学習したことや試行錯誤を後で再利用できるように自分のためにまとめたものです。 特にオープンなIT技術は世界の一人ひとりの活動によって支えられていると思います。 メモの内容が微力ながらそれに貢献できるのではないかと思い公開しています。 記述内容に誤りもあるかもしれません。試す方はご自身で十分検証し自己責任でお願いします。リンクは自由です。
人気の投稿(1ヶ月間)
-
ここでは、Raspberry Pi 5に、基本となるOS「Raspberry Pi OS Lite」に、追加でソフトウェアを構築、設定して、デスクトップ環境構築する手順についてまとめている。 このように基本となる軽量OSに必要なパッケージを加えていくことによって、余計なものが...
-
■ 概要 ここでは、安全なローカルネットワーク上にあるRaspberry Pi 5 (Raspberry Pi OS)に、ローカルHDMIディスプレイに表示されるデスクトップをミラーリングしたリモートデスクトップ接続を行う手順を確認している。 このリモートデスクトッ...
-
IPsecトンネルを2本用意して、一方をメインとし、他方をバックアップとして、 障害時に自動的に切り替わるように設定する方法の概略 実験して試したところ、以下の設定でうまく切り替えることができたので肝心なところをメモしておく。 ここでは、次のような構成をイメージして...
-
RTX1210配下の端末において指定したURLへの通信のみ、指定した経路(ppなど)を通るようにする。 それには、ドメイン名(FQDN)で指定するフィルタ型デフォルトルートを設定すればよい。 もし、その指定するpp経路が固定アドレスなら、固定アドレスで相手先と通信できることに...
-
ここでは、安全なローカルネットワーク上にあるRaspberry Pi 5 (Raspberry Pi OS)に、SSHでリモート接続を行う手順を確認している。 不意な切断でセッションが閉じて動作中コマンドが終了してしまうことを防ぐため、ターミナルマルチプレクサ(Termina...
-
Linuxデスクトップ環境でThunderbird 78.9.0を、IMAPサーバー(Dovcot)のクライアントとしてセットアップした。 これでIMAPサーバーに保存されているメールがThunderbirdで操作できるようになった。 ところが、Thunderbirdはデフォルト...
-
RTX1200をRTX1210に置き換える。 その際のコンフィグファイルの移し替え、ファームウェアのアップデートを行った。 いずれも、tftpコマンドを用いた。 使用したマシンは、Linux(CentOS 7)である。 (注意) RTX1210のシリアル番号が、次の...
-
2017年4月12日 いくつか説明追加 YAMAHA ルーターの「NAT」について勝手なまとめ 以下、NATなどの定義のみを扱っている。 定義したNATは、意図される動作のために、しかるべきインターフェイスに掛けられる必要がある。 しかしここではインターフェイスへの...
-
CentOS 5.7(64bit)に、iaxmodemとhylafaxをインストールする手順 HylaFaxというFAXサーバとそのクライアントソフトウェアを使えば、ネットワークを通じてWindowsマシンなどから手軽にFAXを送信することができるようになる。 さらに、Hy...
-
YAMAHAルーター、RTX1200のファームウェアアップデート手順 現行のファームウェアと、それに伴う設定ファイルのバックアップを行い、その後、ファームウェアのアップデートを行った。 アップデートされたファームウェアが原因で正常動作しなかった場合に、容易に復旧させられるよ...
Ad
Ad
2018年4月12日木曜日
【Linux CentOS 7】iptablesサービスで、filterとnatの両テーブルの内容を保存し復元する方法
以下では、下記ページのようにして、
CentOS 7 でfirewalld の代わりにiptablesサービスを使用することを前提にしている。
http://akira-arets.blogspot.jp/2018/03/linux-centos7-iptablesservice.html
既存のiptables filterルールに加えて、natルールを追加した。
例えば、
# iptables -t nat -A PREROUTING -i eth1 -d 10.1.1.11 -j DNAT --to 192.168.1.11
これによって、このマシンのeth1(10.1.1.11)にパケットを送ると、
宛先が変更されて、192.168.1.11に送信される。
しかし、このnatルールはどうやってファイルに保存できるのだろう。
iptables-save コマンドに-t nat オプションをつけることで、
このnatルールの出力は可能だった。
■ 入力済みのiptablesルール(filteと、natの両方)を保存する。
iptables-save コマンドはオプションなしで、filterテーブルの内容を出力し、
-t nat オプションで、natテーブルの内容を出力する。
そのため次のように、/etc/sysconfig/iptablesファイルに連続出力させた。
「>>」で上書きせずに書き足すことができた。
# iptables-save > /etc/sysconfig/iptables ; iptables-save -t nat >> /etc/sysconfig/iptables
■保存したルールが有効化されたかどうかを確かめた。
○iptablesサービスを再起動し、/etc/sysconfig/iptablesファイルの内容を読み込ませた。
# systemctl restart iptables
○読み込みが正常かどうかを確認した。
# iptables -L -v
# iptables -L -v -t nat
正常に、filterテーブル、natテーブルの両方のルールが復元されていることがわかった。
<参考>
・6. パケットの料理法の解説
< https://linuxjf.osdn.jp/JFdocs/NAT-HOWTO-6.html >
2018年3月16日金曜日
【Linux CentOS 7】firewalld でなく、CentOS6のようにiptablesサービスを使う手順
CentOS 7 では、firewalld がデフォルトになっている。
# systemctl status firewalld
● firewalld.service - firewalld - dynamic firewall daemonこれによって、以下に挙げるようにルールが適用されている。
Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled)
Active: active (running) <略>
そのルールを見ると、プログラミングみたいに階層構造があって、ひたすら長い。
単純なサーバーだし、CentOS6みたいにもっと単純なのがいい。
自分は、CentOS6のiptablesサービスに慣れているので、
CentOS7でもそれと同じように設定したい。
インターネットに接続するサーバーの設定なので、自分で作成したルールも持っている。
それを適用したいのである。(ただし、インターフェイス名は修正する必要がある。)
不慣れなことをして、隙をつくってしまったら意味ない。
■せっかくなので、firewalldによって設定されているルールを一部だけ確認した。
# iptables -L -v
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
2 104 ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED
0 0 ACCEPT all -- lo any anywhere anywhere
0 0 INPUT_direct all -- any any anywhere anywhere
0 0 INPUT_ZONES_SOURCE all -- any any anywhere anywhere
0 0 INPUT_ZONES all -- any any anywhere anywhere
0 0 DROP all -- any any anywhere anywhere ctstate INVALID
0 0 REJECT all -- any any anywhere anywhere reject-with icmp-host-prohibited
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED
0 0 ACCEPT all -- lo any anywhere anywhere
0 0 FORWARD_direct all -- any any anywhere anywhere
0 0 FORWARD_IN_ZONES_SOURCE all -- any any anywhere anywhere
0 0 FORWARD_IN_ZONES all -- any any anywhere anywhere
0 0 FORWARD_OUT_ZONES_SOURCE all -- any any anywhere anywhere
0 0 FORWARD_OUT_ZONES all -- any any anywhere anywhere
0 0 DROP all -- any any anywhere anywhere ctstate INVALID
0 0 REJECT all -- any any anywhere anywhere reject-with icmp-host-prohibited
Chain OUTPUT (policy ACCEPT 2 packets, 104 bytes)
pkts bytes target prot opt in out source destination
2 104 OUTPUT_direct all -- any any anywhere anywhere
このように、最初に、INPUT、FORWARD、OUTPUTチェインが定義されていて、
続いて、各チェインで参照されているターゲットが定義されている。
(以下、一部のみ抜粋)
Chain INPUT_ZONES (1 references)
pkts bytes target prot opt in out source destination
0 0 IN_public all -- wlp4s0 any anywhere anywhere [goto]
0 0 IN_public all -- + any anywhere anywhere [goto]
Chain INPUT_ZONES_SOURCE (1 references)
pkts bytes target prot opt in out source destination
Chain INPUT_direct (1 references)
pkts bytes target prot opt in out source destination
Chain IN_public (2 references)
pkts bytes target prot opt in out source destination
0 0 IN_public_log all -- any any anywhere anywhere
0 0 IN_public_deny all -- any any anywhere anywhere
0 0 IN_public_allow all -- any any anywhere anywhere
0 0 ACCEPT icmp -- any any anywhere anywhere
Chain IN_public_allow (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:ssh ctstate NEW
Chain IN_public_deny (1 references)
pkts bytes target prot opt in out source destination
Chain IN_public_log (1 references)
pkts bytes target prot opt in out source destination
以上は、INPUTチェインをルートとして定義を追ったものである。
ACCEPTだけで受けずに、まず別のチェインで受けることで、階層的に定義がされていることがわかる。
■firewallでなく従来のように、iptablesコマンドで一つずつルールを設定する。
しかし、ここでは自分で従来のようにルールを管理したいので、
firewalldを無効にし、自分で定義を行いたい。
(注意)
ファイアウォールの定義を変更するため、リモートターミナルは切断される。
必ずローカルでコンソールから設定を行う。
○iptablesを導入した。
# yum install iptables-services
インストール:
iptables-services.x86_64 0:1.4.21-18.3.el7_4
依存性を更新しました:
iptables.x86_64 0:1.4.21-18.3.el7_4
完了しました!
# yum info iptables-services
名前 : iptables-services
アーキテクチャー : x86_64
バージョン : 1.4.21
リリース : 18.3.el7_4
容量 : 25 k
リポジトリー : installed
提供元リポジトリー : updates
要約 : iptables and ip6tables services for iptables
URL : http://www.netfilter.org/
ライセンス : GPLv2
説明 : iptables services for IPv4 and IPv6
:
: This package provides the services iptables and ip6tables that have been split
: out of the base package since they are not active by default anymore.
(注意)
以下の手順にすすむ前に、無防備の状態を避けるため、
安全なローカルネットワーク環境で行うか、
予め、LAN接続を断つか、無効にしておく。
○firewalld を停止し、無効にする。
# systemctl stop firewalld
# systemctl disable firewalld
disableにすることで、システムを再起動しても firewalld は起動しない。
○代わって、iptables サービスを起動し、有効化する。
# systemctl start iptables
# systemctl enable iptables
Created symlink from /etc/systemd/system/basic.target.wants/iptables.service to /usr/lib/systemd/system/iptables.service.enableにすることで、システム起動時に iptablesサービス が起動する。
(注意)
ip6tables と、iptablesは別個のサービスである。
もし同様にして、ip6tablesを設定しているなら、
ip6tablesの起動(systemctl start ip6tables)と、
自動起動(systemctl enable ip6tables)の設定も忘れないこと。
この状態で、ルールは自動的に次のようになっていた。
# iptables -L -v
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)あるいは、コンフフィグ直接ファイルを表示する。
pkts bytes target prot opt in out source destination
4623 2499K ACCEPT all -- any any anywhere anywhere state RELATED,ESTABLISHED
0 0 ACCEPT icmp -- any any anywhere anywhere
252 16372 ACCEPT all -- lo any anywhere anywhere
0 0 ACCEPT tcp -- any any anywhere anywhere state NEW tcp dpt:ssh
3 577 REJECT all -- any any anywhere anywhere reject-with icmp-host-prohibited
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 REJECT all -- any any anywhere anywhere reject-with icmp-host-prohibited
Chain OUTPUT (policy ACCEPT 5231 packets, 1654K bytes)
pkts bytes target prot opt in out source destination
# cat /etc/sysconfig/iptables
# sample configuration for iptables service
# you can edit this manually or use system-config-firewall
# please do not ask us to add additional ports/services to this default configuration
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
この状態で一応ネットに接続することができた。
○以下では、自分で作成するルールを設定する。
(設定したい自分のルールをテキストで用意してから望みましょう。)
先ず、ネットワークを不通にする。(ネットが全く使えなくなる。)
# iptables -F ; iptables -P INPUT DROP ; iptables -P FORWARD DROP ; iptables -P OUTPUT DROP
ここで、ルールの内容を表示させた。
# iptables -L -v
Chain INPUT (policy DROP 0 packets, 0 bytes)CentOS6 で見慣れたルールが現れた。
pkts bytes target prot opt in out source destination
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
さらに設定を続ける。
CentOS7では、CentOS6のときと違って、-i で指定するインターフェースが、
独自のものになっていることに注意する。(例えば、-i eth0 でない。)
# iptables <略>
# iptables <略>
<省略>
○設定を終えたら、ルールを保存する。
# iptables-save > /etc/sysconfig/iptables
ルールを保存しなければ、再起動時に設定内容が復元されないので注意。
念の為、システムを再起動して、ルールが適用されているか確認した。
問題なく復元され、有効化されていた。
filterだけでなく、natルールも保存するには次のページを参考にしてください。
http://akira-arets.blogspot.jp/2018/04/linux-centos7-natrules-savingrestoring.html
以上
<参考>
・CentOS7でのiptablesの設定忘れるのでメモ
< https://qiita.com/miosee/items/0599baa3a01301265a43 > 2018年3月16日
・iptables を設定する
< http://dejune.net/deblog/raspberrypi/post/20131016222940.html > 2018年3月16日
・22.8. iptables の設定を保持する(iptables-save と iptables-restore)
< http://www.turbolinux.co.jp/products/server/11s/user_guide/iptablesboot.html > 2018年3月16日
登録:
投稿 (Atom)