[ UBUNTU ] 리눅스 방화벽 UFW 설정

UFW 활성화

sudo ufw enable

Ubuntu 에서 초기값은 비활성화

 

UFW 비활성화

sudo ufw disable

UFW 설정 상태 확인

sudo ufw status 또는 sudo ufw verbose

기본룰 설정 (기본정책)

들어오는 패킷에 대해서는 전체 거부 (deny)

들어오는 패킷에 대해서는 전체 허용 (allow)

sudo ufw show raw 
sudo ufw default deny 
sudo ufw default allow

sudo ufw —help

Usage: ufw COMMAND

Commands:
 enable                          enables the firewall
 disable                         disables the firewall
 default ARG                     set default policy
 logging LEVEL                   set logging to LEVEL
 allow ARGS                      add allow rule
 deny ARGS                       add deny rule
 reject ARGS                     add reject rule
 limit ARGS                      add limit rule
 delete RULE|NUM                 delete RULE
 insert NUM RULE                 insert RULE at NUM
 route RULE                      add route RULE
 route delete RULE|NUM           delete route RULE
 route insert NUM RULE           insert route RULE at NUM
 reload                          reload firewall
 reset                           reset firewall
 status                          show firewall status
 status numbered                 show firewall status as numbered list of RULES
 status verbose                  show verbose firewall status
 show ARG                        show firewall report
 version                         display version information

Application profile commands:
 app list                        list application profiles
 app info PROFILE                show information on PROFILE
 app update PROFILE              update PROFILE
 app default ARG                 set default application policy

 

고급

특정 ip 허용

sudo ufw allow from 192.168.0.77
sudo ufw allow from 192.168.50.0/24 #네트워크 단위 지정

특정 ip 허용 또는 거부 + 포트 제한

sudo ufw allow from 192.168.0.77 to any port 22
sudo ufw deny from 192.168.0.77 to any port 22

들어오는 통신을 막고 나가는 통신을 허용

sudo ufw default deny incoming
sudo ufw default allow outgoing

댓글

Designed by JB FACTORY