Home
Today : 2026-06-15 13:21:51
 
ikjinan.kro.kr
local IP address is: 216.73.217.46  public IP address is: 112.175.185.138 [ LOG IN ]  [ SIGN UP]
Bulletin Board(to Db)
mpm์ด์ฃผ์‚ฌ๋ชฉ  
์ด์žฌ๋ช…  
Science  
Island-monkey-disaster  
Great-korea  
health  
k-culture  
office-file  
Catholic  
freeboard  
windog  
linux-bsd  
apm  
linux-bsd
Title ๋ฐฉํ™”๋ฒฝ ์„ค์ • ufw firewall
File
Name admin | 2026-06-07 | Views: 1
Content

๋„ค, ๋ฐ์Šคํฌํ†ฑ ์ „์šฉ์ด๋ผ๋ฉด ๊ธฐ๋ณธ์ ์œผ๋กœ ๋“ค์–ด์˜ค๋Š” ์—ฐ๊ฒฐ(Inbound)์€ ์ „๋ถ€ ์ฐจ๋‹จ, ๋‚˜๊ฐ€๋Š” ์—ฐ๊ฒฐ(Outbound)์€ ํ—ˆ์šฉ์œผ๋กœ ์„ค์ •ํ•˜๋Š” ๊ฒƒ์ด ๊ฐ€์žฅ ๋ฌด๋‚œํ•ฉ๋‹ˆ๋‹ค.

Ubuntu/HamoniKR ๊ณ„์—ด์ด๋ฉด ๊ฐ€์žฅ ์‰ฌ์šด ๋ฐฉ๋ฒ•์€ UFW(Uncomplicated Firewall) ์ž…๋‹ˆ๋‹ค.

๋จผ์ € ์„ค์น˜ ์—ฌ๋ถ€ ํ™•์ธ:

ย  sudo ufw status

๋งŒ์•ฝ ์—†์œผ๋ฉด ์„ค์น˜:

ย  sudo apt update sudo apt install ufw 1. ๊ธฐ๋ณธ ์ •์ฑ… ์„ค์ •

๋“ค์–ด์˜ค๋Š” ์—ฐ๊ฒฐ ์ „๋ถ€ ์ฐจ๋‹จ:

ย  sudo ufw default deny incoming

๋‚˜๊ฐ€๋Š” ์—ฐ๊ฒฐ ์ „๋ถ€ ํ—ˆ์šฉ:

ย  sudo ufw default allow outgoing 2. ๋ฐฉํ™”๋ฒฝ ํ™œ์„ฑํ™” ย  sudo ufw enable

ํ™•์ธ:

ย  sudo ufw status verbose

์ •์ƒ์ด๋ผ๋ฉด ๋น„์Šทํ•˜๊ฒŒ ๋‚˜์˜ต๋‹ˆ๋‹ค.

ย  Default: deny (incoming), allow (outgoing) 3. SSH ์‚ฌ์šฉ ์—ฌ๋ถ€ ํ™•์ธ

๋งŒ์•ฝ ์ด ์ปดํ“จํ„ฐ์— SSH ์„œ๋ฒ„๋ฅผ ์„ค์น˜ํ•˜์ง€ ์•Š์•˜๋‹ค๋ฉด ์ถ”๊ฐ€ ์„ค์ •์€ ํ•„์š” ์—†์Šต๋‹ˆ๋‹ค.

ํ™•์ธ:

ย  sudo ss -tulnp

๋˜๋Š”

ย  systemctl status ssh

SSH ์„œ๋ฒ„๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š๋Š”๋‹ค๋ฉด ํฌํŠธ 22๋„ ์ž๋™์œผ๋กœ ๋ง‰ํ˜€ ์žˆ์Šต๋‹ˆ๋‹ค.

4. ํ˜„์žฌ ์ƒํƒœ์—์„œ ํ—ˆ์šฉ๋˜๋Š” ๊ฒƒ

์ด ์„ค์ •์ด๋ฉด:

โœ… ์›น ๋ธŒ๋ผ์šฐ์ง• (HTTP/HTTPS)

ย  80/tcp 443/tcp

โœ… DNS ์กฐํšŒ

ย  53/tcp 53/udp

โœ… ์‹œ์Šคํ…œ ์—…๋ฐ์ดํŠธ

ย  apt

โœ… NTP ์‹œ๊ฐ„ ๋™๊ธฐํ™”

ย  123/udp

๋ชจ๋‘ ์ •์ƒ ๋™์ž‘ํ•ฉ๋‹ˆ๋‹ค.

์™œ๋ƒํ•˜๋ฉด ๋‚˜๊ฐ€๋Š” ์—ฐ๊ฒฐ์€ ํ—ˆ์šฉ๋˜์–ด ์žˆ๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.

5. GUI ์„ค์น˜ (์„ ํƒ)

HamoniKR์—์„œ๋Š” GUI๊ฐ€ ๋” ํŽธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ย  sudo apt install gufw

์‹คํ–‰:

ย  gufw

์—ฌ๊ธฐ์„œ๋„

  • Incoming : Deny
  • Outgoing : Allow

๋กœ ์„ค์ • ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

6. ์ถ”์ฒœ ํ™•์ธ

์„ค์ • ํ›„:

ย  sudo ufw status numbered

๊ฒฐ๊ณผ๊ฐ€ ๋Œ€๋žต:

ย  Status: active Default: deny (incoming), allow (outgoing)

์ด๋ฉด ๋ฉ๋‹ˆ๋‹ค.

์‚ฌ์šฉ์ž๋‹˜์ฒ˜๋Ÿผ

  • ์›น์„œํ•‘
  • ๋ฉ”์ผ ํ™•์ธ
  • SSH ํด๋ผ์ด์–ธํŠธ๋กœ ์„œ๋ฒ„ ์ ‘์†
  • rsync๋กœ ์„œ๋ฒ„ ๋ฐฑ์—…

์šฉ๋„๋ผ๋ฉด,

ย  Incoming : DENY Outgoing : ALLOW

๋งŒ ์„ค์ •ํ•ด๋„ ์ƒ๋‹นํžˆ ์•ˆ์ „ํ•œ ๋ฐ์Šคํฌํ†ฑ ํ™˜๊ฒฝ์ด ๋ฉ๋‹ˆ๋‹ค.

God Bless & Peace Be with You
Visitors For today : ( 9 )
2026-06-15