Automate Firewall Rules in Linux

  Рет қаралды 5,128

theurbanpenguin

theurbanpenguin

Күн бұрын

Пікірлер
@Tintak_hatpin
@Tintak_hatpin 2 жыл бұрын
I love these small and helpful videos, the knowledge will be helpful for years.
@theurbanpenguin
@theurbanpenguin 2 жыл бұрын
Glad you like them, thank you
@othernicksweretaken
@othernicksweretaken 2 жыл бұрын
That is exactly how I build up script blocks by fiddling with filters interactively in a shell until I get the matches that I require, and then loop over it or make the thus generated line noise a bit more tangible and comprehensible by my sysadmin colleagues by putting the stuff in functions or intermediary variables. However, if the pipes get too messy I might compact it by switching to awk, perl or python.
@theurbanpenguin
@theurbanpenguin 2 жыл бұрын
excellent
@LVusaAPI
@LVusaAPI 2 жыл бұрын
Hey Andrew would love to see more of fw content
@pbezunartea
@pbezunartea 2 жыл бұрын
Wouldn't the "drop" zone be used rather than the "block" zone? I'd give the potential attackers a timeout in their connection rather than a clear rejection...
@timmy.gunner
@timmy.gunner 2 жыл бұрын
*Hi Andrew is all this FW automation possible through Ansible / puppet /chief ?*
@theurbanpenguin
@theurbanpenguin 2 жыл бұрын
You can configure firewalls with Ansible but as it sets the desired state it is hard to specify the IPs you want to block. Using Fail2Ban you can install and configure with Ansible and Fail2Ban does all of the work for you
@pokibali
@pokibali 2 жыл бұрын
You could possibly run the command and register the output, then loop through it using the firewalld module, I wonder if that would make sense?
@HumbleHuman-k7g
@HumbleHuman-k7g 2 жыл бұрын
Thanks for sharing your knowledges, I wonder why you stack on REL clones and don’t move on up to date distribution like Fedora Linux or OnenSuse Linux ?
@kaliroot6756
@kaliroot6756 2 жыл бұрын
I do not know how familiar you are with linux distributions, but you do not choose Rhel or Rhel like oses (Alma, Rocky, Cloud) cause you want the newest and greatest software. You normaly choose it cause those distributions are very stable. - Fedora is like a Playground, before most features come to RHEL its in a "beta" like fedora release - OpenSUSE is something diffrent, it is like fedora but for SLES(SUSE Enterprise Linux Server)
@othernicksweretaken
@othernicksweretaken 2 жыл бұрын
Maybe he is working like me for a company or authority where your customers force you to e.g. run Oracle, SAP, JBoss, OpenShift etc. where you virtually end up on RHEL. On my private laptop I too prefer running Fedora. I am also glad that Rocky and Alma continue with a replacement for the discontinued (2024) CentOS (not CentOS Stream).
@SpojlerSSJ
@SpojlerSSJ 2 жыл бұрын
That was very interesting. Good job...
@theurbanpenguin
@theurbanpenguin 2 жыл бұрын
Thank you
@s.sje495
@s.sje495 2 жыл бұрын
Hi Andrew, create Video, is it possible to implement a if statement to prevent block my own access by typing a wrong password or any kinds of typo
@theurbanpenguin
@theurbanpenguin 2 жыл бұрын
you could add a simple grep -v as the final command in the pipleline
@isoslimak
@isoslimak 2 жыл бұрын
Great, you will block yourself if you misspell your username while logging in.
@theurbanpenguin
@theurbanpenguin 2 жыл бұрын
I use keys
@home-lab
@home-lab 2 жыл бұрын
You could use an extra grep -v to make sure you are not locked out.
@PlanetCypher_
@PlanetCypher_ 2 жыл бұрын
👍
@djengines
@djengines 2 жыл бұрын
Who leaves ssh open 🤣
@theurbanpenguin
@theurbanpenguin 2 жыл бұрын
For public classes that use SSH
@home-lab
@home-lab 2 жыл бұрын
How else to manage your (remote) server?
@djengines
@djengines 2 жыл бұрын
@@home-lab when I said open I meant open to the Internet.
@othernicksweretaken
@othernicksweretaken 2 жыл бұрын
Maybe one could open it on demand through some port knocking pattern.
@timmy.gunner
@timmy.gunner 2 жыл бұрын
1st again 😊
Using PolKit to rescue sudoers failure
9:20
theurbanpenguin
Рет қаралды 1,9 М.
Demystifying firewalld
22:45
BeginLinux Guru
Рет қаралды 15 М.
Don’t Choose The Wrong Box 😱
00:41
Topper Guild
Рет қаралды 62 МЛН
Каха и дочка
00:28
К-Media
Рет қаралды 3,4 МЛН
SSH Certificate Authority Rocky Linux 8
19:53
theurbanpenguin
Рет қаралды 10 М.
How To Protect Your Linux Server From Hackers!
20:38
LiveOverflow
Рет қаралды 307 М.
Linux Firewall Tutorial | How to Configure Firewall Rules with UFW
13:16
Akamai Developer
Рет қаралды 73 М.
Google’s Quantum Chip: Did We Just Tap Into Parallel Universes?
9:34
How to Set Up a Firewall Using Iptables | SSH Tarpit
12:16
Chris Titus Tech
Рет қаралды 70 М.
18 Commands That Will Change The Way You Use Linux Forever
29:50
Akamai Developer
Рет қаралды 1,3 МЛН
Enabling A Firewall Is Easy In Linux
16:58
DistroTube
Рет қаралды 40 М.
How to protect Linux from Hackers // My server security strategy!
30:39
Christian Lempa
Рет қаралды 231 М.
Linux File System/Structure Explained!
15:59
DorianDotSlash
Рет қаралды 4,2 МЛН
Setting the Correct Permissions on Linux Mountpoints
14:40
theurbanpenguin
Рет қаралды 9 М.