Linux/Vine3.xインストールメモ>>

昨日:0 / 今日:2 / 合計:1853アクセス

セキュリティ Edit

tcp wrapper の設定 Edit

ローカルネットワークからの接続と某ホストからのftp 接続を許すように設定。/etc/hosts.allowは以下。

#
# hosts.allow	This file describes the names of the hosts which are
#		allowed to use the local INET services, as decided
#		by the '/usr/sbin/tcpd' server.
#
ALL: 192.168.0.7 localhost
swat: localhost
in.ftpd: hoge.example.com,192.168.0.0/255.255.255.0,127.0.0.1

/etc/hosts.denyは以下。

#
# hosts.deny	This file describes the names of the hosts which are
#		*not* allowed to use the local INET services, as decided
#		by the '/usr/sbin/tcpd' server.
#
# The portmap line is redundant, but it is left to remind you that
# the new secure portmap uses hosts.deny and hosts.allow.  In particular
# you should know that NFS uses portmap!
ALL: ALL: spawn=(/usr/sbin/safe_finger -l @%h | /bin/mail -s deny-%d-%h yoshi) EXCEPT 192.168.0.7
swat: ALL

    ホーム 一覧 検索 最終更新 バックアップ リンク元   ヘルプ   最終更新のRSS