็†ฑ้–€ๅˆ†้กž
 ่ผ‰ๅ…ฅไธญ…
็›ฎ้Œ„

๐Ÿ›ก️ Linux ้˜ฒ็ซ็‰†่ˆ‡ๅ…ฅไพต้˜ฒ่ญท:็ตๅˆ Firewalld、Fail2Ban ่ˆ‡ Systemd ๅฎ‰ๅ…จ็ญ–็•ฅๅฏฆไฝœ

    ๐Ÿ›ก️ Linux ้˜ฒ็ซ็‰†่ˆ‡ๅ…ฅไพต้˜ฒ่ญท:็ตๅˆ Firewalld、Fail2Ban ่ˆ‡ Systemd ๅฎ‰ๅ…จ็ญ–็•ฅๅฏฆไฝœ

    Linux ็ณป็ตฑๅฎ‰ๅ…จ็š„ๆ ธๅฟƒๅœจๆ–ผ「ๅคšๅฑค้˜ฒ็ฆฆ」。 ๆœฌๆ–‡ๅธถไฝ ไธ€ๆญฅๆญฅ็ตๅˆ FirewalldFail2Ban ่ˆ‡ Systemd, ๅปบ็ซ‹่‡ชๅ‹•ๅŒ–้˜ฒ่ญทๆฉŸๅˆถ,่ฎ“ไผบๆœๅ™จๅœจๅตๆธฌ็•ฐๅธธ็™ปๅ…ฅๆ™‚ๅณๆ™‚ๅฐ้Ž–ๆƒกๆ„ไพ†ๆบ。

    ไธ€、ๆชขๆŸฅ่ˆ‡ๅ•Ÿ็”จ Firewalld

    # ๅฎ‰่ฃ่ˆ‡ๅ•Ÿๅ‹•
    sudo apt install firewalld -y
    sudo systemctl enable --now firewalld
    
    # ๆชข่ฆ–็‹€ๆ…‹
    sudo firewall-cmd --state
    sudo firewall-cmd --list-all
      

    ไบŒ、่จญๅฎš้˜ฒ็ซ็‰†ๅ€ๅŸŸ่ˆ‡ๆœๅ‹™

    # ๅฐ‡ SSH ๅŠ ๅ…ฅ public ๅ€ๅŸŸ
    sudo firewall-cmd --permanent --zone=public --add-service=ssh
    sudo firewall-cmd --reload
    
    # ๆ–ฐๅขž่‡ช่จ‚ๅ€ๅŸŸ(ไพ‹ๅฆ‚ๅ…ง้ƒจ LAN)
    sudo firewall-cmd --permanent --new-zone=internal
    sudo firewall-cmd --permanent --zone=internal --add-source=192.168.0.0/24
      

    ไธ‰、ๆ•ดๅˆ Fail2Ban ๅ…ฅไพต้˜ฒ่ญท

    # ๅฎ‰่ฃ
    sudo apt install fail2ban -y
    
    # ๅปบ็ซ‹่ฆ†ๅฏซ่จญๅฎš
    sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
    sudo vi /etc/fail2ban/jail.local
      

    ่จญๅฎš็ฏ„ไพ‹:

    [sshd]
    enabled = true
    port = ssh
    filter = sshd
    logpath = /var/log/auth.log
    bantime = 600
    maxretry = 5
    action = firewallcmd-ipset
      

    ๅ››、Systemd ่‡ชๅ‹•ๅŒ–ๅ•Ÿๅ‹•่ˆ‡็›ฃๆŽง

    # ๅ•Ÿๅ‹•่ˆ‡ๆชขๆŸฅๆœๅ‹™
    sudo systemctl enable --now fail2ban
    sudo systemctl status fail2ban
    
    # ๆŸฅ็œ‹ๅฐ้Ž–ๅๅ–ฎ
    sudo fail2ban-client status sshd
      

    ไบ”、ๅฎ‰ๅ…จๅผทๅŒ–ๅปบ่ญฐ

    • ๐Ÿ” ้—œ้–‰ root ้ ็ซฏ็™ปๅ…ฅ:PermitRootLogin no
    • ๐Ÿงฑ ไฝฟ็”จ้ž้ ่จญๅŸ ่™Ÿ(ๅฆ‚ 2222)
    • ๐Ÿงฉ ๅ•Ÿ็”จ SELinux / AppArmor ๅผทๅŒ–ๅฑค
    • ๐Ÿ“ˆ ไฝฟ็”จ systemd-analyze ็ขบ่ชๅ•Ÿๅ‹•่€—ๆ™‚

    ๐Ÿ“˜ ็ต่ชž

    ้€้Ž Firewalld、Fail2Ban ่ˆ‡ Systemd ็š„็ต„ๅˆ, ไฝ ่ƒฝๅฟซ้€Ÿๆ‰“้€ ๅ…ผๅ…ท「ๅฝˆๆ€ง、็ฉฉๅฎš่ˆ‡่‡ชๅ‹•ๅŒ–」็š„้˜ฒ็ฆฆๆžถๆง‹。 ๅฐๆ–ผไธญๅฐๅž‹ไผบๆœๅ™จๆˆ–้›ฒ็ซฏไธปๆฉŸ่€Œ่จ€,้€™ๆ˜ฏๆœ€็ฐกๆฝ”ๆœ‰ๆ•ˆ็š„ๅฎ‰ๅ…จ่ตท้ปž。


    ๐Ÿ”— ๅปถไผธ้–ฑ่ฎ€

    — WWFandy・็ณป็ตฑ่ˆ‡็ถฒ่ทฏ็ญ†่จ˜

    ๐Ÿ”— ๅˆ†ไบซ้€™็ฏ‡ LINE Facebook X

    ๆฒ’ๆœ‰็•™่จ€:

    ๅผต่ฒผ็•™่จ€

    ๅญ—็ดš