, , ( ) , , , , , . , , , , .
, , :
iptables , IP- ( , iptables.) , (. ).- ; SSL - node . : -, ( , ,
iptables - , config iptables ), -, (, .) (, , net-snmpd v3 .. ) SSL . , ssh stunnel
iptables, (HTTP, SSH ..) (-), www1 www2 node MySQL 3306 eth0 (www1 www2 /etc/hosts, IP-.):
*filter
-A INPUT -i lo -j ACCEPT
-A INPUT -i ! lo -d 127.0.0.0/8 -j DROP
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A OUTPUT -j ACCEPT
-A INPUT -p tcp --dport 80 -j ACCEPT
-A INPUT -p tcp --dport 443 -j ACCEPT
-A INPUT -p tcp -m state --state NEW --dport 22 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type echo-request -j ACCEPT
-A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables denied: " --log-level debug
-A INPUT -j REJECT
-A FORWARD -j REJECT
-A INPUT -p tcp -s www1 -i eth0 --dport 3306 -j ACCEPT
-A INPUT -p udp -s www1 -i eth0 --dport 3306 -j ACCEPT
-A INPUT -p tcp -s www2 -i eth0 --dport 3306 -j ACCEPT
-A INPUT -p udp -s www2 -i eth0 --dport 3306 -j ACCEPT
COMMIT