我一整天早上都在读firewalld,然后想出下面的公共区域:
<?xml version="1.0" encoding="utf-8"?> <zone> <short>Public</short> <description>For use in public areas. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description> <source address="167.114.37.0/24"/> <source address="92.222.185.0/24"/> <source address="92.222.184.0/24"/> <source address="92.222.186.0/24"/> <source address="149.202.34.10/32"/> <service name="dhcpv6-client"/> <service name="http"/> <service name="ssh"/> <service name="https"/> </zone>
我能想到的最好的办法是,这个区域应该只允许这些端口/服务的传入连接,并提供对这些子网的完全访问。 但是,当我用nmap扫描我的服务器时,我得到了开放端口的小船(我绝对不在白名单子网中的一个)。
PORT STATE SERVICE 1/tcp open tcpmux 3/tcp open compressnet 4/tcp open unknown 6/tcp open unknown 7/tcp open echo 9/tcp open discard 13/tcp open daytime 17/tcp open qotd 19/tcp open chargen 20/tcp open ftp-data 21/tcp open ftp 22/tcp open ssh 23/tcp open telnet 24/tcp open priv-mail 25/tcp filtered smtp 26/tcp open rsftp 30/tcp open unknown 32/tcp open unknown 33/tcp open dsp 37/tcp open time 42/tcp open nameserver 43/tcp open whois 49/tcp open tacacs 53/tcp open domain 70/tcp open gopher 79/tcp open finger 80/tcp closed http 81/tcp open hosts2-ns 82/tcp open xfer 83/tcp open mit-ml-dev 84/tcp open ctf 85/tcp open mit-ml-dev 88/tcp open kerberos-sec 89/tcp open su-mit-tg 90/tcp open dnsix 99/tcp open metagram 100/tcp open newacct 106/tcp open pop3pw 109/tcp open pop2 110/tcp open pop3 111/tcp open rpcbind 113/tcp open ident 119/tcp open nntp 125/tcp open locus-map 135/tcp filtered msrpc 139/tcp filtered netbios-ssn
…名单继续,我想我会在那里停下来。 我在这里错过了什么?
编辑如果我尝试访问这些打开或过滤端口之一,说curl ,我得到以下
$ curl myserver.example.com:125 curl: (7) Failed to connect to myserver.example.com port 125: Operation timed out
而当我尝试访问其中一个封闭的端口时,我正确地获得connection refused 。
testing计算机和服务器之间可能有一个中间路由器。 在这种情况下,路由器通过发送假回复来混淆nmap,可能是NAT实施的一个细微差别。 如果我是正确的,你将得到类似的结果,如果你从计算机扫描任何随机IP。