Re: [問題] 請問如何用防火牆限制telnet的登入ip?
※ 引述《micchiu.bbs@ptt.cc (PP )》之銘言:
> /sbin/ipfw add pass tcp from IP to me 23
> /sbin/ipfw add deny all from any to any
翻一下任何一本講 TCP connection 連線過程的書,要知道 TCP connection
怎麼建立的,還有,要瞭解 TCP 是雙向傳輸...。
# allow local interface
${fwcmd} add allow ip from any to any via lo0
${fwcmd} add deny ip from 127.0.0.0/8 to any
# pass outgoing packet
${fwcmd} add allow ip from any to any out
# pass established
${fwcmd} add allow tcp from any to any established
# pass 140.113.27.50 to me (SYN)
${fwcmd} add allow tcp from 140.113.27.50 to me 23 setup
# deny telnet
${fwcmd} add deny tcp from any to me 23
--
Resistance is futile.
http://blog.gslin.org/ & <gslin@gslin.org>
--
※ Origin: 邪惡小鹿鹿 <Deer.twbbs.org> ◆ From: 140.113.22.90
討論串 (同標題文章)
以下文章回應了本文:
完整討論串 (本文為第 6 之 10 篇):
FreeBSD 近期熱門文章
PTT數位生活區 即時熱門文章