。采用shorewall作为防火墙。 配置网卡: sudo vi /etc/network/interfaces Ubuntu下设置shorewall防火墙 服务器采用Ubuntu作为操作系统,两块网卡,一块接外网(eth0),一块接内网(eth1)。采用shorewall作为防火墙。 配置网卡: sudo vi /etc/network/interfaces # The loopback network interface # This is a list of hotpluggable network interfaces. # The primary network interface auto eth1
1、安装shorewall sudo apt-get install shorewall
sudo cp /usr/share/shorewall/modules /etc/shorewall sudo cp /usr/share/doc/shorewall/default-config/policy /etc/shorewall/ sudo cp /usr/share/doc/shorewall/default-config/nat /etc/shorewall/ sudo cp /usr/share/doc/shorewall/default-config/zones /etc/shorewall/ sudo cp /usr/share/doc/shorewall/default-config/maclist /etc/shorewall/ sudo cp /usr/share/doc/shorewall/default-config/blacklist /etc/shorewall/ sudo cp /usr/share/doc/shorewall/default-config/interfaces /etc/shorewall/interfaces sudo cp /usr/share/doc/shorewall/default-config/rules /etc/shorewall/rules sudo cp /usr/share/doc/shorewall/default-config/hosts /etc/shorewall/hosts sudo cp /usr/share/doc/shorewall/default-config/masq /etc/shorewall/masq
sudo vi /etc/shorewall/interfaces
loc eth1 detect
sudo vi /etc/shorewall/zones
loc Local Local Networks
sudo vi /etc/shorewall/policy
net all DROP info all all REJECT info
AllowSSH net fw AllowDNS net fw AllowWeb net fw AllowSMB net fw AllowNNTP net fw AllowNTP net fw AllowRdate net fw AllowSMTP net fw DropPing net fw
AllowWeb fw net AllowDNS fw net AllowSMTP fw net AllowSMB fw net AllowSMTP fw net AllowNNTP fw net AllowNTP fw net AllowRdate fw net AllowSSH fw net
ACCEPT net fw tcp 9980
|
热议文章·关注:中国齐上3个3G标准的背后 (6-17) 评:既然要用就应该用我们自己的标准TD-SCDMA,这样就不用因为使用国外的标准而付... ·周寰:李部长要求TD只能成功不能失败 (6-17) ·大唐挂牌出售天碁逻辑 "大TD"产业下另起炉灶 (6-17) ·宋俊德:建议运营商机房外包以解决C网分拆 (6-17) ·中移动将报废车辆改成“新型应急通信车” (6-17) ·国家意志下的TD困局 (6-17) ·电信集团57.4万IPTV机顶盒统一招标 (6-16) ·ASON在中国铁通骨干传输网中的应用 (6-18) ·全球ASON最新进展 (6-18) ·ASON网络技术现状及组网应用 (6-18) ·GSM/TD-SCDMA双模终端芯片设计方案浅析 (6-18) ·无线通信系统中的闭环MIMO技术 (6-18) ·TD-SCDMA增强技术及其演进 (6-18) ·为什么不能与苹果合作推出TD-iPhone (6-18) ·“山寨机”代表着国产手机未来发展方向 (6-17) ·重组后三大运营商会受到资本市场的尊重 (6-5) ·电信和联通必须快速转移小灵通用户 (5-30) |
||||||||||||||||||
|