码迷,mamicode.com
首页 > 其他好文 > 详细

day RHCE

时间:2017-09-30 13:16:30      阅读:176      评论:0      收藏:0      [点我收藏+]

标签:界面   nbsp   name   goto   scripts   sel   ane   5.0   eth0   

1、配置SELINUX

server
[root@server0 ~]# getenforce 
Enforcing
[root@server0 ~]# vim /etc/sysconfig/selinux 
SELINUX=enforcing

desktop
[root@desktop0 ~]# getenforce
[root@desktop0 ~]# vim /etc/sysconfig/selinux 
SELINUX=enforcing

 

2、配置防火墙对SSH的限制

server
[root@server0 ~]# firewall-cmd --list-all

[root@server0 ~]# firewall-cmd --permanent --add-service=ssh

[root@server0 ~]# firewall-cmd --permanent --add-rich-rule="rule family=ipv4 source address=172.25.0.0/24 service name=ssh accept"
[root@server0 ~]# firewall-cmd --permanent --add-rich-rule="rule family=ipv4 source address=172.17.10.0/24 service name=ssh reject"

[root@server0 ~]# firewall-cmd --reload 
[root@server0 ~]# firewall-cmd --list-all

  

desktop
[root@desktop0 ~]# firewall-cmd --list-all

[root@desktop0 ~]# firewall-cmd --permanent --add-service=ssh

[root@desktop0 ~]# firewall-cmd --permanent --add-rich-rule="rule family=ipv4 source address=172.25.0.0/24 service name=ssh accept"
[root@desktop0 ~]# firewall-cmd --permanent --add-rich-rule="rule family=ipv4 source address=172.17.10.0/24 service name=ssh reject"

[root@desktop0 ~]# firewall-cmd --reload 
[root@desktop0 ~]# firewall-cmd --list-all

  

 

3、配置IPv6地址

  另:图形界面  # nmtui

  另:图形界面2

  另:修改配置文件,重启服务(不推荐)

[root@server0 ~]# vim /etc/sysconfig/network-scripts/ifcfg-eth0 
[root@server0 ~]# systemctl restart network

  

  另:goto ipv6

server
[root@server0 ~]# nmcli conn show
[root@server0 ~]# nmcli device show eth0
[root@server0 ~]# nmcli conn edit eth0 
nmcli> goto ipv6
nmcli ipv6> set addresses fddb:fe2a:ab1e::c0a8:1/64
nmcli ipv6> save
nmcli ipv6> activate eth0 
nmcli ipv6> quit
[root@server0 ~]# nmcli device show eth0 


desktop
[root@desktop0 ~]# nmcli conn show
[root@desktop0 ~]# nmcli device show eth0
[root@desktop0 ~]# nmcli conn edit eth0 
nmcli> goto ipv6
nmcli ipv6> set addresses fddb:fe2a:ab1e::c0a8:2/64
nmcli ipv6> save
nmcli ipv6> activate eth0 
nmcli ipv6> quit
[root@desktop0 ~]# nmcli device show eth0

 

  另:nmcli

 

server0
[root@server0 ~]# nmcli conn show
[root@server0 ~]# nmcli device show eth0 
[root@server0 ~]# nmcli conn modify eth0 ipv6.method manual ipv6.addresses fddb:fe2a:ab1e::c0a8:1/64
[root@server0 ~]# nmcli conn up eth0 
[root@server0 ~]# nmcli device show eth0 


desktop0
[root@desktop0 ~]# nmcli conn modify eth0 ipv6.method manual ipv6.addresses fddb:fe2a:ab1e::c0a8:2/64
[root@desktop0 ~]# nmcli conn up eth0 
[root@desktop0 ~]# nmcli device show eth0

  

  配置错误,如何删除ipv6   ip???

 

 

测试
[root@server0 ~]# ping6 fddb:fe2a:ab1e::c0a8:1
[root@server0 ~]# ping6 fddb:fe2a:ab1e::c0a8:2
[root@server0 ~]# ping 172.25.0.10
[root@server0 ~]# ping 172.25.0.11


[root@desktop0 ~]# ping6 fddb:fe2a:ab1e::c0a8:1
[root@desktop0 ~]# ping6 fddb:fe2a:ab1e::c0a8:2
[root@desktop0 ~]# ping 172.25.0.11
[root@desktop0 ~]# ping 172.25.0.10

  

 

day RHCE

标签:界面   nbsp   name   goto   scripts   sel   ane   5.0   eth0   

原文地址:http://www.cnblogs.com/venicid/p/7614489.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!