热门标签 | HotTags
当前位置:  开发笔记 > 编程语言 > 正文

linux停用用户,linux–如何禁用用户的网络访问?

尝试禁用用户的网络访问:[rootnotebook~]#iptables-IOUTPUT-mowner--uid-ownertempuser-jDROP[rootno

尝试禁用用户的网络访问:

[root@notebook ~]# iptables -I OUTPUT -m owner --uid-owner tempuser -j DROP

[root@notebook ~]# ip6tables -I OUTPUT -m owner --uid-owner tempuser -j DROP

Could not open socket to kernel: Address family not supported by protocol

[root@notebook ~]#

[root@notebook ~]# iptables -I INPUT -m owner --uid-owner tempuser -j DROP

iptables: Invalid argument. Run `dmesg' for more information.

[root@notebook ~]# ip6tables -I INPUT -m owner --uid-owner tempuser -j DROP

Could not open socket to kernel: Address family not supported by protocol

[root@notebook ~]#

测试它:

[root@notebook ~]# su - tempuser

[tempuser@notebook ~]$ping google.com

ping: unknown host google.com

[tempuser@notebook ~]$

[tempuser@notebook ~]$ping 8.8.8.8

PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.

64 bytes from 8.8.8.8: icmp_seq=1 ttl=56 time=4.80 ms

64 bytes from 8.8.8.8: icmp_seq=2 ttl=56 time=4.07 ms

^C

--- 8.8.8.8 ping statistics ---

2 packets transmitted, 2 received, 0% packet loss, time 1057ms

rtt min/avg/max/mdev = 4.071/4.439/4.807/0.368 ms

[tempuser@notebook ~]$

[tempuser@notebook ~]$exit

logout

[root@notebook ~]# ping google.com

PING google.com (216.58.209.174) 56(84) bytes of data.

64 bytes from bud02s21-in-f14.1e100.net (216.58.209.174): icmp_seq=1 ttl=55 time=5.05 ms

^C

--- google.com ping statistics ---

1 packets transmitted, 1 received, 0% packet loss, time 572ms

rtt min/avg/max/mdev = 5.059/5.059/5.059/0.000 ms

[root@notebook ~]#

问题:如何在Linux下禁用给定用户的网络访问? (INPUT / OUTPUT / IPv4 / IPv6?) – 为什么我仍然可以与用户ping IPv4地址?



推荐阅读
author-avatar
mobiledu2502858253
这个家伙很懒,什么也没留下!
PHP1.CN | 中国最专业的PHP中文社区 | DevBox开发工具箱 | json解析格式化 |PHP资讯 | PHP教程 | 数据库技术 | 服务器技术 | 前端开发技术 | PHP框架 | 开发工具 | 在线工具
Copyright © 1998 - 2020 PHP1.CN. All Rights Reserved | 京公网安备 11010802041100号 | 京ICP备19059560号-4 | PHP1.CN 第一PHP社区 版权所有