当前位置:网站首页>Hedhat firewall
Hedhat firewall
2022-07-05 01:11:00 【weixin_ fifty-one million four hundred and twenty-eight thousan】
The firewall will read the configured policy rules from top to bottom , Immediately after the match is found, the matching work is finished and the behavior defined in the match is executed ( To release or prevent ). If there is no match after reading all the policy rules , Go ahead and implement the default strategy . generally speaking , There are two kinds of firewall policy rules :“ through ”( Let's go ) and “ Block up ”( That is to prevent ). When the default policy of firewall is reject ( Block up ), It's about setting the allow rule ( through ), Otherwise no one can come in ; If the default policy of the firewall is allow , It's about setting rejection rules , Otherwise everyone can come in , Firewall also lost the role of prevention .
iptables The service refers to the policy entries used to process or filter traffic as rules , Multiple rules can form a rule chain , The rule chain is classified according to the location of packet processing , As follows :
Process packets before routing (PREROUTING);
Process incoming packets (INPUT);
Process outgoing packets (OUTPUT);
Process forwarded packets (FORWARD);
Process packets after routing (POSTROUTING).
Generally speaking , The traffic sent from the intranet to the Internet is generally controllable and benign , So the most used is INPUT Rule chain , The rule chain can make it more difficult for hackers to invade the intranet from the external network .
For example, in the community where you live , Property management companies have two provisions : Prohibit hawkers from entering the community ; All kinds of vehicles must be registered when entering the community . Obvious , These two rules should be applied to the front door of the community ( Where the flow must pass ), Not on the security door of every house . According to the matching order of firewall policies mentioned above , There may be many situations . such as , The visitors are vendors , Will be directly rejected by the security of the property company , There is no need to register the vehicle . If visitors enter the main gate of the community in a car , be “ Prohibit hawkers from entering the community ” The first rule of is not matched , So match the second strategy in order , That is, the vehicle needs to be registered . If you are a community resident, you need to enter the main entrance , Then these two provisions will not match , Therefore, the default release policy will be implemented .
however , Only policy rules cannot guarantee the safety of the community , The security guard should also know what actions to take to deal with these matching traffic , such as “ allow ”“ Refuse ”“ registration ”“ Ignore it ”. These actions correspond to iptables The terms of service are ACCEPT( Allow flow through )、REJECT( Reject traffic through )、LOG( Logging information )、DROP( Reject traffic through ).“ Allow flow through ” and “ Logging information ” It's easy to understand , What needs to be emphasized here is REJECT and DROP The difference between . Just DROP Come on , It directly discards traffic and does not respond ;REJECT Then it will reply one more message after rejecting the traffic “ The message has been received , But it was thrown away ” Information , So that the traffic sender can clearly see the response information of data rejected .
边栏推荐
- 全网最全正则实战指南,拿走不谢
- node工程中package.json文件作用是什么?里面的^尖括号和~波浪号是什么意思?
- 测试部新来了个00后卷王,上了年纪的我真的干不过了,已经...
- [Yocto RM]10 - Images
- Call Huawei order service to verify the purchase token interface and return connection reset
- Innovation leads the direction. Huawei Smart Life launches new products in the whole scene
- Introduction to redis (1)
- Apifox (postman + swagger + mock + JMeter), an artifact of full stack development and efficiency improvement
- [microprocessor] VHDL development of microprocessor based on FPGA
- 创新引领方向 华为智慧生活全场景新品齐发
猜你喜欢

Database performance optimization tool

Apifox (postman + swagger + mock + JMeter), an artifact of full stack development and efficiency improvement

【大型电商项目开发】性能压测-性能监控-堆内存与垃圾回收-39

LeetCode周赛 + AcWing周赛(T4/T3)分析对比

dotnet-exec 0.6.0 released

揭露测试外包公司,关于外包,你或许听到过这样的声音

dotnet-exec 0.6.0 released

测试部新来了个00后卷王,上了年纪的我真的干不过了,已经...

Delaying wages to force people to leave, and the layoffs of small Internet companies are a little too much!
![[wave modeling 3] three dimensional random real wave modeling and wave generator modeling matlab simulation](/img/22/6d3867015811aae29b8a7df5ee3d0b.png)
[wave modeling 3] three dimensional random real wave modeling and wave generator modeling matlab simulation
随机推荐
潘多拉 IOT 开发板学习(RT-Thread)—— 实验4 蜂鸣器+马达实验【按键外部中断】(学习笔记)
Redis(1)之Redis简介
Expose testing outsourcing companies. You may have heard such a voice about outsourcing
Discrete mathematics: reasoning rules
全栈开发提效神器——ApiFox(Postman + Swagger + Mock + JMeter)
Applet live + e-commerce, if you want to be a new retail e-commerce, use it!
[pure tone hearing test] pure tone hearing test system based on MATLAB
Global and Chinese markets of emergency rescue vessels (errv) 2022-2028: Research Report on technology, participants, trends, market size and share
Reasons and solutions of redis cache penetration and avalanche
创新引领方向 华为智慧生活全场景新品齐发
Maximum number of "balloons"
Database postragesql client authentication
[wave modeling 1] theoretical analysis and MATLAB simulation of wave modeling
Take you ten days to easily complete the go micro service series (IX. link tracking)
Game 280 of leetcode week
LeetCode周赛 + AcWing周赛(T4/T3)分析对比
【海浪建模3】三维随机真实海浪建模以及海浪发电机建模matlab仿真
Query for Boolean field as "not true" (e.g. either false or non-existent)
SAP UI5 应用开发教程之一百零七 - SAP UI5 OverflowToolbar 容器控件介绍的试读版
【海浪建模2】三维海浪建模以及海浪发电机建模matlab仿真