Life is fun and easy!
不正IP報告数
Okan Sensor
ページへ戻る
印刷
MacOS X/ipfw
をテンプレートにして作成 ::
UJP
tech_regist2
:MacOS X/ipfw をテンプレートにして作成
開始行:
TITLE:Firewall
**SASL LOGINに失敗しているIPアドレスを取り出す
grep "SASL LOGIN authentication failed" /var/log/system....
**現在のipfwの設定値を表示する
ujp:~ user$ ipfw list
ipfw: socket: Operation not permitted
ujp:~ user$
rootユーザにスイッチする.
ujp:~ user$ su
Password:
sh-3.2# ipfw list
00001 allow udp from any 626 to any dst-port 626
01000 allow ip from any to any via lo0
01010 deny ip from any to 127.0.0.0/8
01020 deny ip from 224.0.0.0/4 to any in
01030 deny tcp from any to 224.0.0.0/4 in
12300 allow ip from any to any
65534 deny ip from any to any
65535 allow ip from any to any
sh-3.2#
**IPアドレスのルールを追加する
sh-3.2# ipfw add 1001 deny tcp from 88.215.177.135 to an...
01001 deny tcp from 88.215.177.135 to any in
sh-3.2# ipfw list
00001 allow udp from any 626 to any dst-port 626
01000 allow ip from any to any via lo0
01001 deny tcp from 88.215.177.135 to any in ←追加した...
01010 deny ip from any to 127.0.0.0/8
01020 deny ip from 224.0.0.0/4 to any in
01030 deny tcp from any to 224.0.0.0/4 in
12300 allow ip from any to any
65534 deny ip from any to any
65535 allow ip from any to any
sh-3.2#
もう一回追加する.
sh-3.2# ipfw add 1001 deny tcp from 175.116.152.58 to an...
01001 deny tcp from 175.116.152.58 to any in
sh-3.2# ipfw list
00001 allow udp from any 626 to any dst-port 626
01000 allow ip from any to any via lo0
01001 deny tcp from 88.215.177.135 to any in ←さっき追...
01001 deny tcp from 175.116.152.58 to any in ←今追加し...
01010 deny ip from any to 127.0.0.0/8
01020 deny ip from 224.0.0.0/4 to any in
01030 deny tcp from any to 224.0.0.0/4 in
12300 allow ip from any to any
65534 deny ip from any to any
65535 allow ip from any to any
sh-3.2#
ルール番号はダブルブッキングOKのようだけど登録順に並べ...
終了行:
TITLE:Firewall
**SASL LOGINに失敗しているIPアドレスを取り出す
grep "SASL LOGIN authentication failed" /var/log/system....
**現在のipfwの設定値を表示する
ujp:~ user$ ipfw list
ipfw: socket: Operation not permitted
ujp:~ user$
rootユーザにスイッチする.
ujp:~ user$ su
Password:
sh-3.2# ipfw list
00001 allow udp from any 626 to any dst-port 626
01000 allow ip from any to any via lo0
01010 deny ip from any to 127.0.0.0/8
01020 deny ip from 224.0.0.0/4 to any in
01030 deny tcp from any to 224.0.0.0/4 in
12300 allow ip from any to any
65534 deny ip from any to any
65535 allow ip from any to any
sh-3.2#
**IPアドレスのルールを追加する
sh-3.2# ipfw add 1001 deny tcp from 88.215.177.135 to an...
01001 deny tcp from 88.215.177.135 to any in
sh-3.2# ipfw list
00001 allow udp from any 626 to any dst-port 626
01000 allow ip from any to any via lo0
01001 deny tcp from 88.215.177.135 to any in ←追加した...
01010 deny ip from any to 127.0.0.0/8
01020 deny ip from 224.0.0.0/4 to any in
01030 deny tcp from any to 224.0.0.0/4 in
12300 allow ip from any to any
65534 deny ip from any to any
65535 allow ip from any to any
sh-3.2#
もう一回追加する.
sh-3.2# ipfw add 1001 deny tcp from 175.116.152.58 to an...
01001 deny tcp from 175.116.152.58 to any in
sh-3.2# ipfw list
00001 allow udp from any 626 to any dst-port 626
01000 allow ip from any to any via lo0
01001 deny tcp from 88.215.177.135 to any in ←さっき追...
01001 deny tcp from 175.116.152.58 to any in ←今追加し...
01010 deny ip from any to 127.0.0.0/8
01020 deny ip from 224.0.0.0/4 to any in
01030 deny tcp from any to 224.0.0.0/4 in
12300 allow ip from any to any
65534 deny ip from any to any
65535 allow ip from any to any
sh-3.2#
ルール番号はダブルブッキングOKのようだけど登録順に並べ...
ページ名: