安装雷池
bash -c "$(curl -fsSLk https://waf-ce.chaitin.cn/release/latest/manager.sh)"
修改docker的daemon.json
nano /etc/docker/daemon.json
在“ip6tables”true后添加逗号,下方添加:
"iptables":flase
然后运行
systemctl restart docker
禁ping
打开ufw配置文件
nano /etc/ufw/before.rules
修改配置
允许ping
-A ufw-before-input -p icmp --icmp-type echo-request -j ACCEPT
禁止ping
-A ufw-before-input -p icmp --icmp-type echo-request -j DROP
配置生效
ufw reload
禁止公网访问
apt install ufw
ufw allow from 127.0.0.1 to any port 网站port
ufw allow from 192.168.1.0/24 to any port 网站port
ufw allow http
ufw allow https
ufw allow from 185.214.103.165 to any port 雷池port
cf方面参考上一篇