立即注册 登录
五常信息网(五常论坛) 返回首页

青青子矜的个人空间 http://www.5cxx.com/5c/?8230 [收藏] [复制] [分享] [RSS]

日志

设置IPFW防火墙规则,解决Discuz! X3.2云平台等的通讯问题

已有 1151 次阅读2015-1-2 23:01 | 发送信息, 应用中心, 云平台, 防火墙, 服务器

很老的一台服务器了,系统是FreeBSD7.2的,一直运行着Discuz 7.2。最近安装了Discuz X3.2,结果遇到了麻烦。
进后台比老牛拉车还慢。云平台检测不通过,应用中心连不上。
想一想应该是防火墙的问题。
原来的服务器的防火墙我只允许外网访问80端口,并且服务器不得向外发送信息。规则是相当苛刻的。
没办法关闭防火墙,3.2正常了。
这不是我要的结果。
开始研究云平台都和那些IP有关联。
最后在ipfw规则中,添加了允许系统和云平台的相关ip、应用中心addon.discuz.com的ip通讯,同时开启53端口。
还剩下一个问题,UCenter里的应用通讯失败。不得已在应用设置里加了服务器的内网ip,通讯成功了。
大致就是这么个情况。
-------------------------------
#!/bin/sh
ipfw -q -f flush
ipfw add allow ip from any to any via lo0
ipfw deny ip from any to any to 127.0.0.0/8
ipfw add deny log ip from any to any ipopt rr
ipfw add deny log ip from any to any ipopt ts
ipfw add deny log ip from any to any ipopt ssrr
ipfw add deny log ip from any to any ipopt lsrr
ipfw add deny tcp from any to any in tcpflags syn,fin
ipfw add deny udp from any to any 80
ipfw add allow udp from me to any 53 out
ipfw add allow udp from any 53 to me in

ipfw add check-state
ipfw add allow tcp from me to 140.207.69.30 out setup keep-state
ipfw add allow tcp from 140.207.69.30 to me in setup keep-state
ipfw add allow tcp from me to 112.65.195.175 out setup keep-state
ipfw add allow tcp from me to 101.226.62.63 out setup keep-state
ipfw add allow tcp from me to 101.226.103.122 out setup keep-state
ipfw add allow tcp from me to 58.251.139.148 out setup keep-state
ipfw add allow tcp from me to 140.207.54.53 out setup keep-state
ipfw add allow tcp from me to 183.60.15.158 out setup keep-state
ipfw add allow tcp from me to 112.90.83.87 out setup keep-state
ipfw add allow tcp from me to 123.58.177.199 25 out setup keep-state
ipfw add allow tcp from me to 123.58.178.59 25 out setup keep-state
ipfw add allow tcp from 123.58.178.59 to me in setup keep-state
ipfw add allow tcp from 123.58.177.199 to me in setup keep-state
ipfw add allow tcp from any to me 80 in
ipfw add allow tcp from me 80 to any out
ipfw add allow tcp from 192.168.1.x to me 21,22 in setup keep-state
ipfw add allow tcp from me to 192.168.1.x out setup keep-state
ipfw add deny log all from any to any


路过

鸡蛋

鲜花

握手

雷人

评论 (0 个评论)

facelist doodle 涂鸦板

您需要登录后才可以评论 登录 | 立即注册

QQ|手机版|小黑屋|Archiver|五常信息网(五常论坛) ( 黑ICP备06006344号

GMT+8, 2024-3-29 01:31 , Processed in 0.035155 second(s), 21 queries .

Powered by Discuz! X3.2

© 2001-2013 Comsenz Inc.

返回顶部