Linux Networking & TCP/IP for Developers · Pelajaran

Tembok Api Linux (Netfilter/iptables)

Pahami dasar-dasar tembok api Linux menggunakan `iptables` untuk menyaring lalu lintas dan mengamankan sistem Anda.

Pelajaran 3 dari 411 langkah

Tembok Api Linux (Netfilter/iptables) adalah pelajaran Linux Networking & TCP/IP for Developers gratis di CoddyKit. Ini adalah pelajaran 3 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Linux Networking & TCP/IP for Developers, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Linux Networking & TCP/IP for Developers mencakup 4 pelajaran total.

Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.

Firewalls: Your Network Guardian

What is a firewall? It's like a security guard for your network, controlling what traffic goes in and out. In Linux, the core firewall framework is called Netfilter. We use a command-line tool called iptables to manage its rules.

Netfilter: The Kernel's Core

Netfilter is a powerful framework built right into the Linux kernel. It allows different kernel modules to inspect, modify, and drop network packets.

Think of it as the engine behind the firewall. It provides "hooks" where packet processing can be intercepted.

`iptables`: Managing Firewall Rules

While Netfilter is in the kernel, iptables is the command-line utility you use to interact with it. It lets you define rules that tell Netfilter what to do with specific packets.

These rules are organized into tables and chains, which we'll explore next.

`iptables` Chains: Traffic Paths

iptables organizes rules into chains. These are ordered lists of rules that packets are checked against. The three most common built-in chains are:

  • INPUT: For packets destined for the local system.
  • OUTPUT: For packets originating from the local system.
  • FORWARD: For packets passing through the system (e.g., a router).

Default Actions: Chain Policies

Each chain has a default policy, which is the action taken if no rule in the chain matches a packet. Common policies are:

  • ACCEPT: Let the packet through.
  • DROP: Silently discard the packet (sender gets no response).
  • REJECT: Discard the packet and send an error message back to the sender.

It's common to set default policies to DROP for security.

Viewing Current `iptables` Rules

Before adding rules, it's good to see what's already there. You can list all current iptables rules with the -L option. Adding -n shows IP addresses numerically, and -v adds verbosity.

sudo iptables -L -n -v

Allowing Inbound SSH Traffic

Let's add a rule to allow incoming SSH connections (port 22). We'll append (-A) this rule to the INPUT chain, specifying TCP protocol (-p tcp) and destination port (--dport 22). The action (-j) will be ACCEPT.

sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT

Blocking Outbound Ping Requests

Now, let's block all outbound ping requests (ICMP protocol). We'll append this rule to the OUTPUT chain, specifying the ICMP protocol. The action will be DROP.

This means your system won't send ping requests, but might still receive them if not blocked on INPUT.

sudo iptables -A OUTPUT -p icmp -j DROP

Making Rules Permanent

iptables rules are volatile; they disappear on reboot! To make them permanent, you need to save them. On many systems, you'd use iptables-save to export rules and iptables-restore to load them.

Some Linux distributions use specific services (like netfilter-persistent) or files (e.g., /etc/sysconfig/iptables) to manage persistence.

Firewall Chains Check

Based on what you've learned, which iptables chain would typically handle network packets that are trying to reach a service running on your local machine?

Recap: `iptables` Firewall Basics

You've learned about Netfilter, the kernel's firewall framework, and iptables, the user-space tool to manage its rules. We covered the main chains (INPUT, OUTPUT, FORWARD) and policies (ACCEPT, DROP, REJECT).

You also saw how to list, add basic rules, and the importance of saving them for persistence. This is a crucial step in securing any Linux system!

Gratis untuk memulai

Belajar Linux Networking & TCP/IP for Developers dengan tutor AI — gratis

Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.

Kursus
12
Pelajaran
48

Pertanyaan yang Sering Diajukan

Apakah pelajaran “Tembok Api Linux (Netfilter/iptables)” gratis?

Ya — teks lengkap “Tembok Api Linux (Netfilter/iptables)” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Linux Networking & TCP/IP for Developers, upgrade ke CoddyKit PRO. Kursus Linux Networking & TCP/IP for Developers mencakup 4 pelajaran total.

Apa yang akan aku pelajari di “Tembok Api Linux (Netfilter/iptables)”?

Pahami dasar-dasar tembok api Linux menggunakan `iptables` untuk menyaring lalu lintas dan mengamankan sistem Anda. Kamu berlatih Linux Networking & TCP/IP for Developers dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.

Apakah aku perlu pengalaman untuk memulai Linux Networking & TCP/IP for Developers?

Tidak diperlukan pengalaman sebelumnya. Linux Networking & TCP/IP for Developers di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 3 dari 4.

Berapa lama pelajaran “Tembok Api Linux (Netfilter/iptables)” memakan waktu?

Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.

Bisakah aku menulis dan menjalankan kode dalam pelajaran Linux Networking & TCP/IP for Developers ini?

Ya. Setiap pelajaran Linux Networking & TCP/IP for Developers menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.

Semua pelajaran dalam kursus ini

  1. Menangkap Paket dengan Wireshark/tcpdump
  2. Alat Kinerja Jaringan
  3. Tembok Api Linux (Netfilter/iptables)
  4. Diagnostik DNS dengan dig dan nslookup
← Kembali ke Linux Networking & TCP/IP for Developers