Skill 详情
firewall-config
Relevant DevSecOps infrastructure specialty, but narrowly focused on firewall configuration.
使用前先检查
自动化审核只检查相关性,不代表安全审查或推荐。使用前请阅读来源中的说明。
SKILL.md
这段内容是审核时保存的快照。外部来源才是完整且最新的版本。
--- name: firewall-config description: Configure iptables, nftables, and cloud firewalls. Implement network segmentation and traffic filtering. Use when securing network perimeters or implementing security zones. license: MIT metadata: author: devops-skills version: "1.0" --- # Firewall Configuration Configure host-based and cloud firewalls for network security. ## When to Use This Skill Use this skill when: - Setting up a new server and need to restrict network access - Implementing network segmentation between application tiers - Configuring cloud security groups for AWS, GCP, or Azure resources - Migrating from iptables to nftables - Auditing existing firewall rules for compliance - Responding to a security incident requiring emergency network blocks ## Prerequisites - Root or sudo access on Linux hosts - AWS CLI configured for cloud security groups - Understanding of TCP/IP, ports, and protocols - Network diagram showing required traffic flows ## iptables ### Basic Setup with Default Deny ```bash # Flush existing rules iptables -F iptables -X iptables -t nat -F iptables -t mangle -F # Default policies - deny all inbound, allow outbound iptables -P INPUT DROP iptables -P FORWARD DROP iptables -P OUTPUT ACCEPT # Allow established connections iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT # Allow loopback iptables -A INPUT -i lo -j ACCEPT # Drop invalid packets iptables -A INPUT -m conntrack --ctstate INVALID -j DROP # Allow SSH (restrict to management subnet) iptables -A INPUT -p tcp --dport 22 -s 10.0.100.0/24 -j ACCEPT # Allow HTTP/HTTPS from anywhere iptables -A INPUT -p tcp -m multiport --dports 80,443 -j ACCEPT # Allow ICMP (ping) with rate limiting iptables -A INPUT -p icmp --icmp-type echo-request -m limit --limit 1/s --limit-burst 4 -j ACCEPT # Log dropped packets (rate limited to avoid log flooding) iptables -A INPUT -m limit --limit 5/min -j LOG --log-prefix "IPTABLES-DROP: " --log-level 4 # Save rules (Debian/Ubuntu) iptables-save > /etc/iptables/rules.v4 ip6tables-save > /etc/iptables/rules.v6 ``` ### Anti-DDoS Rules ```bash # SYN flood protection iptables -A INPUT -p tcp --syn -m limit --limit 25/s --limit-burst 50 -j ACCEPT iptables -A INPUT -p tcp --syn -j DROP # Limit new connections per source IP iptables -A INPUT -p tcp --dport 80 -m connlimit --connlimit-above 50 -j REJECT # Block port scanning (detect TCP flags abuse) iptables -A INPUT -p tcp --tcp-flags ALL NONE -j DROP iptables -A INPUT -p tcp --tcp-flags ALL ALL -j DROP iptables -A INPUT -p tcp --tcp-flags ALL FIN,URG,PSH -j DROP iptables -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -j DROP iptables -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j DROP ``` ### Application-Specific Rules ```bash # Web server with database backend # Allow app servers to reach database (port 5432) iptables -A INPUT -p tcp --dport 5432 -s 10.0.1.0/24 -j ACCEPT # Allow monitoring (Prometheus node exporter) iptables -A INPUT -p tcp --dport 9100 -s 10.0.200.0/24 -j ACCEPT # DNS resolution iptables -A INPUT -p udp --sport 53 -j ACCEPT iptables -A INPUT -p tcp --sport 53 -j ACCEPT # NTP iptables -A INPUT -p udp --sport 123 -j ACCEPT # Block specific IP (incident response) iptables -I INPUT 1 -s 203.0.113.50 -j DROP ``` ## UFW (Uncomplicated Firewall) ```bash # Enable UFW with default deny ufw default deny incoming ufw default allow outgoing ufw enable # Allow SSH from management network ufw allow from 10.0.100.0/24 to any port 22 proto tcp # Allow HTTP/HTTPS ufw allow 80/tcp ufw allow 443/tcp # Allow specific application profile ufw allow 'Nginx Full' # Rate limit SSH (max 6 connections in 30 seconds) ufw limit ssh # Allow port range ufw allow 8000:8080/tcp # Deny specific IP ufw deny from 203.0.113.50 # Check status ufw status verbose ufw status numbered # Delete a rule by number ufw delete 3 # Application profiles ufw app list ufw app info 'Nginx Full' ``` ## nftables ### Complete Server Configuration ```bash在 GitHub 阅读完整来源 (打开外部页面)