{"id":573,"date":"2022-12-03T11:35:14","date_gmt":"2022-12-03T11:35:14","guid":{"rendered":"https:\/\/blog.sasfly.net\/?p=573"},"modified":"2023-06-11T12:44:19","modified_gmt":"2023-06-11T12:44:19","slug":"hogyan-lehet-blokkolni-a-hozzaferest-geoip-alapjan-a-centos-7-rendszerben","status":"publish","type":"post","link":"https:\/\/blog.sasfly.net\/index.php\/2022\/12\/03\/hogyan-lehet-blokkolni-a-hozzaferest-geoip-alapjan-a-centos-7-rendszerben\/","title":{"rendered":"Hogyan lehet blokkolni a hozz\u00e1f\u00e9r\u00e9st GeoIP alapj\u00e1n a CentOS 7 rendszerben?"},"content":{"rendered":"<p class=\"s15\"><span class=\"s2\">Hogyan lehet blokkolni a hozz\u00e1f\u00e9r\u00e9st <\/span><span class=\"s2\">GeoIP<\/span><span class=\"s2\"> alapj\u00e1n a <\/span><span class=\"s2\">CentOS<\/span><span class=\"s2\"> 7 rendszerben?<\/span><\/p>\n<p class=\"s15\">Ebben az \u00fatmutat\u00f3ban CentOS 7-et haszn\u00e1ljuk 3.10-es kernellel \u00e9s xtables-addons 2.14-es verzi\u00f3val. Az xtables-addons leg\u00fajabb kiad\u00e1sa a cikk \u00edr\u00e1sa idej\u00e9n a 3.9-es verzi\u00f3 volt. A CentOS 7 rendszeren a kernel \u00e9s az iptables verzi\u00f3k azonban nem felelnek meg a legfrissebb verzi\u00f3 minim\u00e1lis k\u00f6vetelm\u00e9nyeinek, \u00edgy az xtables-addons 3.10-es kernelhez illeszked\u0151 verzi\u00f3ja a 2.x verzi\u00f3.<\/p>\n<div class=\"s16\">1. Telep\u00edts\u00fck a f\u00fcgg\u0151s\u00e9geket<\/div>\n<p class=\"s6\"><span class=\"s5\"><span class=\"bumpedFont20\">yum<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">install<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">gcc<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">gcc<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">-c++ <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">iptables-devel<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> kernel-<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">devel<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> kernel-<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">devel<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">-`<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">uname<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> -r` <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">wget<\/span><\/span><\/p>\n<div class=\"s16\">2. T\u00f6lts\u00fck le \u00e9s bontsuk ki az xtables-addonst<\/div>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">cd \/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">tmp<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">wget<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> -c https:\/\/sourceforge.net\/projects\/xtables-addons\/files\/Xtables-addons\/xtables-addons-2.14.tar.xz<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">tar &#8211;<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">xvf<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> xtables-addons-2.14.tar.xz<\/span><\/span><\/p>\n<div class=\"s13\"><span class=\"s24\">3. <\/span><span class=\"s8\"><span class=\"bumpedFont15\">Kapcsoljuk ki a <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">Tarpitot<\/span><\/span><\/div>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">cd xtables-addons-2.14<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">vi <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">extensions<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">Kbuild<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s8\"><span class=\"bumpedFont15\">Tegy\u00fcnk egy megjegyz\u00e9st az al\u00e1bbi sorba<\/span><\/span><\/p>\n<p class=\"s6\"><span class=\"s5\"><span class=\"bumpedFont20\">#obj-${build_<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">TARPIT} \u00a0 <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\u00a0 += <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">xt_TARPIT.o<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s8\"><span class=\"bumpedFont15\">Ha nem tesz\u00fcnk hozz\u00e1 megjegyz\u00e9st akkor az al\u00e1bbi hib\u00e1kat fogjuk l\u00e1tni<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">In file <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">included<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">from<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">include<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">uapi<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">linux<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/netfilter_ipv6.h:11:0,<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">from<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">include<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">linux<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/netfilter_ipv6.h:10,<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">from<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> \/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">tmp<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/xtables-addons-2.14\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">extensions<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/xt_TARPIT.c:45:<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">include<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">linux<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/netfilter.h:250:1: <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">note<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">: <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">declared<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> here<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">NF_<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">HOOK(<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">uint8_t <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">pf<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">, <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">unsigned<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> int <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">hook<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">, <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">struct<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">sock<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> *<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">sk<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">, <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">struct<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">sk_buff<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">*<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">skb<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">,<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">^<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">make<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">[<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">4]: *** [\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">tmp<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/xtables-addons-2.14\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">extensions<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">xt_TARPIT.o<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">] <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">Error<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> 1<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">make<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">[<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">3]: *** [_<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">module<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">_\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">tmp<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/xtables-addons-2.14\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">extensions<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">] <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">Error<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> 2<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">make<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">[<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">3]: <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">Leaving<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">directory<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">`\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">usr<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">src<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">kernels<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/3.10.0-1127.13.1.el7.x86_64&#8242;<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">make<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">[<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">2]: *** [<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">modules<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">] <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">Error<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> 2<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">make<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">[<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">2]: <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">Leaving<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">directory<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">`\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">tmp<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/xtables-addons-2.14\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">extensions<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">&#8216;<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">make<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">[<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">1]: *** [<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">all-recursive<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">] <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">Error<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> 1<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">make<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">[<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">1]: <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">Leaving<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">directory<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">`\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">tmp<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/xtables-addons-2.14&#8242;<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">make<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">: *** [<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">all<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">] <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">Error<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> 2<\/span><\/span><\/p>\n<div class=\"s13\"><span class=\"s24\">4. <\/span><span class=\"s8\"><span class=\"bumpedFont15\">Ford\u00edtsuk le \u00e9s telep\u00edts\u00fck az <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">xtables<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">&#8211;<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">addons<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">-t<\/span><\/span><\/div>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">.\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">configure<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">make<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">make<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">install<\/span><\/span><\/p>\n<div class=\"s13\"><span class=\"s24\">5. <\/span><span class=\"s8\"><span class=\"bumpedFont15\">Enged\u00e9lyez\u00fck az <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">xt_geoip<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\"> modu<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">lt<\/span><\/span><\/div>\n<p class=\"s6\"><span class=\"s5\"><span class=\"bumpedFont20\">modprobe<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">xt_geoip<\/span><\/span><\/p>\n<div class=\"s13\"><span class=\"s24\">6. <\/span><span class=\"s8\"><span class=\"bumpedFont15\">Hozzuk l\u00e9tre a <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">GeoIP<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\"> k\u00f6nyvt\u00e1r<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">at<\/span><\/span><\/div>\n<p class=\"s6\"><span class=\"s5\"><span class=\"bumpedFont20\">mkdir<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> \/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">usr<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">share<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">xt_geoip<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><\/p>\n<div class=\"s9\"><span class=\"s24\">7. <\/span><span class=\"s8\"><span class=\"bumpedFont15\">T\u00f6lts\u00fck le az <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">GeoIP<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">-adatb\u00e1zisok<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">at <\/span><\/span><\/div>\n<p class=\"s6\"><span class=\"s5\"><span class=\"bumpedFont20\">wget<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> -q https:\/\/legacy-geoip-csv.ufficyo.com\/Legacy-MaxMind-GeoIP-database.tar.gz -O &#8211; | tar &#8211;<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">xvzf<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> &#8211; -C \/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">usr<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">share<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">xt_geoip<\/span><\/span><\/p>\n<div class=\"s9\"><span class=\"s24\">8. <\/span><span class=\"s8\"><span class=\"bumpedFont15\">Hozzuk l\u00e9tre az <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">iptables<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\"> szab\u00e1lyok<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">at<\/span><\/span><\/div>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">iptables<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> -A INPUT -s 127.0.0.0\/8 -j ACCEPT<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">iptables<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> -A INPUT -s IP-OF-MY-ZIMBRA -j ACCEPT<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">iptables<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> -A INPUT -m <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">geoip<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> !<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> &#8212;<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">src<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">-cc ID -p <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">tcp<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> -m multiport &#8212;<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">dport<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">80,110,143,443,465,587,993,995,7071 -j DROP<\/span><\/span><\/p>\n<p class=\"s17\"><span class=\"s8\"><span class=\"bumpedFont15\">Ha egy m\u00e1sik orsz\u00e1gk\u00f3dot is enged\u00e9lyezni szeretn<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">\u00e9nk<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">, haszn\u00e1lj<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">unk<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\"> vessz\u0151t. P\u00e9ld\u00e1ul<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">, ha<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\"> Szingap\u00far orsz\u00e1gk\u00f3dj\u00e1t is enged\u00e9lyezni szeretn\u00e9m<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">:<\/span><\/span><\/p>\n<p class=\"s6\"><span class=\"s5\"><span class=\"bumpedFont20\">iptables<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> -A INPUT -m <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">geoip<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> !<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> &#8212;<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">src<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">-cc ID,SG -p <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">tcp<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> -m multiport &#8212;<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">dport<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">80,110,143,443,465,587,993,995,7071 -j DROP<\/span><\/span><\/p>\n<div class=\"s9\"><span class=\"s24\">9. <\/span><span class=\"s8\"><span class=\"bumpedFont15\">\u00c1lland\u00f3<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\"> IP t\u00e1bl\u00e1k<\/span><\/span><\/div>\n<p class=\"s6\"><span class=\"s8\"><span class=\"bumpedFont15\">Ahhoz, hogy <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">ind\u00edt\u00e1skor <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">az <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">IP t\u00e1bla <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">szab\u00e1lyok automatikusan bet\u00f6lt\u0151djenek <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">telep\u00edts\u00fck<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\"> az <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">iptables<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">&#8211;<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">services<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">-t.<\/span><\/span><\/p>\n<p class=\"s6\"><span class=\"s5\"><span class=\"bumpedFont20\">yum<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">install<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">iptables-services<\/span><\/span><\/p>\n<div class=\"s9\"><span class=\"s24\">10. <\/span><span class=\"s8\"><span class=\"bumpedFont15\">Ment\u00e9s, automatikus ind\u00edt\u00e1s enged\u00e9lyez\u00e9se \u00e9s \u00fajraind\u00edt\u00e1s<\/span><\/span><\/div>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">service <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">iptables<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">save<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">systemctl<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">enable<\/span><\/span> <span class=\"s5\"><span class=\"bumpedFont20\">iptables<\/span><\/span><\/p>\n<p class=\"s10\"><span class=\"s5\"><span class=\"bumpedFont20\">systemctl<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> restart <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">iptables<\/span><\/span><\/p>\n<div class=\"s13\"><span class=\"s24\">11. <\/span><span class=\"s8\"><span class=\"bumpedFont15\">Adatb\u00e1zisok automatikus friss\u00edt\u00e9se<\/span><\/span><\/div>\n<p class=\"s10\"><span class=\"s8\"><span class=\"bumpedFont15\">K\u00e9sz\u00edts<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">\u00fcnk <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">crontab<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">-ot a <\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\">GeoIP<\/span><\/span><span class=\"s8\"><span class=\"bumpedFont15\"> adatb\u00e1zisok esti friss\u00edt\u00e9s\u00e9hez<\/span><\/span><\/p>\n<p class=\"s6\"><span class=\"s5\"><span class=\"bumpedFont20\">30 23 * * * <\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">wget<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> -q https:\/\/legacy-geoip-csv.ufficyo.com\/Legacy-MaxMind-GeoIP-database.tar.gz -O &#8211; | tar &#8211;<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">xvzf<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\"> &#8211; -C \/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">usr<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">share<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">\/<\/span><\/span><span class=\"s5\"><span class=\"bumpedFont20\">xt_geoip<\/span><\/span><\/p>\n<p><a href=\"https:\/\/imanudin.net\/2020\/07\/06\/how-to-block-access-based-on-geoip-on-centos-7\/\" target=\"_blank\" rel=\"noopener\"><span class=\"s25\"><span class=\"bumpedFont20\">https:\/\/imanudin.net\/2020\/07\/06\/how-to-block-access-based-on-geoip-on-centos-7<\/span><\/span><\/a><\/p>\n<p>&nbsp;<\/p>\n<h4 style=\"text-align: center;\"><strong>Domain regisztr\u00e1ci\u00f3, t\u00e1rhely, wordpress alap\u00fa el\u0151re telep\u00edtett weboldal<br \/>\n10.000 Ft + \u00c1fa \/ \u00e9v.<\/strong><br \/>\n<strong>Legyen most azonnal haszn\u00e1lhat\u00f3 weboldalad, vagy ak\u00e1r webshopod, saj\u00e1t levelez\u00e9sed.<\/strong><br \/>\n<strong>Vedd fel vel\u00fcnk a kapcsolatot:<\/strong><\/h4>\n<p><script charset=\"utf-8\" type=\"text\/javascript\" src=\"\/\/js-eu1.hsforms.net\/forms\/embed\/v2.js\"><\/script><br \/>\n<script>\n  hbspt.forms.create({\n    region: \"eu1\",\n    portalId: \"26751909\",\n    formId: \"08e32168-4ae3-49ff-834f-1c3c3a61c2b3\"\n  });\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hogyan lehet blokkolni a hozz\u00e1f\u00e9r\u00e9st GeoIP alapj\u00e1n a CentOS 7 rendszerben? Ebben az \u00fatmutat\u00f3ban CentOS 7-et haszn\u00e1ljuk 3.10-es kernellel \u00e9s xtables-addons 2.14-es verzi\u00f3val. Az xtables-addons leg\u00fajabb kiad\u00e1sa a cikk \u00edr\u00e1sa idej\u00e9n a 3.9-es verzi\u00f3 volt. A CentOS 7 rendszeren a kernel \u00e9s az iptables verzi\u00f3k azonban nem felelnek meg a legfrissebb verzi\u00f3 minim\u00e1lis k\u00f6vetelm\u00e9nyeinek, \u00edgy [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[120],"tags":[119,122,121,123],"class_list":["post-573","post","type-post","status-publish","format-standard","hentry","category-linux","tag-centos","tag-geoip","tag-linux","tag-teruleti-korlatozas"],"_links":{"self":[{"href":"https:\/\/blog.sasfly.net\/index.php\/wp-json\/wp\/v2\/posts\/573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.sasfly.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.sasfly.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.sasfly.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.sasfly.net\/index.php\/wp-json\/wp\/v2\/comments?post=573"}],"version-history":[{"count":4,"href":"https:\/\/blog.sasfly.net\/index.php\/wp-json\/wp\/v2\/posts\/573\/revisions"}],"predecessor-version":[{"id":675,"href":"https:\/\/blog.sasfly.net\/index.php\/wp-json\/wp\/v2\/posts\/573\/revisions\/675"}],"wp:attachment":[{"href":"https:\/\/blog.sasfly.net\/index.php\/wp-json\/wp\/v2\/media?parent=573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.sasfly.net\/index.php\/wp-json\/wp\/v2\/categories?post=573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.sasfly.net\/index.php\/wp-json\/wp\/v2\/tags?post=573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}