linux系统加固(9)

时间:2026-01-21   来源:未知    
字号:

linux 系统加固手册。linux服务器安全。

然后我们配置它vi /etc/apf/conf.apf

一般配置:

启用防火墙使用块列表

USE_DS=”1″

然后我将列出常规的配置和CPanel配置方式,因为CPanel是应该最广泛的虚拟主机管理软件

1.常规配置(DNS,Mail,Web,FTP) Common ingress (inbound)

# Common ingress (inbound) TCP ports -3000_3500 = passive port range for Pure FTPD IG_TCP_CPORTS=”21,22,25,53,80,110,143,443,995″

#

# Common ingress (inbound) UDP ports IG_UDP_CPORTS=”53″

# Egress filtering [0 = Disabled / 1 = Enabled]

EGF=”1″

# Common egress (outbound) TCP ports

EG_TCP_CPORTS=”21,25,80,443,43″

#

# Common egress (outbound) UDP ports

EG_UDP_CPORTS=”20,21,53″

2.CPanel配置

Common ingress (inbound) ports

# Common ingress (inbound) TCP ports -3000_3500 = passive port range for Pure FTPD IG_TCP_CPORTS=”21,22,25,53,80,110,143,443,2082,2083, 2086,2087,

2095, 2096,3000_3500″

#

# Common ingress (inbound) UDP ports

IG_UDP_CPORTS=”53″

Common egress (outbound) ports

# Egress filtering [0 = Disabled / 1 = Enabled]

EGF=”1″

# Common egress (outbound) TCP ports

EG_TCP_CPORTS=”21,25,80,443,43,2089″

#

# Common egress (outbound) UDP ports

EG_UDP_CPORTS=”20,21,53″

复制代码

之后启动防火墙 /etc/apf/apf -s

如果运行良好我在回去修改配置文件,使DEVM=”0″

然后我们配置APF的AntiDos: vi /etc/apf/ad/conf.antidos

linux系统加固(9).doc 将本文的Word文档下载到电脑,方便复制、编辑、收藏和打印
× 游客快捷下载通道(下载后可以自由复制和排版)
VIP包月下载
特价:19 元/月 原价:99元
低至 0.1 元/份 每月下载300
全站内容免费自由复制
VIP包月下载
特价:19 元/月 原价:99元
低至 0.1 元/份 每月下载300
全站内容免费自由复制
注:下载文档有可能出现无法下载或内容有问题,请联系客服协助您处理。
× 常见问题(客服时间:周一到周五 9:30-18:00)