Потом поразмыслил, и прикинул, что раз вы из соображений безопасности по дефолту даже
sshd отключаете от работы, то работа без файрвола тем более будет плохим решением.
Поэтому установил только один
iptables и предложил ему такой многократно провереный в боях с хакерами простенький конфиг:
#
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 5900 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
Запускаю файрвол.
Но не тут то было - он ругается -
service iptables start
Job for iptables.service failed because the control process exited with error code.
See "systemctl status iptables.service" and "journalctl -xe" for details.
Иду смотреть, что ему не нравится -
Спойлер
systemctl status iptables.service
● iptables.service - IPv4 firewall with iptables
Loaded: loaded (/lib/systemd/system/iptables.service; disabled; vendor preset: disabled)
Active: failed (Result: exit-code) since Вт 2017-09-26 02:27:56 EEST; 41s ago
Process: 4520 ExecStart=/etc/init.d/iptables start (code=exited, status=1/FAILURE)
Main PID: 4520 (code=exited, status=1/FAILURE)
сен 26 02:27:56 host-122.localdomain systemd[1]: Starting IPv4 firewall with iptables...
сен 26 02:27:56 host-122.localdomain iptables-restore[4529]: iptables-restore: line 1 failed
сен 26 02:27:56 host-122.localdomain iptables[4520]: Applying iptables firewall rules: iptables-rest
сен 26 02:27:56 host-122.localdomain iptables[4531]: Applying iptables firewall rules: failed
сен 26 02:27:56 host-122.localdomain iptables[4520]: [FAILED]
сен 26 02:27:56 host-122.localdomain systemd[1]: iptables.service: Main process exited, code=exited,
сен 26 02:27:56 host-122.localdomain systemd[1]: Failed to start IPv4 firewall with iptables.
сен 26 02:27:56 host-122.localdomain systemd[1]: iptables.service: Unit entered failed state.
сен 26 02:27:56 host-122.localdomain systemd[1]: iptables.service: Failed with result 'exit-code'.
и
Спойлер
journalctl -xe
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
--
-- Произошел сбой юнита iptables.service.
--
-- Результат: failed.
сен 26 02:25:05 host-122.localdomain systemd[1]: iptables.service: Unit entered failed state.
сен 26 02:25:05 host-122.localdomain systemd[1]: iptables.service: Failed with result 'exit-code'.
сен 26 02:25:17 host-122.localdomain ntpd[537]: reply from 193.25.222.240: offset -0.040139 delay 0.
сен 26 02:25:18 host-122.localdomain ntpd[537]: reply from 66.135.44.92: offset -0.034575 delay 0.17
сен 26 02:25:20 host-122.localdomain ntpd[537]: reply from 80.240.216.155: offset -0.041541 delay 0.
сен 26 02:25:44 host-122.localdomain ntpd[537]: reply from 83.162.251.163: offset -0.035472 delay 0.
сен 26 02:27:49 host-122.localdomain ntpd[537]: reply from 66.135.44.92: offset -0.035497 delay 0.17
сен 26 02:27:56 host-122.localdomain systemd[1]: Starting IPv4 firewall with iptables...
-- Subject: Начинается запуск юнита iptables.service
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
--
-- Начат процесс запуска юнита iptables.service.
сен 26 02:27:56 host-122.localdomain iptables-restore[4529]: iptables-restore: line 1 failed
сен 26 02:27:56 host-122.localdomain iptables[4520]: Applying iptables firewall rules: iptables-rest
сен 26 02:27:56 host-122.localdomain iptables[4531]: Applying iptables firewall rules: failed
сен 26 02:27:56 host-122.localdomain iptables[4520]: [FAILED]
сен 26 02:27:56 host-122.localdomain systemd[1]: iptables.service: Main process exited, code=exited,
сен 26 02:27:56 host-122.localdomain systemd[1]: Failed to start IPv4 firewall with iptables.
-- Subject: Ошибка юнита iptables.service
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
--
-- Произошел сбой юнита iptables.service.
--
-- Результат: failed.
сен 26 02:27:56 host-122.localdomain systemd[1]: iptables.service: Unit entered failed state.
сен 26 02:27:56 host-122.localdomain systemd[1]: iptables.service: Failed with result 'exit-code'.
сен 26 02:27:59 host-122.localdomain ntpd[537]: reply from 80.240.216.155: offset -0.041290 delay 0.
сен 26 02:28:00 host-122.localdomain ntpd[537]: reply from 193.25.222.240: offset -0.036514 delay 0.
сен 26 02:28:23 host-122.localdomain ntpd[537]: reply from 83.162.251.163: offset -0.036524 delay 0.
сен 26 02:29:39 host-122.localdomain su[4290]: pam_tcb(su:session): Session closed for root
сен 26 02:29:43 host-122.localdomain su[4541]: pam_tcb(su:auth): Authentication passed for root from
сен 26 02:29:43 host-122.localdomain su[4541]: pam_tcb(su:session): Session opened for root by somov(
Сдается мне, это уже не по моей линии, а разработчиков, не?