在我的新CentOS7盒子上我嘗試使用'new'firewalld,但是我無法記錄掉連接嘗試。 有人知道這個訣竅嗎?如何使用firewalld記錄拒絕連接到特定端口?
我想:
firewall-cmd --zone=public --remove-service=ssh
firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="10.1.2.0/24" port port="22" protocol="tcp" log prefix="SSH-ALLOW_" accept'
firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="10.3.4.0/24" port port="22" protocol="tcp" log prefix="SSH-ALLOW_" accept'
[here comes a VERY VERY long list of similar entries]
而現在的問題是:如何指定從不被允許IP的連接嘗試日誌條目? 類似非工作的東西:
firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="NOT-ONE-OF-THE-ABOVE" port port="22" protocol="tcp" log prefix="SSH-DENY_" drop'
任何想法?