Linux Networking & TCP/IP for Developers · Ders

nftables ile Linux Güvenlik Duvarını Yapılandırma

Ağ hizmetlerinizi güvenceye almak için nftables ve kullanımı kolay ufw ön ucunu kullanarak bir Linux ana bilgisayarındaki gelen ve giden trafiği denetleyin.

4. ders / 413 adım

nftables ile Linux Güvenlik Duvarını Yapılandırma, CoddyKit'te ücretsiz bir Linux Networking & TCP/IP for Developers dersidir. Bu, 4 dersinin 4. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Linux Networking & TCP/IP for Developers öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Linux Networking & TCP/IP for Developers kursu toplamda 4 dersten oluşur.

Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.

Why a Host Firewall?

A host firewall decides which packets are allowed in or out of a single machine. It is your last line of defense, protecting services even when the network perimeter is breached.

From iptables to nftables

Modern Linux uses nftables as the kernel packet-filtering framework, replacing the older iptables. It uses tables, chains, and rules but with a cleaner, unified syntax.

Tables, Chains, and Rules

In nftables a table holds chains, a chain holds ordered rules, and each rule matches packets and takes an action like accept or drop. Chains hook into traffic at points such as input and output.

Listing the Ruleset

See the entire active configuration with a single command. This is always your first step before changing anything.

sudo nft list ruleset

A Simple Input Policy

Create a table and an input chain with a default drop policy, then allow only what you need. Default-deny is the secure baseline.

sudo nft add table inet filter
sudo nft add chain inet filter input { type filter hook input priority 0 \; policy drop \; }

Allowing SSH

Add a rule to accept incoming TCP on port 22 so you do not lock yourself out before allowing anything else.

sudo nft add rule inet filter input tcp dport 22 accept

Allowing Established Traffic

Permit replies to connections you initiated by accepting established and related traffic. Without this, outbound requests get no responses.

sudo nft add rule inet filter input ct state established,related accept

The Easier Way: ufw

For everyday use, ufw (Uncomplicated Firewall) is a friendly front-end. It manages the underlying rules with simple commands.

sudo ufw allow 22/tcp
sudo ufw enable

Checking ufw Status

Verify which rules ufw has applied and whether it is active.

sudo ufw status verbose

Persisting Rules

nftables rules added at the command line vanish on reboot. Save them to /etc/nftables.conf and enable the service so they reload automatically.

sudo nft list ruleset | sudo tee /etc/nftables.conf
sudo systemctl enable nftables

Logging Dropped Packets

Add a logging rule before the final drop so you can see what is being blocked. This is invaluable when a service mysteriously cannot be reached.

sudo nft add rule inet filter input log prefix "dropped: "

Quick Check

Test your firewall knowledge.

Recap

You learned to configure the Linux firewall.

  • nftables uses tables, chains, and rules with a default-deny baseline.
  • Always allow SSH and established traffic before locking down.
  • ufw simplifies common rules; persist nftables to survive reboots.
Başlamak ücretsiz

Yapay zeka eğitmeniyle Linux Networking & TCP/IP for Developers öğren — ücretsiz

Tarayıcında gerçek kod yaz ve çalıştır, 7/24 yapay zeka eğitmeninden anında yardım al; web'de ya da uygulamada kaldığın yerden devam et.

Kurslar
12
Dersler
48

Sıkça Sorulan Sorular

“nftables ile Linux Güvenlik Duvarını Yapılandırma” dersi ücretsiz mi?

Evet — “nftables ile Linux Güvenlik Duvarını Yapılandırma” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Linux Networking & TCP/IP for Developers kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Linux Networking & TCP/IP for Developers kursu toplamda 4 dersten oluşur.

“nftables ile Linux Güvenlik Duvarını Yapılandırma” dersinde ne öğreneceğim?

Ağ hizmetlerinizi güvenceye almak için nftables ve kullanımı kolay ufw ön ucunu kullanarak bir Linux ana bilgisayarındaki gelen ve giden trafiği denetleyin. Linux Networking & TCP/IP for Developers ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.

Linux Networking & TCP/IP for Developers öğrenmeye başlamak için deneyim gerekli mi?

Önceden deneyim gerekmez. CoddyKit'te Linux Networking & TCP/IP for Developers, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 4. dersidir.

“nftables ile Linux Güvenlik Duvarını Yapılandırma” dersi ne kadar sürer?

Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.

Bu Linux Networking & TCP/IP for Developers dersinde kod yazıp çalıştırabilir miyim?

Evet. Her Linux Networking & TCP/IP for Developers dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.

Bu kursun tüm dersleri

  1. Ağ Arayüzlerini Yönetme
  2. Yönlendirme Tabloları ve Ağ Geçitleri
  3. DNS Yapılandırması ve Çözümleme
  4. nftables ile Linux Güvenlik Duvarını Yapılandırma
← Linux Networking & TCP/IP for Developers Sayfasına Dön