使用场景
远程登录服务器/后台,远离SSH爆破,陌生人进入房间等等......
使用方法
首先你得是个公网IPV4/IPV6才行,然后准备一个DDNS域名,使用A,AAAA记录不要使用CNAME记录,一个DNS记录只能有一个IPV4和IPV6
使用crontab创建开机任务就完事了
要同时监听多个域名就换个名字再创建个xxx.sh文件就ok了
在这之前你还得干一件最重要的事,那就是开启防火墙并禁止所有入站,在禁止所有入站并允许你的IP访问指定端口之前别退出SSH哟,否则你就得哭了
你可以通过这两条其中一条命令来允许你的IP访问所有端口
ufw版 ufw allow from 你的IP to any
iptables版
#!/bin/bash
LOG_FILE="iptables.log"
DOMAIN="ddns.com"
PORTS="54321,12345"
POLICY="ACCEPT" # 默认为允许
update_iptables_rule() {
local new_ipv4
local new_ipv6
new_ipv4=$(dig +short $DOMAIN)
new_ipv6=$(dig +short AAAA $DOMAIN)
last_ipv4=$(cat $IP_FILE | grep "IPv4" | cut -d ' ' -f 2)
last_ipv6=$(cat $IP_FILE | grep "IPv6" | cut -d ' ' -f 2)
IFS=',' read -ra port_array <<< "$PORTS"
for port in "${port_array[@]}"; do
rule_name="$DOMAIN"
if [ -n "$new_ipv4" ]; then
if [ "$new_ipv4" != "$last_ipv4" ]; then
iptables -D INPUT -s $last_ipv4 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
iptables -A INPUT -s $new_ipv4 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
echo "$(date +"%Y-%m-%d %T") - Updated IPv4 rule: $POLICY $new_ipv4 accessing port $port" >> $LOG_FILE
fi
fi
if [ -n "$new_ipv6" ]; then
if [ "$new_ipv6" != "$last_ipv6" ]; then
ip6tables -D INPUT -s $last_ipv6 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
ip6tables -A INPUT -s $new_ipv6 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
echo "$(date +"%Y-%m-%d %T") - Updated IPv6 rule: $POLICY $new_ipv6 accessing port $port" >> $LOG_FILE
fi
fi
done
}
add_initial_iptables_rule() {
local new_ipv4
local new_ipv6
new_ipv4=$(dig +short $DOMAIN)
new_ipv6=$(dig +short AAAA $DOMAIN)
IFS=',' read -ra port_array <<< "$PORTS"
for port in "${port_array[@]}"; do
rule_name="$DOMAIN"
if [ -n "$new_ipv4" ]; then
if ! iptables -C INPUT -s $new_ipv4 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name" &>/dev/null; then
iptables -A INPUT -s $new_ipv4 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
echo "$(date +"%Y-%m-%d %T") - Added initial IPv4 rule: $POLICY $new_ipv4 accessing port $port" >> $LOG_FILE
fi
fi
if [ -n "$new_ipv6" ]; then
if ! ip6tables -C INPUT -s $new_ipv6 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name" &>/dev/null; then
ip6tables -A INPUT -s $new_ipv6 -p tcp --dport $port -j $POLICY -m comment --comment "$rule_name"
echo "$(date +"%Y-%m-%d %T") - Added initial IPv6 rule: $POLICY $new_ipv6 accessing port $port" >> $LOG_FILE
fi
fi
done
}
add_initial_iptables_rule
while true; do
update_iptables_rule
sleep 300 #循环间隔
done
UFW版
#!/bin/bash
LOG_FILE="ufw.log"
DOMAIN="ddns.net"
PORTS="54321,12345"
POLICY="ALLOW" # 默认为允许
update_ufw_rule() {
local new_ipv4
local new_ipv6
new_ipv4=$(dig +short $DOMAIN)
new_ipv6=$(dig +short AAAA $DOMAIN)
IFS=',' read -ra port_array <<< "$PORTS"
for port in "${port_array[@]}"; do
rule_name="$DOMAIN"
if [ -n "$new_ipv4" ]; then
ufw delete allow proto tcp from any to any port $port comment "$rule_name"
ufw allow proto tcp from $new_ipv4 to any port $port comment "$rule_name"
echo "$(date +"%Y-%m-%d %T") - Updated IPv4 rule: allow $new_ipv4 access to port $port" >> $LOG_FILE
fi
if [ -n "$new_ipv6" ]; then
ufw delete allow proto tcp from any to any port $port comment "$rule_name"
ufw allow proto tcp from $new_ipv6 to any port $port comment "$rule_name"
echo "$(date +"%Y-%m-%d %T") - Updated IPv6 rule: allow $new_ipv6 access to port $port" >> $LOG_FILE
fi
done
}
add_initial_ufw_rule() {
local new_ipv4
local new_ipv6
new_ipv4=$(dig +short $DOMAIN)
new_ipv6=$(dig +short AAAA $DOMAIN)
IFS=',' read -ra port_array <<< "$PORTS"
for port in "${port_array[@]}"; do
rule_name="$DOMAIN"
if [ -n "$new_ipv4" ]; then
ufw allow proto tcp from $new_ipv4 to any port $port comment "$rule_name"
echo "$(date +"%Y-%m-%d %T") - Added initial IPv4 rule: allow $new_ipv4 access to port $port" >> $LOG_FILE
fi
if [ -n "$new_ipv6" ]; then
ufw allow proto tcp from $new_ipv6 to any port $port comment "$rule_name"
echo "$(date +"%Y-%m-%d %T") - Added initial IPv6 rule: allow $new_ipv6 access to port $port" >> $LOG_FILE
fi
done
}
add_initial_ufw_rule
while true; do
update_ufw_rule
sleep 300 # 检查间隔
done
收藏了
ufw和iptables哪个hao好呢?两者有什么区别?
@a1109918523 #2 iptables是底层,ufw是建立在iptables上的前端,简单的需求用ufw就行了,不过ufw是默认白名单,你还要配置其他的访问策略