一、更改ssh端口
1、更改sshd配置文件
echo Port 4000 >>/etc/ssh/sshd_config
2、关闭selinux
setenforce 0
sed -i 's/SELINUX=enforcing/SELINUX=disabled/g' /etc/selinux/config
3、配置防火墙
firewall-cmd --add-port=4000/tcp --permanent
firewall-cmd --reload
4、重启sshd服务
systemctl restart sshd
二、防火墙配置
rich rules:
rule protocol value="icmp" drop
rule family="ipv4" source address="10.78.239.0/24" port port="22" protocol="tcp" accept
rule family="ipv4" source address="10.78.180.0/24" port port="10050" protocol="tcp" accept
rule family="ipv4" source address="10.78.180.0/24" port port="10051" protocol="tcp" accept
rule family="ipv4" source address="10.78.239.0/24" port port="80" protocol="tcp" accept
rule family="ipv4" source address="10.78.239.0/24" port port="3306" protocol="tcp" accept
rule family="ipv4" source address="10.78.246.0/24" port port="3306" protocol="tcp" accept