»ùÓÚLINUX²Ù×÷ϵͳµÄ·À»ðǽ¼¼Êõ¼°Æä¾ßÌåʵÏÖ
[ÕªÒª]±¾ÎĽéÉÜÁËLINUXϳ£ÓõķÀ»ðǽ¹æÔòÅäÖÃÈí¼þIpchains£»´ÓʵÏÖÔÀí¡¢ÅäÖ÷½·¨ÒÔ¼°¹¦ÄÜÌØµãµÄ½Ç¶ÈÃèÊöÁËLINUX·À»ðǽµÄÈýÖÖ¹¦ÄÜ£»²¢¸ø³öÁËÒ»¸öLINUX·À»ðǽʵÀý×÷Ϊ²Î¿¼¡£
[¹Ø¼ü×Ö]LINUX·À»ðǽ¡¢ipchains ¡¢°ü¹ýÂË¡¢´úÀí¡¢IPαװ
1 ǰÑÔ
·À»ðǽ×÷ÎªÍøÂ簲ȫ´ëÊ©ÖеÄÒ»¸öÖØÒª×é³É²¿·Ö£¬Ò»Ö±Êܵ½ÈËÃÇµÄÆÕ±é¹Ø×¢¡£LINUXÊÇÕ⼸ÄêÒ»¿îÒì¾üÍ»ÆðµÄ²Ù×÷ϵͳ£¬ÒÔÆä¹«¿ªµÄÔ´´úÂ롢ǿ´óÎȶ¨µÄÍøÂ繦ÄܺʹóÁ¿µÄÃâ·Ñ×ÊÔ´Êܵ½Òµ½çµÄÆÕ±éÔÞÑï¡£LINUX·À»ðǽÆäʵÊDzÙ×÷ϵͳ±¾ÉíËù×Ô´øµÄÒ»¸ö¹¦ÄÜÄ£¿é¡£Í¨¹ý°²×°Ìض¨µÄ·À»ðǽÄںˣ¬LINUX²Ù×÷ϵͳ»á¶Ô½ÓÊÕµ½µÄÊý¾Ý°ü°´Ò»¶¨µÄ²ßÂÔ½øÐд¦Àí¡£¶øÓû§ËùÒª×öµÄ£¬¾ÍÊÇʹÓÃÌØ¶¨µÄÅäÖÃÈí¼þ£¨Èçipchains£©È¥¶¨ÖÆÊʺÏ×Ô¼ºµÄ“Êý¾Ý°ü´¦Àí²ßÂÔ”¡£
2 LINUX·À»ðǽÅäÖÃÈí¼þ—Ipchains
IpchainsÊÇLINUX 2.1¼°ÆäÒÔÉϰ汾ÖÐËù´øµÄÒ»¸ö·À»ðǽ¹æÔò¹ÜÀí³ÌÐò¡£Óû§¿ÉÒÔʹÓÃËüÀ´½¨Á¢¡¢±à¼¡¢É¾³ýϵͳµÄ·À»ðǽ¹æÔò¡£µ«Í¨³££¬ÐèÒª×Ô¼º´´½¨Ò»¸ö·À»ðǽ¹æÔò½Å±¾ /etc/rc.d/rc.firewall£¬²¢Ê¹ÏµÍ³Æô¶¯Ê±×Ô¶¯ÔËÐÐÕâ¸ö½Å±¾¡£
Ò»¸öLINUX·À»ðǽϵͳµÄ°²È«»úÖÆÊÇͨ¹ýInput¡¢Output¡¢ForwardÕâÈý¸ö“·À»ðÁ´”À´ÊµÏֵġ£¶øÓû§ÕýÊÇʹÓÃipchainsÔÚÕâÈý¸ö“Á´”ÉϷֱ𴴽¨Ò»Ìד·À»ð¹æÔò”£¬À´Íê³É¶Ôµ½À´Êý¾Ý°ü²ã²ãÏÞÖÆµÄÄ¿µÄ¡£
ÆäÖУ¬Ã¿¸öÁ´¶¼°üÀ¨Ò»×éÓÉÓû§´´½¨µÄ¹ýÂ˹æÔò£¬Êý¾Ý°üÒÀ´Îµ½´ïÿ¸öÁ´£¬²¢±È½ÏÆäÖеÄÿÌõ¹æÔò£¬Ö±µ½ÕÒ³öÆ¥Å乿Ôò²¢Ö´ÐÐÏàÓ¦²ßÂÔ£¨Èçͨ¹ý¡¢¾Ü¾øµÈ£©£¬·ñÔòÖ´ÐÐĬÈϲßÂÔ¡£Êµ¼ÊÖУ¬Êý¾Ý°üÔÚµ½´ïInputÁ´Ö®Ç°»¹Òª½øÐвâÊÔºÍÕý³£ÐÔ¼ì²é£¬ÔÚµ½Â·Óɱí֮ǰ»¹Òª±»ÅжÏÊÇ·ñ±»Î±×°£¬ÕâЩ£¬ÔÚ±¾Í¼Öж¼±»Ê¡ÂÔÁË¡£
Ipchains ¾³£Ê¹ÓõÄÃüÁîÐиñʽÈçÏ£º
Ipchains –A chain [–i interface] [–p protocol] [[!] -y]
[–s source-ip [port]] [-d destination-ip [port]] –j policy [-l]
¶Ô¸÷Ñ¡ÏîµÄ˵Ã÷ÈçÏÂ±í£º
-A <chain> Ìí¼ÓÒ»¹æÔòµ½Á´Î²¡£chain¿ÉΪinput¡¢output¡¢forward¡£
-i <interface> Ö¸¶¨±¾¹æÔòÊÊÓõÄÍøÂç½Ó¿Ú¡£Í¨³£ÓÐeth0¡¢eth1¡¢lo¡¢ppp0µÈ¡£
-p <protocol> Ö
Ïà¹ØÎĵµ£º
²»Í¬µÄ¹ú¼ÒºÍµØÇøÒòÎÄ»¯µÄ²îÒ죬ÔÚÈÕÆÚ¡¢Ê±¼äÒÔ¼°»õ±Ò·ûºÅµÈ±íʾ·½Ê½É϶¼²»ÍêÈ«Ïàͬ£¬×îΪÃ÷ÏԵľÍÊÇÓïÑÔ¡£ÓÐʱÔÚ±àдÈí¼þ¸øÓû§Ê¹ÓÃʱ£¬¿ª·¢Õß¡¢Î¬
»¤ÕßÒÔ¼°×îÖÕÓû§¿ÉÄÜ·Ö±ðÀ´×Ô²»Í¬µÄÇøÓò£¬¶øÒªÇóËûÃǾùʹÓÃͬһÖÖÓïÑÔÏÔÈ»ÊDz»Ã÷ÖªµÄ£¬Òò´Ëµ±Ò»¸ö³ÌÐò»òÕßÈí¼þ±àд¸øÈ«ÊÀ½çÈËʹÓÃʱ£¬Í¨³£·ÖΪÁ½¸ö²¿·Ö£º
¹ú¼Ê»¯ (intern ......
rhel5Óërhel4²»Í¬µÄµØ·½ÊÇ£¬rhel5ÀïûÓÐ/etc/X11/gdm/Õâ¸öĿ¼£¬rhel5µÄgdmµÄÅäÖÃÎļþ·ÅÔÚÕâÀï/usr/share/gdm/defaults.conf¡£
ÐèÒªÐ޸ĵĵط½ÈçÏ£º
ÐÞ¸Ä/usr/share/gdm/defaults.confÎļþ£¬È·±£ÀïÃæÓÐÒÔϼ¸ÐУº
Enable=true
DisplaysPerHost=10
Port=177
ÔÙÐÞ¸Ä/etc/inittabÎļþ£¬°ÑĬÈϼ¶±ð¸ÄΪ5,ÔÙ¼ÓÈëÒÔÏÂÐ ......
ת×Ô http://hi.baidu.com/grantzhou/blog/item/56a91cf3b685cdc90a46e09d.html
ËÄ¡¢sched_setscheduler()ϵͳµ÷Óá£
Õâ¸öϵͳµ÷Óõĵ÷Óòã´ÎºÍ´úÂë¶¼±Ènice¸´ÔÓЩ£¬ËùÉæ¼°µÄÒ²Óв»ÉÙÎÒÃÇÕâÀï²»¸ÐÐËȤµÄ¶«Î÷£¬Òò´Ë¾Í²»ÔÙÒÔչʾ´úÂëµÄ·½·¨½éÉÜËüÃÇÁË¡£ÕâÀï½öÔÚ¹¦Äܲã´ÎÉÏ£¬´ÓÓënice()¶Ô±ÈµÄ½Ç¶ÈÉ϶ÔËü×öÒ»¸ ......
Íø¿¨µÄÉèÖÃ
¼ûÒÔǰµÄÎÄÕÂ
Ö÷»úÃûµÄÉèÖÃ:
/etc/sysconfig/network
NETWORKING=yes
NETWORKING_IPV6=yes
HOSTNAME=a100 ----->Ö÷»úÃû
smbÊÇSamba µÄÖ÷ÒªÆô¶¯·þÎñÆ÷£¬ÈÃÆäËü»úÆ÷ÄÜÖªµÀ´Ë»úÆ÷¹²ÏíÁËʲô£»
......
linuxĿ¼¼Ü¹¹
/ ¸ùĿ¼
/bin ³£ÓõÄÃüÁî binary file µÄÄ¿錄
/boot ´æ·ÅϵͳÆô¶¯Ê±±ØÐë¶ÁÈ¡µÄµµ°¸£¬°üÀ¨ºËÐÄ (kernel) &nb ......