[root@centos001 ~]# cd /etc/sysconfig/network-scripts/ [root@centos001 network-scripts]# ls ifcfg-e ifdown-isdn ifup-bnep ifup-routes ifcfg-ens ifdown-post ifup-eth ifup-sit ifcfg-ens33 ifdown-ppp ifup-ib ifup-Team ifcfg-lo ifdown-routes ifup-ippp ifup-TeamPort ifdown ifdown-sit ifup-ipv6 ifup-tunnel ifdown-bnep ifdown-Team ifup-isdn ifup-wireless ifdown-eth ifdown-TeamPort ifup-plip init.ipv6-global ifdown-ib ifdown-tunnel ifup-plusb network-functions ifdown-ippp ifup ifup-post network-functions-ipv6 ifdown-ipv6 ifup-aliases ifup-ppp [root@centos001 network-scripts]# cp ifcfg-ens33 ifcfg-ens33\:0 // 斜槓是爲了給冒號轉義 [root@centos001 network-scripts]# vi !$ vi ifcfg-ens33\:0 [root@centos001 network-scripts]# ifdown ens33 && ifup ens33 成功斷開設備 'ens33'。 鏈接已成功激活(D-Bus 活動路徑:/org/freedesktop/NetworkManager/ActiveConnection/3) [root@centos001 network-scripts]# ifconfig ens33: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500 inet 192.168.10.120 netmask 255.255.255.0 broadcast 192.168.10.255 inet6 fe80::20c:29ff:fe34:4a63 prefixlen 64 scopeid 0x20<link> ether 00:0c:29:34:4a:63 txqueuelen 1000 (Ethernet) RX packets 687 bytes 61191 (59.7 KiB) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 547 bytes 55264 (53.9 KiB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0 ens33:0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500 inet 192.168.10.129 netmask 255.255.255.0 broadcast 192.168.10.255
[root@centos001 network-scripts]# mii-tool ens33 ens33: negotiated 1000baseT-FD flow-control, link ok
[root@centos001 ~]# systemctl disable firewalld Removed symlink /etc/systemd/system/dbus-org.fedoraproject.FirewallD1.service. Removed symlink /etc/systemd/system/basic.target.wants/firewalld.service. [root@centos001 ~]# systemctl stop firewalld [root@centos001 ~]# yum install -y iptables-services [root@centos001 ~]# systemctl start iptables
iptables -A INPUT -s 192.168.188.1 -p tcp --sport 1234 -d 192.168.188.128 --dport 80 -j DROP
iptables -I/-A/-D INPUT -s 1.1.1.1 -j DROP iptables -I INPUT -s 192.168.1.0/24 -i eth0 -j ACCEPT
iptables -nvL --line-numbers iptables -D INPUT 1
iptables -P INPUT DROP
1.selinux教程 http://os.51cto.com/art/201209/355490.htm
2.selinux pdf電子書 http://pan.baidu.com/s/1jGGdExKhtml