This article is a mirror article of machine translation, please click here to jump to the original article.

View: 9471|Reply: 1

[linux] CentOS 7 prohibits an IP from accessing the server

[Copy link]
Posted on 2/28/2022 3:35:36 PM | | | |
Requirements: The production server and the UAT server are in the same computer room, but in different CIDR segments, both the production server and the UAT server can communicate with each other. In order to prevent the UAT server from misconfiguring the middleware (database, Redis, Kafka) that accesses the production environment, it is necessary to configure the firewall of the production server to prohibit access to the UAT serverThe official (production) server prohibits IP access from the UAT server

Reference:

In linux, Iptables restricts the same IP connection to prevent CC attacks
https://www.itsvse.com/thread-2943-1-1.html

iptables firewall only allows certain IPs to access certain ports and specific websites
https://www.itsvse.com/thread-2535-1-1.html

CentOS7 View and turn off the firewall
https://www.itsvse.com/thread-7771-1-1.html

Check the firewalld.service service status with the following command:


Review the currently configured firewall rules, with the following command:


To disable access to 10.7.212.128 and 10.7.212.129, execute the following command on the production server:


Of course, it can also be directly restrictedThe entire IP segmentAccess, as follows:


To delete the newly created rule, the command is as follows:


After changing the configurationBe sure to reload the configuration file, the command is as follows:



(End)




Previous:Practical Operation: Use ProGet to build a NuGet private repository
Next:ASP.NET Detailed explanation of Configuration priorities in Core(10).
Posted on 2/28/2022 7:52:00 PM |
Learn to learn...
Disclaimer:
All software, programming materials or articles published by Code Farmer Network are only for learning and research purposes; The above content shall not be used for commercial or illegal purposes, otherwise, users shall bear all consequences. The information on this site comes from the Internet, and copyright disputes have nothing to do with this site. You must completely delete the above content from your computer within 24 hours of downloading. If you like the program, please support genuine software, purchase registration, and get better genuine services. If there is any infringement, please contact us by email.

Mail To:help@itsvse.com