Ambdós costats versió prèvia Revisió prèvia Següent revisió | Revisió prèvia |
linux:ufw:start [18/07/2019 01:48] – [uso] mate | linux:ufw:start [28/04/2022 01:45] (actual) – [uso] mate |
---|
== uso por defecto | == uso por defecto |
* consultar:<code bash>grep 'DEFAULT_' /etc/default/ufw</code> | * consultar:<code bash>grep 'DEFAULT_' /etc/default/ufw</code> |
* cambiar:<code bash>sudo ufw default allow outgoing</code> | * cambiar:<code bash>sudo ufw default deny incoming |
| sudo ufw default allow outgoing</code> |
| |
== uso | == uso |
sudo ufw allow ssh # /etc/services</code> | sudo ufw allow ssh # /etc/services</code> |
* bloquear una ip+puerto a una ip específica:<code bash>sudo ufw deny from 192.168.2.100/8 to 192.168.2.101 port 25</code> | * bloquear una ip+puerto a una ip específica:<code bash>sudo ufw deny from 192.168.2.100/8 to 192.168.2.101 port 25</code> |
| * rango de puertos:<code bash>sudo ufw allow 6000:7000 proto tcp</code> |
* bloquear tráfico entrante, permitir saliente a un puerto:<code bash>sudo ufw allow out on eth0 to any port 25 proto tcp | * bloquear tráfico entrante, permitir saliente a un puerto:<code bash>sudo ufw allow out on eth0 to any port 25 proto tcp |
sudo ufw deny in on eth0 from any 25 proto tcp</code> | sudo ufw deny in on eth0 from any 25 proto tcp</code> |
/via: [[https://www.linux.com/learn/introduction-uncomplicated-firewall-ufw]] | /via: [[https://www.linux.com/learn/introduction-uncomplicated-firewall-ufw]] |
/via: [[https://www.cyberciti.biz/faq/howto-configure-setup-firewall-with-ufw-on-ubuntu-linux/]] | /via: [[https://www.cyberciti.biz/faq/howto-configure-setup-firewall-with-ufw-on-ubuntu-linux/]] |
| /via: [[https://www.digitalocean.com/community/tutorials/como-configurar-un-firewall-con-ufw-en-ubuntu-18-04-es]] |
| |
== ficheros | == ficheros |
* **/etc/default/ufw**: high level configuration, such as default policies, IPv6 support and kernel modules to use | * **/etc/default/ufw**: high level configuration, such as default policies, IPv6 support and kernel modules to use |
| * ''sudo sed -i s/IPV6=yes/IPV6=no/g /etc/default/ufw'' |
* **/etc/ufw/before[6].rules**: rules in these files are evaluated before any rules added via the ufw command | * **/etc/ufw/before[6].rules**: rules in these files are evaluated before any rules added via the ufw command |
* /**etc/ufw/after[6].rules**: rules in these files are evaluated after any rules added via the ufw command | * /**etc/ufw/after[6].rules**: rules in these files are evaluated after any rules added via the ufw command |