﻿{"id":629,"date":"2021-07-06T00:41:29","date_gmt":"2021-07-05T16:41:29","guid":{"rendered":"https:\/\/www.cloudy.pub\/?p=629"},"modified":"2021-07-06T00:41:29","modified_gmt":"2021-07-05T16:41:29","slug":"linux-xian-zhi-duan-kou-lian-jie","status":"publish","type":"post","link":"https:\/\/www.0moon.com\/?p=629","title":{"rendered":"Linux\u9650\u5236\u7aef\u53e3\u8fde\u63a5"},"content":{"rendered":"\n<p>IPTABLES\u57283600\u79d2\u7684\u65f6\u95f4\u5185\uff0c\u5bf922\u7aef\u53e3\u5efa\u7acb\u8d85\u8fc720\u6b21\u94fe\u63a5\uff0c\u5219\u4e22\u5305\u5904\u7406(\u7c7b\u4f3cfail2ban)\uff1a<\/p>\n\n\n<p>iptables -I INPUT -p tcp &#8211;dport 22 -m state &#8211;state NEW -m recent &#8211;name SSHBAN &#8211;set<br \/>\niptables -I INPUT -p tcp &#8211;dport 22 -m state &#8211;state NEW -m recent &#8211;name SSHBAN &#8211;update &#8211;seconds 3600 &#8211;hitcount 20 -j DROP<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Firewall\u548cIPTABLES\u9650\u5236\u6bcf\u4e2a IP \u7684\u6700\u5927\u8fde\u63a5\u6570\uff1a<\/p>\n\n\n<p>firewall-cmd &#8211;direct &#8211;add-rule ipv4 filter INPUT_direct 0 -p tcp &#8211;dport 22 -m state &#8211;state NEW -m recent &#8211;set<br \/>\nfirewall-cmd &#8211;direct &#8211;add-rule ipv4 filter INPUT_direct 1 -p tcp &#8211;dport 80 -m state &#8211;state NEW -m recent &#8211;update &#8211;seconds 30 &#8211;hitcount 6 -j REJECT &#8211;reject-with tcp-reset<\/p>\n<p>iptables -A INPUT -p tcp &#8211;syn &#8211;dport 443 -m connlimit &#8211;connlimit-above 50 -j REJECT<br \/>\niptables -A INPUT -p tcp &#8211;syn &#8211;dport 80 -m connlimit &#8211;connlimit-above 50 -j REJECT<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\u67e5\u770b\u5df2\u5b58\u5728IPTABLES\u89c4\u5219\uff1a<\/p>\n\n\n<p>iptables -L -n &#8211;line-number<\/p>\n","protected":false},"excerpt":{"rendered":"<p>IPTABLES\u57283600\u79d2\u7684\u65f6\u95f4\u5185\uff0c\u5bf922\u7aef\u53e3\u5efa\u7acb\u8d85\u8fc720\u6b21\u94fe\u63a5\uff0c\u5219\u4e22\u5305\u5904\u7406(\u7c7b\u4f3cfail2ban)\uff1a Fi [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12,13],"tags":[],"class_list":["post-629","post","type-post","status-publish","format-standard","hentry","category-linux","category-study"],"_links":{"self":[{"href":"https:\/\/www.0moon.com\/index.php?rest_route=\/wp\/v2\/posts\/629","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.0moon.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.0moon.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.0moon.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.0moon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=629"}],"version-history":[{"count":2,"href":"https:\/\/www.0moon.com\/index.php?rest_route=\/wp\/v2\/posts\/629\/revisions"}],"predecessor-version":[{"id":631,"href":"https:\/\/www.0moon.com\/index.php?rest_route=\/wp\/v2\/posts\/629\/revisions\/631"}],"wp:attachment":[{"href":"https:\/\/www.0moon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=629"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.0moon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=629"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.0moon.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=629"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}