官术网_书友最值得收藏!

Securing Your Server with a Firewall

Security is one of those things that's best done in layers. Security-in-depth, we call it. So, on any given corporate network, you will find a firewall appliance separating the internet from the demilitarized zone (DMZ), where your internet-facing servers are kept. You will also find a firewall appliance between the DMZ and the internal LAN, and firewall software installed on each inpidual server and client. We want to make it as tough as possible for intruders to reach their final destinations within our networks. 

Interestingly though, of all the major Linux distros, only the SUSE distros and the Red Hat-type distros come with firewalls already set up and enabled. When you look at your Ubuntu virtual machine, you'll see that it's wide open, as if it were extending a hearty welcome to any would-be intruder.

Since the focus of this book is on hardening our Linux servers, we'll focus this chapter on that last level of defense, the firewalls on our servers and clients.

In this chapter, we'll cover:

  • An overview of iptables
  • Uncomplicated Firewall for Ubuntu systems
  • firewalld for Red Hat systems
  • nftables, a more universal type of firewall system
主站蜘蛛池模板: 苗栗市| 河北区| 安康市| 台北市| 天水市| 海晏县| 兰溪市| 渝北区| 收藏| 峡江县| 和平县| 陕西省| 泾源县| 通州市| 沂源县| 绿春县| 喜德县| 砚山县| 桓仁| 竹北市| 内江市| 清镇市| 宁陵县| 安仁县| 汝阳县| 中阳县| 永嘉县| 文登市| 辽宁省| 西盟| 弥渡县| 湖口县| 无极县| 绿春县| 鸡西市| 汶川县| 当涂县| 和田县| 金溪县| 昂仁县| 安溪县|