์ฝ˜ํ…์ธ ๋กœ ๊ฑด๋„ˆ๋›ฐ๊ธฐ

Linux

  • Ubuntu ์„œ๋ฒ„๋ฅผ ํ•ญ์ƒ ๊นจ์–ด์žˆ๋Š” ์ƒํƒœ๋กœ ์œ ์ง€ํ•˜๋Š” ๋ฒ•
  • Nginx ์— Let’s Encrypt ์˜ SSL ์„ ๋ฐœ๊ธ‰๋ฐ›๊ณ  ์ ์šฉํ•˜๋Š” ๋ฒ•
  • Ubuntu ์—์„œ nginx, php, mariadb ๊นŒ์ง€ ์„ธํŒ…๋ฐฉ๋ฒ•
  • Ubuntu ์˜ ๋ฐฉํ™”๋ฒฝ ufw ์‚ฌ์šฉ๋ฒ•
  • Cron ์‚ฌ์šฉ๋ฒ•

Ubuntu

  • Ubuntu ์„œ๋ฒ„๋ฅผ ํ•ญ์ƒ ๊นจ์–ด์žˆ๋Š” ์ƒํƒœ๋กœ ์œ ์ง€ํ•˜๋Š” ๋ฒ•
  • Nginx ์— Let’s Encrypt ์˜ SSL ์„ ๋ฐœ๊ธ‰๋ฐ›๊ณ  ์ ์šฉํ•˜๋Š” ๋ฒ•
  • Ubuntu ์—์„œ nginx, php, mariadb ๊นŒ์ง€ ์„ธํŒ…๋ฐฉ๋ฒ•
  • Ubuntu ์˜ ๋ฐฉํ™”๋ฒฝ ufw ์‚ฌ์šฉ๋ฒ•
  • nginx ๋ฅผ ์‚ฌ์šฉ์ค‘์ธ๋ฐ ์›Œ๋“œํ”„๋ ˆ์Šค์—์„œ ๊ณ ์œ ์ฃผ์†Œ๋ฅผ ๊ธ€ ์ด๋ฆ„์œผ๋กœ ์„ค์ •ํ•˜๋ฉด 404 ์˜ค๋ฅ˜๊ฐ€ ๋‚  ๋•Œ

Nginx

  • Nginx ์— Let’s Encrypt ์˜ SSL ์„ ๋ฐœ๊ธ‰๋ฐ›๊ณ  ์ ์šฉํ•˜๋Š” ๋ฒ•
  • Ubuntu ์—์„œ nginx, php, mariadb ๊นŒ์ง€ ์„ธํŒ…๋ฐฉ๋ฒ•
  • nginx ๋ฅผ ์‚ฌ์šฉ์ค‘์ธ๋ฐ ์›Œ๋“œํ”„๋ ˆ์Šค์—์„œ ๊ณ ์œ ์ฃผ์†Œ๋ฅผ ๊ธ€ ์ด๋ฆ„์œผ๋กœ ์„ค์ •ํ•˜๋ฉด 404 ์˜ค๋ฅ˜๊ฐ€ ๋‚  ๋•Œ

Mac

  • ๋งฅ๋ถ 2019์— macOS Sequoia๋ฅผ ์žฌ์„ค์น˜(ํด๋ฆฐ ์„ค์น˜ ํฌํ•จ)ํ•˜๋Š” ๋ฐฉ๋ฒ•

Cinema

  • ์˜์ƒ ํ™”๋ฉด ๋น„์œจ / ํ•ด์ƒ๋„ ์ฐจํŠธ
View Categories
  • Home
  • Docs
  • firewalld ์‚ฌ์šฉ๋ฒ•

firewalld ์‚ฌ์šฉ๋ฒ•

3 min read


# ์„œ๋น„์Šค ์‹œ์ž‘
[root@localhost ~]# systemctl start firewalld

# ์„œ๋น„์Šค ์žฌ์‹œ์ž‘
[root@localhost ~]# systemctl restart firewalld

# ์„œ๋น„์Šค ์ค‘์ง€
[root@localhost ~]# systemctl stop firewalld

# ์„œ๋น„์Šค ๋“ฑ๋ก
[root@localhost ~]# systemctl enable firewalld

# ์„œ๋น„์Šค ์ƒํƒœ ํ™•์ธ
[root@localhost ~]# systemctl status firewalld

# firewalld ์ •์ฑ… ์ €์žฅ ๋˜๋Š” ์ ์šฉ
[root@localhost ~]# firewall-cmd --reload

# firewalld ์„ค์ •ํŒŒ์ผ ๊ฒฝ๋กœ
[root@localhost ~]# vi /etc/firewalld/firewalld.conf
firewalld ์กด(zone) ๊ด€๋ฆฌ

โ–ท ์กด(zone)์€ ๋ฐฉํ™”๋ฒฝ์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์˜์—ญ๋ณ„ ๊ทธ๋ฃน์ด๋ผ๊ณ  ๋ณด๋ฉด ๋ฉ๋‹ˆ๋‹ค. ๋ฐฉํ™”๋ฒฝ์„ ๊ธฐ์ค€์œผ๋กœ ์™ธ๋ถ€๋Š” External(์™ธ๋ถ€), ๋‚ด๋ถ€๋Š” Internal(๋‚ด๋ถ€), ์ค‘๊ฐ„ ์˜์—ญ์ธ DMZ ๋“ฑ ๋‹ค์–‘ํ•œ ์กด์œผ๋กœ ๋‚˜๋ˆ ์„œ ๊ทธ๋ฃน ๊ด€๋ฆฌ๊ฐ€ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

โ–ท firewalld ์—์„œ ๊ธฐ๋ณธ์œผ๋กœ ์ œ๊ณตํ•˜๋Š” ์กด(zone)์ด ์žˆ์œผ๋ฉฐ, ์‹ ๊ทœ ์ถ”๊ฐ€ํ•˜์—ฌ ์‚ฌ์šฉ๋„ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์•„๋ž˜ ๋‚ด์šฉ์„ ์ฐธ๊ณ ํ•˜๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค.

# ์‚ฌ์ „ ์ •์˜๋œ zone ๋ชฉ๋ก ํ™•์ธ
[root@localhost ~]# firewall-cmd --get-zones
block dmz drop external home internal public trusted work

# ๊ธฐ๋ณธ ์„ค์ • zone ํ™•์ธ
[root@localhost ~]# firewall-cmd --get-default-zone
public

# ๊ธฐ๋ณธ zone ๋ณ€๊ฒฝ
[root@localhost ~]# firewall-cmd --set-default-zone=external

# ํ˜„์žฌ ์„ค์ • ํ™•์ธ
[root@localhost ~]# firewall-cmd --list-all

# ์ „์ฒด zone ๋ชฉ๋ก ์ƒ์„ธ ํ™•์ธ
[root@localhost ~]# firewall-cmd --list-all-zones

# ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค์— ์ ์šฉ๋œ zone ๋ฆฌ์ŠคํŠธ ํ™•์ธ (๋ณ€๊ฒฝ ์ „)
[root@localhost ~]# firewall-cmd --get-active-zone
external
  interfaces: enp0s8 enp0s3

# ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค์— zone ๋ณ€๊ฒฝ
[root@localhost ~]# firewall-cmd --change-interface=enp0s3 --zone=public

# ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค์— ์ ์šฉ๋œ zone ๋ฆฌ์ŠคํŠธ ํ™•์ธ (๋ณ€๊ฒฝ ํ›„)
[root@localhost ~]# firewall-cmd --get-active-zone
external
  interfaces: enp0s8
public
  interfaces: enp0s3

# ์‹ ๊ทœ zone ์ถ”๊ฐ€
[root@localhost ~]# firewall-cmd --permanent --new-zone=test
success

# ๊ธฐ์กด zone ์‚ญ์ œ
[root@localhost ~]# firewall-cmd --permanent --delete-zone=test
success
firewalld ์„œ๋น„์Šค ๊ด€๋ฆฌ

โ–ท firewalld ์„œ๋น„์Šค๋Š” ์ž˜ ์•Œ๋ ค์ง„ ํฌํŠธ ๋˜๋Š” ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์„œ๋น„์Šค๋ฅผ ์‚ฌ์ „ ์ •์˜ํ•œ ๊ฒƒ์ž…๋‹ˆ๋‹ค. 

โ–ท firewalld ์„œ๋น„์Šค๋ฅผ ์ด์šฉํ•˜๋ฉด ssh, telnet, icmp, mysql ๋“ฑ ์ž˜ ์•Œ๋ ค์ง„ ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์— ๋Œ€ํ•ด ๋ณ„๋„ ํฌํŠธ๋กœ ์„ค์ •ํ•˜์ง€ ์•Š๊ณ  ์„œ๋น„์Šค ์ด๋ฆ„์œผ๋กœ ๊ด€๋ฆฌ๊ฐ€ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.


# ์‚ฌ์ „ ๋“ฑ๋ก๋œ ์„œ๋น„์Šค ๋ชฉ๋ก ํ™•์ธ
[root@localhost ~]# firewall-cmd --get-services

# ์‚ฌ์ „ ์ •์˜๋œ ์„œ๋น„์Šค ํŒŒ์ผ ์œ„์น˜
[root@localhost ~]# firewall-cmd --get-services

# ํŠน์ • zone์— ํ—ˆ์šฉ๋œ ์„œ๋น„์Šค ๋ฆฌ์ŠคํŠธ ํ™•์ธ (์„œ๋น„์Šค ์ถ”๊ฐ€ ์ „)
[root@localhost ~]# firewall-cmd --list-service --zone=public
cockpit dhcpv6-client ssh

# ํŠน์ • zone์— ์„œ๋น„์Šค ์ถ”๊ฐ€ (http, https, dns, telnet)
[root@localhost ~]# firewall-cmd --permanent --zone=public --add-service=http
[root@localhost ~]# firewall-cmd --permanent --zone=public --add-service=https
[root@localhost ~]# firewall-cmd --permanent --zone=public --add-service=dns
[root@localhost ~]# firewall-cmd --permanent --zone=public --add-service=telnet

# ํŠน์ • zone์— ์„œ๋น„์Šค ์‚ญ์ œ (telnet)
[root@localhost ~]# firewall-cmd --permanent --zone=public --remove-service=telnet

# ์„œ๋น„์Šค ์ถ”๊ฐ€ ํ›„ ์„œ๋น„์Šค ์ ์šฉ์„ ์œ„ํ•ด ๋ฐฉํ™”๋ฒฝ ์žฌ์‹œ์ž‘
[root@localhost ~]# firewall-cmd --reload

# ํŠน์ • zone์— ํ—ˆ์šฉ๋œ ์„œ๋น„์Šค ๋ฆฌ์ŠคํŠธ ํ™•์ธ (์„œ๋น„์Šค ์ถ”๊ฐ€ ํ›„)
[root@localhost ~]# firewall-cmd --list-service --zone=public
cockpit dhcpv6-client dns http https ssh
firealld ํฌํŠธ(port) ๊ด€๋ฆฌ
โ–ท firewalld ํฌํŠธ(port)๋Š” ์œ„์—์„œ ์„ค๋ช…ํ•œ firewalld ์„œ๋น„์Šค์—์„œ ์–ธ๊ธ‰๋˜์ง€ ์•Š์€ ์„œ๋น„์Šค์˜ ํฌํŠธ๋ฅผ ๋“ฑ๋กํ•  ๋•Œ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.


# ํ—ˆ์šฉ ํฌํŠธ ๋ฆฌ์ŠคํŠธ ํ™•์ธ (์ถ”๊ฐ€ ์ „)
[root@localhost ~]# firewall-cmd --list-port --zone=public

# ํŠน์ • ํฌํŠธ TCP 8080, 8081 ์ถ”๊ฐ€
[root@localhost ~]# firewall-cmd --permanent --zone=public --add-port=8080/tcp
[root@localhost ~]# firewall-cmd --permanent --zone=public --add-port=8081/tcp

# ํŠน์ • ํฌํŠธ TCP 8081 ์‚ญ์ œ
[root@localhost ~]# firewall-cmd --permanent --zone=public --remove-port=8081/tcp

# ํฌํŠธ ์ ์šฉ์„ ์œ„ํ•œ ๋ฐฉํ™”๋ฒฝ ์žฌ์‹œ์ž‘
[root@localhost ~]# firewall-cmd --reload

# ํ—ˆ์šฉ ํฌํŠธ ๋ฆฌ์ŠคํŠธ ํ™•์ธ (์ถ”๊ฐ€ ํ›„)
[root@localhost ~]# firewall-cmd --list-port --zone=public
8080/tcp
firewalld IP ๊ด€๋ฆฌ
โ–ท firewalld IP๋Š” ํŠน์ • IP๋‚˜ IP ๋Œ€์—ญ์„ ํ—ˆ์šฉํ•  ๋•Œ ์‚ฌ์šฉ ํ•ฉ๋‹ˆ๋‹ค.


# ํ—ˆ์šฉ IP ๋ฆฌ์ŠคํŠธ ํ™•์ธ (์ถ”๊ฐ€ ์ „)
[root@localhost ~]# firewall-cmd --list-sources --zone=public

# ํ—ˆ์šฉ IP ์ถ”๊ฐ€
[root@localhost ~]# firewall-cmd --permanent --zone=public --add-source=10.0.2.0/24
[root@localhost ~]# firewall-cmd --permanent --zone=public --add-source=10.0.3.0/24

# ํ—ˆ์šฉ IP ์‚ญ์ œ
[root@localhost ~]# firewall-cmd --permanent --zone=public --remove-source=10.0.3.0/24

# ํ—ˆ์šฉ IP ์ ์šฉ์„ ์œ„ํ•œ ๋ฐฉํ™”๋ฒฝ ์žฌ์‹œ์ž‘
[root@localhost ~]# firewall-cmd --reload

# ํ—ˆ์šฉ IP ๋ฆฌ์ŠคํŠธ ํ™•์ธ (์ถ”๊ฐ€ ํ›„)
[root@localhost ~]# firewall-cmd --list-sources --zone=public
10.0.2.0/24
firewalld ์ •์ฑ…(rule) ํ˜„ํ™ฉ ํ™•์ธ
โ–ท firewalld ์—์„œ ์ƒ์„ฑํ•œ ์ •์ฑ…(rule)์€ ์กด(zone)๋ณ„๋กœ ๊ด€๋ฆฌ๋˜๋ฉฐ, ์•„๋ž˜ ๊ฒฝ๋กœ์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 โ†’ ์ •์ฑ… ๊ฒฝ๋กœ : /etc/firewalld/zones


# firewalld zone ๊ฒฝ๋กœ ํ™•์ธ
[root@localhost ~]# ls -al /etc/firewalld/zones
total 20
drwxr-x---. 2 root root 110 Jan 10 08:29 .
drwxr-x---. 7 root root 159 Jan 10 08:25 ..
-rw-r--r--. 1 root root 304 Jan 10 07:53 external.xml
-rw-r--r--. 1 root root 328 Jan 10 07:53 external.xml.old
-rw-r--r--. 1 root root 489 Jan 10 08:28 public.xml
-rw-r--r--. 1 root root 523 Jan 10 08:28 public.xml.old
-rw-r--r--. 1 root root  54 Jan 10 07:30 test.xml.old

# public zone ์ •์ฑ… ํ™•์ธ
[root@localhost ~]# cat /etc/firewalld/zones/public.xml
firewalld ๋กœ๊น…(logging) ์„ค์ •
โ–ท firewalld ๋กœ๊น…(logging)์€ ๋ฐฉํ™”๋ฒฝ์— ์ ‘๊ทผํ•œ ๋กœ๊ทธ๋ฅผ ๋‚จ๊ธฐ๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋กœ๊น…(lgging) ์„ค์ • ๋ฐฉ๋ฒ•์€ ์•„๋ž˜์™€ ๊ฐ™์Šต๋‹ˆ๋‹ค.


# firewalld.conf์—์„œ ๋กœ๊น… ์„ค์ • ๋ณ€๊ฒฝ
[root@localhost ~]# vi /etc/firewalld/firewalld.conf
LogDenied=off
->
LogDenied=all

# ์„œ๋น„์Šค ์žฌ์‹œ์ž‘
[root@localhost ~]# systemctl restart firewalld

# ์„ค์ • ํ™•์ธ
[root@localhost ~]# firewall-cmd --get-log-denied

# ๋กœ๊ทธ ๋ณด๊ธฐ
[root@localhost ~]# dmesg | grep -i REJECT

# ๋กœ๊ทธ ํŒŒ์ผ ์ƒ์„ฑ ํ›„ ๋กœ๊น… ์„ค์ • (์‹ ๊ทœ ํŒŒ์ผ ์ƒ์„ฑ ํ›„ ์•„๋ž˜ ๋‚ด์šฉ ์ถ”๊ฐ€)
[root@localhost ~]# vi /etc/rsyslog.d/firewalld-droppd.conf

:msg,contains,"_DROP" /var/log/firewalld-droppd.log
:msg,contains,"_REJECT" /var/log/firewalld-droppd.log
& stop

# rsyslog ์„œ๋น„์Šค ์žฌ์‹œ์ž‘
[root@localhost ~]# systemctl restart rsyslog.service

# deny log ํ™•์ธ
[root@localhost ~]# tail -f /etc/firewalld-droppd.log

What are your Feelings

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Still stuck? How can we help?

How can we help?

Updated on 2025-02-09

Powered by BetterDocs

๋‹ต๊ธ€ ๋‚จ๊ธฐ๊ธฐ ์‘๋‹ต ์ทจ์†Œ

์ด๋ฉ”์ผ ์ฃผ์†Œ๋Š” ๊ณต๊ฐœ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ํ•„์ˆ˜ ํ•„๋“œ๋Š” *๋กœ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค