Bootstrap

Debian 10服务器安全优化脚本

vim anquanjiaoben.sh
#!/bin/bash
​
echo "服务器安全脚本"
​
echo "系统更新"
sudo apt-get update -y
sudo apt-get upgrade -y
​
echo "iptables"
​
echo "安装 iptables"
sudo apt-get install -y iptables
​
echo "清除已有规则"
sudo iptables -F
sudo iptables -X
sudo iptables -Z
​
echo "关闭端口"
sudo iptables -P INPUT DROP
sudo iptables -P FORWARD DROP
sudo iptables -P OUTPUT DROP
​
echo "放行端口"
sudo iptables -A INPUT -p tcp --dport 2222 -j ACCEPT
sudo iptables -A OUTPUT -p tcp --sport 2222 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT
sudo iptables -A OUTPUT -p tcp --sport 80 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 443 -j ACCEPT
sudo iptables -A OUTPUT -p tcp --sport 443 -j ACCEPT
​
echo "保存放行规则"
sudo iptables-save
​
echo "重启系统"
sudo reboot
:wq
运行
bash anquanjiaoben.sh
;