浏览代码

Merge pull request #51 from Len-PGH/master

update fail2ban rules
FusionPBX 9 年之前
父节点
当前提交
efa5161ff6
共有 2 个文件被更改,包括 19 次插入13 次删除
  1. 1 4
      source/getting_started/post_installation.rst
  2. 18 9
      source/iptables.rst

+ 1 - 4
source/getting_started/post_installation.rst

@@ -1,11 +1,8 @@
 *****************
 Post Installation
 *****************
-.. image:: _static/images/logo.png
-        :width: 130pt
-        :align: center
-        :height: 76.5pt
 
+|
 
 After The install is complete please keep the login details from the install in a safe and secure place.  Just in case you need them later.
 

+ 18 - 9
source/iptables1.rst → source/iptables.rst

@@ -4,15 +4,15 @@
    :target: https://github.com/fusionpbx/fusionpbx-docs
 
 Basic Rules
-===========
+~~~~~~~~~~~~
 
 | ``iptables -A INPUT -i lo -j ACCEPT``
 | ``iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT``
 | ``iptables -A INPUT -p tcp --dport 22 -j ACCEPT``
 | ``iptables -A INPUT -p tcp --dport 80 -j ACCEPT``
 | ``iptables -A INPUT -p tcp --dport 443 -j ACCEPT``
-| ``iptables -A INPUT -p tcp --dport 5060 -j ACCEPT``
-| ``iptables -A INPUT -p udp --dport 5060 -j ACCEPT``
+| ``iptables -A INPUT -p tcp --dport 5060:5069 -j ACCEPT``
+| ``iptables -A INPUT -p udp --dport 5060:5069 -j ACCEPT``
 | ``iptables -A INPUT -p tcp --dport 5080 -j ACCEPT``
 | ``iptables -A INPUT -p udp --dport 5080 -j ACCEPT``
 | ``iptables -A INPUT -p udp --dport 16384:32768 -j ACCEPT``
@@ -22,8 +22,9 @@ Basic Rules
 | ``iptables -P FORWARD DROP``
 | ``iptables -P OUTPUT ACCEPT``
 
+
 Friendly Scanner
-================
+~~~~~~~~~~~~~~~~~
 
 Rules to block not so friendly scanner
 
@@ -33,29 +34,37 @@ Rules to block not so friendly scanner
 | ``iptables -I INPUT -j DROP -p udp --dport 5080 -m string --string "friendly-scanner" --algo bm``
 
 Show iptable rules
-==================
+~~~~~~~~~~~~~~~~~~~
 
 | ``sudo iptables -L -v``
 
 Show line numbers
-=================
+~~~~~~~~~~~~~~~~~~
 
 | ``iptables -L -v --line-numbers``
 
 Delete a line
-=============
+~~~~~~~~~~~~~~
 
 Delete line 2
 
+Flush out iptables
+~~~~~~~~~~~~~~~~~~~
+
+iptables -P INPUT ACCEPT
+iptables -P FORWARD ACCEPT
+iptables -P OUTPUT ACCEPT
+iptables -F
+
 | ``iptables -D INPUT 2``
 
 Block IP address
-================
+~~~~~~~~~~~~~~~~~
 
 | ``iptables -I INPUT -s 62.210.245.132 -j DROP``
 
 Save Changes
-============
+~~~~~~~~~~~~~
 
 Debian & Ubuntu