ama-iptables wama-newbies, anelukuluku, anentshisekelo (Ingxenye yesibili)

Nini DesdeLinux Nganginezinyanga ezimbalwa kuphela ubudala futhi ngabhala okokufundisa okulula kakhulu ukukuqonda mayelana nama-iptables: ama-iptable wama-newbies, anelukuluku, anentshisekelo (ingxenye yokuqala) . Ngisebenzisa izingathekiso ezifana nokuqhathanisa ikhompyutha yethu nendlu yethu, i-firewall yethu nomnyango wendlu, kanye nezinye izibonelo, ngichaze ngendlela emnandi, ngaphandle kobuchwepheshe obuningi noma imiqondo eyinkimbinkimbi, ukuthi yini i-firewall, yini iptables futhi ukuthi ungaqala kanjani ukuyisebenzisa futhi ulungiselele. Lokhu ukuqhubeka, ingxenye yesibili yezifundo zangaphambilini ze-iptables 🙂

Kwenzeka ukuthi ezinsukwini ezimbalwa ezedlule ngisebenzisa i-Linksys AP (Access Point) ngafaka iWifi endlini yentombi yami, yize indawo leyo ingeyena onolwazi kakhulu kwezobuchwepheshe, okungukuthi, akukhona ukuthi kunezingozi eziningi zokuqhekeka , kuhlale kungumqondo omuhle ukuthi ube nokuphepha okuhle kakhulu ku-Wifi nakumakhompyutha.

Ngeke ngiphawule ngokuvikeleka kwe-Wifi lapha, ngoba akuyona inhloso yokuthunyelwe, ngizogxila kulungiselelo lwe-iptables engilusebenzisa njengamanje kwi-laptop yami.

Le miyalo elandelayo yenziwa esigungwini, idinga ukwenziwa ngamalungelo okuphatha, ngizolungiselela i-Sudo kumyalo ngamunye, ungenza okufanayo noma uvikele ukusebenzisa iSudo ngokwenza imiyalo ngqo njengezimpande

Kokuthunyelwe kwangaphambilini bengichazile ukuthi kuyadingeka ku-firewall ukuqala ukuphika yonke ithrafikhi engenayo, yalokhu:

sudo iptables -P INPUT DROP

Ngemuva kwalokho kufanele sivumele ikhompyutha yethu ukuthi ibe nemvume yokufaka idatha:

sudo iptables -A INPUT -i lo -j ACCEPT

Kanye nokwamukela amaphakethe ezicelo aqhamuka kwikhompyutha yethu:

sudo iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

Ukuqonda kangcono le migqa, ngincoma ukuthi ufunde isigamu sokuqala sendatshana eyedlule: ama-iptable wama-newbies, anelukuluku, anentshisekelo (ingxenye yokuqala)

Kuze kube manje ikhompyutha yethu ingakwazi ukuzulazula kwi-inthanethi ngaphandle kwezinkinga, kepha akekho noyedwa ovela kunoma iyiphi enye indawo (i-LAN, i-inthanethi, i-Wifi, njll.) Ezokwazi ukufinyelela kwikhompyutha yethu nganoma iyiphi indlela. Sizoqala ukumisa ama-iptable ngokwezidingo zethu.

Usebenzisa i-ulogd ukukhipha izingodo ze-iptables ziye kwelinye ifayela:

Ngokuzenzakalelayo izingodo ze-iptables zingena ku-kernel log, ku-log log, noma into enjalo ... ku-Arch ngokuzenzakalela, okwamanje angikhumbuli nokuthi bayaphi, yingakho ngisebenzisa Ulogd ukuze izingodo ze-iptables zikwelinye ifayela.

sudo iptables -A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j ULOG

Ukunikeza ukufinyelela kuseva yami yangasese:

Angisebenzisi i-VirtualBox noma yini efana nokwenza i-virtualize, ngine-server yami yangasese eyenziwe nge-virtual I-Qemu + KVM okumele ikwazi ukuxhuma kwi-laptop yami kanjalo, nemithetho ye-iptables engisanda kuyibeka ngenhla ngeke ikwazi, yingakho kufanele nginike imvume ku-IP yeseva yami ebonakalayo ukuze ikwazi ukufinyelela kwi-laptop yami :

sudo iptables -A INPUT -i virbr0 -p tcp -s 192.168.122.88 -j ACCEPT

Sizocacisa lo mugqa, kubalulekile ukuthi uqonde ukuthi ipharamitha ngayinye isho ukuthini, ngoba izophindwa kaningi kusuka manje kuqhubeke:

-OKUFAKELWA : Ngithi ngizomemezela umthetho wethrafikhi engenayo

- ngi 0 : Ngimemezela ukuthi i-interface engizokwamukela ngayo ithrafikhi akuyona i-etho (LAN) noma i-wlan0 (i-Wifi), ngisho ngqo ukuthi yisixhumi esibonakalayo sami se-virbr0, okungukuthi, i-interface yenethiwekhi ebonakalayo (yangaphakathi) i-laptop yami exhumana ngayo neseva yami ebonakalayo (futhi okuphambene nalokho)

-p tcp : Ngicacisa umthetho olandelwayo, okusetshenziswa kakhulu yi-UDP ne-TCP, lapha bekunenele impela ukungakufaki lokhu kepha ... kuyisiko ukucacisa uhlobo lwephrothokholi ukwamukelwa

- ikhasi 192.168.122.88 : Umthombo, umthombo wamaphakeji. Ngamanye amagama, umthetho ubhekisa kumaphakethe aqhamuka ngqo kwi-IP 192.168.122.88

-J YAMUKELA : Kakade lapha ngithi engifuna ukukwenza ngamaphakeji afana nalokhu okungenhla, kulokhu yamukela.

Ngamanye amagama, njengesifinyezo, ngizokwamukela amaphakethe avela ku-IP 192.168.122.88, kepha uma kwenzeka ufuna ukufaka amaphakethe aqhamuka kuleyo IP KODWA! Bafaka kusuka kusixhumi esibonakalayo esingeyona i-virbr0, okungukuthi, ake sithi bazama ukufaka amaphakethe avela ku-IP 192.168.122.88 kepha bavela kukhompyutha kwinethiwekhi yethu ye-Wifi, uma kunjalo, amaphakethe azokwaliwa. kungani? Ngoba sikucacisa ngokusobala ukuthi yebo, samukela amaphakethe kusuka ku-192.168.122.88 yebo, kodwa futhi kuphela kepha, futhi kufanele bangene kusuka kusixhumi esibonakalayo se-virbr0 (ngaphakathi, i-virtual interface interface), uma amaphakethe evela kwesinye isikhombimsebenzisi (i-LAN, i-RAS, Wifi, njll) lapho-ke ngeke zamukelwe. Ngokucacisa i-interface njengoba ubona ukuthi singayikhawulela ngisho nangaphezulu, singaba nokulawula okungcono kokungena (noma okungangeni) kwikhompyutha yethu.

Ukwamukela i-ping kusuka kunoma iyiphi i-IP ye-Wifi yasekhaya:

Kusuka kwenye ikhompyutha exhuma kwi-Wifi, uma uzama ukufaka i-laptop yami ngifuna ukuyivumela. isizathu? Umqondo futhi ukuthi emasontweni ambalwa alandelayo wokuxhumanisa i-PC yendlu eseduze nenethiwekhi, ngakho-ke ukwaba imininingwane kuzoba nzima kakhulu, kube uketshezi oluningi, lapho ngiqala ukwenza izivivinyo zokuxhumanisa ideskithophu ne-Wifi, ngizo ngidinga ukufaka i-laptop yami ukuze ngibheke ukuxhumeka, uma ngabe i-laptop yami ingangibuyiseli emuva ngicabanga ukuthi i-AP iyahluleka, noma ukuthi kube nephutha ekufinyeleleni i-Wifi, yingakho ngifuna ukuvumela i-ping.

sudo iptables -A INPUT -i wlo1 -p icmp -s 192.168.1.0/24 -d 192.168.1.51 -j ACCEPT

-OKUFAKELWA : Njengakuqala, ngibhekisa kuthrafikhi engenayo

-ngisho1 : Kufana naphambilini. Esimweni esedlule ngacacisa i-interface ebonakalayo, kulokhu ngichaza esinye isixhumi esibonakalayo, leso se-wifi yami: wlo1

-p icmp Iphrothokholi ye-Icmp, icmp = ping. Lokho wukuthi, angivumeli i-SSH noma yini efana nayo, ngivumela i-ping (icmp) kuphela

-s 192.168.1.0/24 : Umthombo wamaphakethe, okungukuthi, inqobo nje uma amaphakethe evela ku-IP 192.168.1.? izokwamukelwa

-d 192.168.1.51 : IP IP, okungukuthi, i-IP yami.

-J YAMUKELA : Ngikhombisa okufanele ukwenze ngamaphakeji afana nalawa angenhla, yamukela.

Lokho kungukuthi, nokuchaza lokhu ngendlela esebenzayo, ngiyavuma ukuthi bangibamba (i-icmp protocol) okuya kuyo ngqo i-IP yami, inqobo nje uma bevela ku-IP efana no-192.168.1 .__ kodwa futhi, abakwazi ukuza kusuka kunoma yisiphi isikhombimsebenzisi senethiwekhi, kufanele bangene ngqo kusuka kusixhumi esibonakalayo senethiwekhi yami ye-Wifi (wlo1)

Yamukela i-SSH nge-IP eyodwa kuphela:

Kwesinye isikhathi ngidinga ukuxhuma nge SSH kusuka ku-smartphone yami ukulawula i-laptop, yingakho kufanele ngivumele ukufinyelela kwe-SSH kwi-laptop yami kusuka kuma-IP we-Wifi yami, ngalokhu:

sudo iptables -A INPUT -i wlo1 -p tcp -s 192.168.1.0/24 -d 192.168.1.51 --dport 22 -j ACCEPT

Ukusuka kulayini okuwukuphela kwento ehlukile noma efanele ukugqanyiswa yile: –Bika 22 (I-SSH port ngiyisebenzisa)

Ngamanye amagama, ngiyayemukela imizamo yokuxhuma kwi-laptop yami nge-port 22, inqobo nje uma zivela ku-IP ye-wifi yami, kufanele futhi babe ne-IP yami njengendawo ethile futhi bangene nge-wlo1 interface, okungukuthi, leyo ye-wifi yami (hhayi i-lan, njll.)

Ukubavumela ukuthi babuke iwebhusayithi yakho:

Akusilo icala lami, kepha uma noma ngubani kini enewebhusayithi ebanjelwe futhi angafuni ukuphika ukufinyelela kunoma ngubani, okungukuthi, ukuthi wonke umuntu kusuka noma yikuphi angangena kuleyo webhusayithi, kulula kakhulu kunalokho ongakucabanga:

sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT

Ngamanye amagama, lapha bavumela wonke umgwaqo ongenayo (tcp) ngetheku 80. Njengoba ukwazi ukubona, angisho ukuthi iyiphi i-IP noma inethiwekhi engivumela ukufinyelela kuyo, ngokungacacisi uhla lwe-IP ukuvumela, iptables icabanga ukuthi ngifuna ukuvumela ukufinyelela kuwo wonke amabanga we-IP akhona, okungukuthi, emhlabeni wonke 🙂

Okunye ukuhlanganiswa:

Ngineminye imithetho eminingi efana, ngokwesibonelo, ukwamukela i-ping yama-IPs kusuka ekhaya lami le-LAN (ngoba lokhu kungumugqa ofanayo njengalokhu ngenhla, kushintsha amabanga we-IP), afana kakhulu njengoba ngisanda kuchaza ngenhla ... i-laptop ngaleyo ndlela angizisebenzisi izinto eziyindida impela, zokunciphisa ukuxhumana, i-anti DDoS, ngikushiya lokho kumaseva, kwi-laptop yami angikudingi 🙂

Noma kunjalo, kuze kube manje indatshana.

Njengoba ukwazi ukubona, ukusebenza ngama-iptables akuyona leyo nto eyinkimbinkimbi nganoma iyiphi indlela, uma nje wakhe umbhalo lapho ubhala khona imithetho yakho kulula kakhulu bese uyayiguqula, engeza noma ususe imithetho ku-firewall yakho.

Angizibheki njengongoti ngale ndaba kude nayo, yize kukhona ukungabaza onakho, bayaphawula lapha, ngizozama ukukusiza ngangokunokwenzeka.

Phendula ngokucaphuna


Shiya umbono wakho

Ikheli lakho le ngeke ishicilelwe. Ezidingekayo ibhalwe nge *

*

*

  1. Ubhekele imininingwane: Miguel Ángel Gatón
  2. Inhloso yedatha: Lawula Ugaxekile, ukuphathwa kwamazwana.
  3. Ukusemthethweni: Imvume yakho
  4. Ukuxhumana kwemininingwane: Imininingwane ngeke idluliselwe kubantu besithathu ngaphandle kwesibopho esisemthethweni.
  5. Isitoreji sedatha: Idatabase ebanjwe yi-Occentus Networks (EU)
  6. Amalungelo: Nganoma yisiphi isikhathi ungakhawulela, uthole futhi ususe imininingwane yakho.

  1.   ubungozi kusho

    Kuhle kakhulu, kuchazwe kahle, kuhle.
    Ngiyaluthanda lolu hlobo lokuthunyelwe.

    1.    KZKG ^ Gaara kusho

      Ngiyabonga kakhulu ngokuphawula 🙂

      Lokhu okuthunyelwe bekuyisikweletu ebenginaso isikhathi eside, kumnandi futhi kumnandi ekugcineni ukukwazi ukusikhokha ^ _ ^

      Phendula ngokucaphuna

      1.    I-FIXOCONN kusho

        umbuzo ingabe usecuba?
        … Kwenzeka ukuthi ezinsukwini ezimbalwa ezedlule ngisebenzisa i-Linksys AP (Access Point) ngafaka iWifi endlini yentombi yami

        1.    KZKG ^ Gaara kusho

          Yebo kunjalo, ngazalwa futhi ngihlala eCuba. kungani umbuzo?

        2.    U-Sam burgos kusho

          @FIXOCONN: Sawubona mngani bese uthethelela isihloko sombuzo, kepha usichaza kanjani iCinnamon ukuthi ivele njengendawo yedeskithophu kumenzeli womsebenzisi? Ngisebenzisa iMint 13 neCinnamon, kepha angilutholi ngandlela-thile uphawu lweCinnamon ku-agent yami yomsebenzisi njalo lapho ngiphawula ngaleli sayithi

          Ungaba nomusa ongidlulisela imininingwane yakho yomenzeli womsebenzisi uma kungeyona inkinga enkulu? Ngingathanda ukwazi leyo datha ukuyibeka ngokwami ​​=)

          Ngikushiya ikhasi ukuze ulibuyekeze futhi unginike imininingwane. Ngiyabonga nabaphathi, thethelela i- "trolling" (uma ungayibiza kanjalo) ngami ngalolu lwazi -> http://user-agent-string.info/

          1.    KZKG ^ Gaara kusho

            Faka i- "Cinnamon" (ngaphandle kwezingcaphuno) kunoma iyiphi ingxenye ye-UserAgent, lapho-ke ilogo kufanele ivele kumazwana azayo 🙂

  2.   UBruno cascio kusho

    Kuhle kakhulu okuthunyelwe! kucace bha 😀

    1.    KZKG ^ Gaara kusho

      Siyabonga ngokufunda futhi ngiyabonga ngokuphawula kwakho 🙂

  3.   i-vale kusho

    Ngiyabonga! Kuyangisiza impela!

  4.   U-Oscar Granada kusho

    Sawubona, okokuqala ukuhalalisela okuningi nge-blog, ngicabanga ukuthi kuhle.
    Okungahle kube kuhle ukusho ukuthi inketho yokungena nge-ULOG ayisebenzi ezinhlelweni ezisebenzayo ezine-ulogd2, kulokhu icala umthetho kufanele ube:
    ama-sudo iptables -I-INPUT -p tcp -m tcp -tcp-amafulegi I-FIN, SYN, RST, ACK SYN -j NFLOG

    1.    KZKG ^ Gaara kusho

      Okokuqala, ngiyabonga kakhulu ngalokho okushoyo nge-blog 🙂

      Ngine-ulogd v2.0.2-2 efakwe ku-Arch, futhi ulayini engiwubeka usebenza ngaphandle kwezinkinga (bekufanele ngibeke i-loglevel = 1 ku /etc/ulogd.conf, kepha ithatha izingodo ziye kwelinye ifayela ngaphandle kwezinkinga.

      Ngabe usebenzisa ulogd v2 noma ngaphezulu, ingabe umugqa engiwushiyele umsebenzi awukufanele?

      Ozithobayo nokubonga ngokuphawula.

  5.   I-Citux kusho

    Bengihlala ngilinde ingxenye yesibili, ngiyakhumbula lapho ngifunda eyokuqala (kwakungukuthwasa kwami ​​ezindongeni zomlilo). Ngiyabonga @ KZKG ^ Gaara, Mayelana 🙂

    1.    KZKG ^ Gaara kusho

      Ngiyabonga ngokungifunda 😀
      Futhi hehe yebo, ngathi ... lokhu okuthunyelwe kwakuyisikweletu enganginaso kudala ^ _ ^

  6.   Jose Luis Gonzalez placeholder image kusho

    Sanibonani. Kuhle kakhulu okuthunyelwe. Ngizama ukumisa imithetho ye-iptables ukuqondisa kabusha ithrafikhi kusuka ku-squid kuya ku-dansguardian futhi namanje ayifezi inhloso. Ngingaluthokozela usizo ngalokhu.

    1.    KZKG ^ Gaara kusho

      iptables yalokho? Ngabe lokho akwenziwa ngqo ngama-ACL ku-squid?

  7.   ongenagama kusho

    "Ngineminye imithetho eminingi efana .."
    Yilokhu engikubiza ngokuthi yi-paranoia, mfana
    Okuthe xaxa kancane bese ubeka iphakethe lamaRotwailer's ethekwini ngalinye elivulekile kwimodemu / ku-router yakho

    1.    KZKG ^ Gaara kusho

      HAHAHAHAHAHAHAHAHA Ngiyafa yinsini nabashushuluzi hahahaha

  8.   Ivan kusho

    Ngiyakubingelela mngani, kwenzeka ukuthi ngidinga usizo ukulungisa ama-IPTable ngendlela yokuthi yenqabe ukufinyelela kwe-port 80 kuphela lapho ngithayipha ikheli kusiphequluli sama-nameservers wami wangokwezifiso, kulapho ngokwesibonelo ngithayipha i-ns1.mydomain.com futhi ns2.mydomain. com (okuyi-nameservers yami) ama-IPtables anqabile ukufinyelela ku-port 80 ukuze isiphequluli sizame ukulayisha ikhasi kepha ngemuva kwesikhashana siphelelwe isikhathi futhi singalayishi, kwenzeka ukuthi sengizamile ngemiyalo enjengale:

    iptables -A INPUT -d ns1.midomini.com -p tcp -dport 80 -j DROP
    iptables -A INPUT -d ns2.midomini.com -p tcp -dport 80 -j DROP

    Kepha ukuphela kwento eyenzayo ukwenqaba ukungena ethekwini 80 kuzo zonke izizinda zami (ngoba babelana nge-IP efanayo ne-Virtual Host), ngifuna ukuthi ibe ku-url yamagama ami ne-IP kuphela lapho amagama ami akhomba khona, okungukuthi, amatafula e-IP anqabela ukufinyelela ku-port 80 ku:

    ns1.midomini.com (Ekhomba u-A) -> 102.887.23.33
    ns2.midomini.com (Ekhomba u-A) -> 102.887.23.34

    kanye nama-IP akhonjiswa ngamagama wamagama

    102.887.23.33
    102.887.23.34

    Isibonelo senkampani enalesi simiso yile: Dreamhost
    Ama-nameservers abo: ns1.dreamhost.com kanye ns2.dreamhost.com kanye nama-IP akhomba ukungaphenduli lapho kuthayishwa kubha yekheli lesiphequluli

    Ngibonga kakhulu kusengaphambili ngokunaka kwakho, ngithanda kakhulu ukuthi unginikeze isandla kulokhu, ngiyakudinga futhi ngokuphuthumayo !!

    Usuku oluhle !!

    1.    KZKG ^ Gaara kusho

      Sawubona Ivan,

      Ngithinte nge-imeyili (kzkggaara[at]desdelinux[chashazi] net) ukukhuluma ngayo ngomoya ophansi futhi uyichaze kangcono, kusasa nakanjani ngizokuphendula (namuhla ngiyadlula)

      Lokho ofuna ukukwenza kulula, angazi ukuthi kungani imigqa ongitshela yona ingakusebenzeli, kufanele, kepha kufanele uhlole izingodo nezinye izinto ezizoba zinde kakhulu lapha.

      Ngiyabingelela futhi ngilinde i-imeyili yakho

  9.   i-neysonv kusho

    ngokomqondo ngama-iptables ngingaagwema ukuthunyelwa izicelo zokunqamula kusuka ezinhlelweni ezinjenge-aircrack. Ngiqinisile ??? Hhayi-ke ngizokwenza izivivinyo kepha uma ungitshela lokho ungangijabulisa kakhulu i-XDDD

    1.    KZKG ^ Gaara kusho

      Ngokomqondo ngicabanga kanjalo, manje, angazi ukuthi kungenziwa kanjani, angikaze ngikwenze ... kepha ngiyaphinda, ngombono, ngicabanga ukuthi kungenzeka.

  10.   Alex kusho

    Ngemuva kokusebenzisa imithetho ye-iptables, akunakwenzeka kimi ukufinyelela amafolda okwabelwana ngawo we-windows kunethiwekhi yendawo. Yimuphi umthetho okufanele ngiwusebenzise ukukulungisa?
    Ngiyabonga

    1.    KZKG ^ Gaara kusho

      Yimiphi imithetho ye-iptables oyisebenzisile?
      Le yingxenye yesi-2 yama- "iptables we-newbies", uyifundile eyokuqala? Ngicela lokhu ukwazi ukuthi ngabe uyisebenzisile yini imithetho ebikokuthunyelwe kwangaphambilini

      1.    Alex kusho

        Yebo, ngifunde izingxenye zombili. Ngombhalo engizisekela kokunye okuthumele mayelana nemithetho yokuqala nge-systemd.

        #! / bin / bash
        # - UTF 8 -

        # Iptables kanambambili
        iptables = »/ usr / bin / iptables»

        ulahlile ngaphandle ""

        ## Amathebula ahlanzekile ##
        $ iptables -F
        $ iptables -X
        $ iptables -Z
        #echo »- Kwenziwe i-FLUS kuma-iptables» && echo »»

        # # Ukusungula izingodo nge-ULOGD ##
        $ iptables -A INPUT -p tcp -m tcp -tcp-flags FIN, SYN, RST, ACK SYN -j ULOG

        # # Chaza inqubomgomo ezenzakalelayo ye-DROP ##
        $ iptables -P INPUT DROP
        $ iptables -P PHAMBILI IDROPHU
        #echo »- Inqubomgomo ye-DROP ichazwe ngokuzenzakalela» && echo »»

        # # Vumela konke ku-localhost ##
        $ iptables -I-INPUT -i lo -j YAMUKELA
        $ iptables -I-OUTPUT -o lo -j YAMUKELA
        #echo »- Konke kuvunyelwe kwe-localhost» && echo »»

        # # Vumela ukufaka amaphakethe wokuxhuma engiwaqalayo ##
        $ iptables -A INPUT -m state-state ESTABLISHED, RELATED -j ACCEPT
        #echo »- Amaphakethe wokuxhuma avunyelwe aqalwe yimi» && echo »»

        ulahle ngaphandle "##################
        i-echo »## I-IPTABLES YENZELWE KULUNGILE! ## »
        ulahle ngaphandle "##################

        Ngifundile ku-inthanethi ukuthi kwi-samba kufanele ube nemithetho elandelayo kwiskripthi:

        $ iptables -I-INPUT -p tcp -dport 139 -j YAMUKELA
        $ iptables -I-INPUT -p tcp -dport 445 -j YAMUKELA
        $ iptables -I-INPUT -p udp -sport 137 -j YAMUKELA
        $ iptables -I-INPUT -p udp -dport 137 -j YAMUKELA
        $ iptables -I-INPUT -p udp -dport 138 -j YAMUKELA

        Kodwa-ke, ngisho nakubo angikwazi ukubona amaqembu e-windows. : S

      2.    Alex kusho

        Inkinga ixazululiwe. Shintsha iqembu lokusebenzela kanye nabasingathi bavumela amapharamitha kufayela lokumiswa kwe-samba.

  11.   otkmanz kusho

    I-athikili enhle kakhulu, kuhle nje !!!!
    Ngisanda kuyifunda futhi ngiyayithanda indlela oyichaza ngayo nokusetshenziswa okusebenziseka kahle kwama-iptables, ngithanda kakhulu ukufunda ukuthi ngiyisebenzisa kanjani ngokujula okukhulu.
    Ukubingelela ne-athikili enhle kakhulu, ngiyethemba uzoshicilela okuningi ngama-Iptable! ^^

  12.   I-LEO kusho

    Sawubona;

    Nginommeleli onama-iptables futhi enye yamanethiwekhi ami ayikwazi ukubamba http://www.google.cl ngalesi sizathu nginezimbobo ezivinjiwe futhi ngizama izindlela eziyinkulungwane zokuvula amachweba kungenzeki lutho. Uma ngikwazi ukuphawula angikwazi ukuxhuma umbono

  13.   Borja kusho

    Siyakuhalalisela kokuthunyelwe! Kuhle kakhulu. Kepha nginombuzo. Kwesinye isikhathi ikheli le-IP onikezwe lona kunethiwekhi lingashintsha (uma kuliqiniso ukuthi singanika i-IP kuma-MAC Addres ethu), kepha ngabe kukhona okungenzeka ngama-Iptable okuvumela ukufinyelela kuseva yethu nge-SSH ngekheli le-MAC?

    Ngiyethemba ngichazeke kahle.

    Ozithobayo, futhi ngiyabonga kakhulu!

  14.   UFernando Martin Gan kusho

    Sawubona, uyazi ukuthi ngine-server ye-linux emisiwe futhi ngemuva kokubeka le miyalo ngivimbe yonke into futhi ngalahlekelwa ukufinyelela, ngingathola konke cishe kepha ngilahlekelwe izinto ezi-2. * Angisakwazi ukufinyelela kusuka kusiphequluli sewebhu ngegama elithi «iseva» uma nge-ip, 10.10.10.5 ngakolunye uhlangothi angiboni izinsizakusebenza ezabiwe ezivela kumhloli wamazwibela kunethiwekhi, ngaphambi kokuthi ngibeke ubone zonke izinsizakusebenza ezabiwe. Ngiyethemba ungangisiza, ngiyazi ukuthi kuyisilima kepha angikwazi ukukuxazulula, ngiyabonga

  15.   tau kusho

    Ngicaphuna igama nezwi:
    '
    Iphrothokholi ye-icmp, icmp = ping. Lokho wukuthi, angivumeli i-SSH noma yini efana nayo, ngivumela i-ping (icmp) kuphela
    '

    I-ICMP ne-PING azifani. I-Pinging iyingxenye yephrothokholi ye-ICMP, kepha akuyona yonke into. Umthetho olandelwayo we-ICMP (Internet Control Message Protocol) unokusetshenziswa okuningi, okunye kwakho kunezingozi ezithile. Futhi wamukela yonke ithrafikhi ye-ICMP. Kuzodingeka ukhawulele kuphela i-ping.

    Ukubingelela!

  16.   ozkr kusho

    Kufanele ngenze i-internship kepha angiqondi okuningi ngama-iptables, ngicela ungisize….
    ngiyabonga !!!!!!!