logo NodeSeekbeta

动态IP更新防火墙脚本 监听DDNS域名更新防火墙

使用场景

远程登录服务器/后台,远离SSH爆破,陌生人进入房间等等......

使用方法

首先你得是个公网IPV4/IPV6才行,然后准备一个DDNS域名,使用A,AAAA记录不要使用CNAME记录,一个DNS记录只能有一个IPV4和IPV6
使用crontab创建开机任务就完事了
要同时监听多个域名就换个名字再创建个xxx.sh文件就ok了
在这之前你还得干一件最重要的事,那就是开启防火墙并禁止所有入站,在禁止所有入站并允许你的IP访问指定端口之前别退出SSH哟,否则你就得哭了
你可以通过这两条其中一条命令来允许你的IP访问所有端口

ufw版 ufw allow from 你的IP to any

iptables版

#!/bin/bash

LOG_FILE="iptables.log"
DOMAIN="ddns.com"
PORTS="54321,12345"
POLICY="ACCEPT" # 默认为允许

update_iptables_rule() {
    local new_ipv4
    local new_ipv6

    new_ipv4=$(dig +short $DOMAIN)
    new_ipv6=$(dig +short AAAA $DOMAIN)

    last_ipv4=$(cat $IP_FILE | grep "IPv4" | cut -d ' ' -f 2)
    last_ipv6=$(cat $IP_FILE | grep "IPv6" | cut -d ' ' -f 2)

    IFS=',' read -ra port_array <<< "$PORTS"

    for port in "${port_array[@]}"; do
        rule_name="$DOMAIN"
        if [ -n "$new_ipv4" ]; then
            if [ "$new_ipv4" != "$last_ipv4" ]; then
                iptables -D INPUT -s $last_ipv4 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
                iptables -A INPUT -s $new_ipv4 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
                echo "$(date +"%Y-%m-%d %T") - Updated IPv4 rule: $POLICY $new_ipv4 accessing port $port" >> $LOG_FILE
            fi
        fi

        if [ -n "$new_ipv6" ]; then
            if [ "$new_ipv6" != "$last_ipv6" ]; then
                ip6tables -D INPUT -s $last_ipv6 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
                ip6tables -A INPUT -s $new_ipv6 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
                echo "$(date +"%Y-%m-%d %T") - Updated IPv6 rule: $POLICY $new_ipv6 accessing port $port" >> $LOG_FILE
            fi
        fi
    done
}

add_initial_iptables_rule() {
    local new_ipv4
    local new_ipv6

    new_ipv4=$(dig +short $DOMAIN)
    new_ipv6=$(dig +short AAAA $DOMAIN)

    IFS=',' read -ra port_array <<< "$PORTS"

    for port in "${port_array[@]}"; do
        rule_name="$DOMAIN"
        if [ -n "$new_ipv4" ]; then
            if ! iptables -C INPUT -s $new_ipv4 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name" &>/dev/null; then
                iptables -A INPUT -s $new_ipv4 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
                echo "$(date +"%Y-%m-%d %T") - Added initial IPv4 rule: $POLICY $new_ipv4 accessing port $port" >> $LOG_FILE
            fi
        fi

        if [ -n "$new_ipv6" ]; then
            if ! ip6tables -C INPUT -s $new_ipv6 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name" &>/dev/null; then
                ip6tables -A INPUT -s $new_ipv6 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
                echo "$(date +"%Y-%m-%d %T") - Added initial IPv6 rule: $POLICY $new_ipv6 accessing port $port" >> $LOG_FILE
            fi
        fi
    done
}

add_initial_iptables_rule

while true; do
    update_iptables_rule
    sleep 300 #循环间隔
done

UFW版

#!/bin/bash

LOG_FILE="ufw.log"
DOMAIN="ddns.net"
PORTS="54321,12345"
POLICY="ALLOW" # 默认为允许

update_ufw_rule() {
    local new_ipv4
    local new_ipv6

    new_ipv4=$(dig +short $DOMAIN)
    new_ipv6=$(dig +short AAAA $DOMAIN)

    IFS=',' read -ra port_array <<< "$PORTS"

    for port in "${port_array[@]}"; do
        rule_name="$DOMAIN"
        if [ -n "$new_ipv4" ]; then
            ufw delete allow proto tcp from any to any port $port comment "$rule_name"
            ufw allow proto tcp from $new_ipv4 to any port $port comment "$rule_name"
            echo "$(date +"%Y-%m-%d %T") - Updated IPv4 rule: allow $new_ipv4 access to port $port" >> $LOG_FILE
        fi

        if [ -n "$new_ipv6" ]; then
            ufw delete allow proto tcp from any to any port $port comment "$rule_name"
            ufw allow proto tcp from $new_ipv6 to any port $port comment "$rule_name"
            echo "$(date +"%Y-%m-%d %T") - Updated IPv6 rule: allow $new_ipv6 access to port $port" >> $LOG_FILE
        fi
    done
}

add_initial_ufw_rule() {
    local new_ipv4
    local new_ipv6

    new_ipv4=$(dig +short $DOMAIN)
    new_ipv6=$(dig +short AAAA $DOMAIN)

    IFS=',' read -ra port_array <<< "$PORTS"

    for port in "${port_array[@]}"; do
        rule_name="$DOMAIN"
        if [ -n "$new_ipv4" ]; then
            ufw allow proto tcp from $new_ipv4 to any port $port comment "$rule_name"
            echo "$(date +"%Y-%m-%d %T") - Added initial IPv4 rule: allow $new_ipv4 access to port $port" >> $LOG_FILE
        fi

        if [ -n "$new_ipv6" ]; then
            ufw allow proto tcp from $new_ipv6 to any port $port comment "$rule_name"
            echo "$(date +"%Y-%m-%d %T") - Added initial IPv6 rule: allow $new_ipv6 access to port $port" >> $LOG_FILE
        fi
    done
}

add_initial_ufw_rule

while true; do
    update_ufw_rule
    sleep 300 # 检查间隔
done
  • 收藏了

  • ufw和iptables哪个hao好呢?两者有什么区别?

  • @a1109918523 #2 iptables是底层,ufw是建立在iptables上的前端,简单的需求用ufw就行了,不过ufw是默认白名单,你还要配置其他的访问策略

你好啊,陌生人!

我的朋友,看起来你是新来的,如果想参与到讨论中,点击下面的按钮!

📈用户数目📈

目前论坛共有72225位seeker

🎉欢迎新用户🎉