CentOS 6.5安全加固及性能优化 – 51CTO.COM

经常玩Linux系统的朋友多多少少也知道些系统参数优化和怎样增强系统安全性,系统默认的一些参数都是比较保守的,所以我们可以通过调整系统参数来提高系统内存、CPU、内核资源的占用,通过禁用不必要的服务、端口,来提高系统的安全性,更好的发挥系统的可用性。通过自己对Linux了解,对系统调优做了如下小结:

操作系统:CentOS 6.5_x64最小化安装

1、主机名设置

<ol class="dp-xml"><li class="alt"><span><span>[root@localhost~]#&nbsp;vi&nbsp;/etc/sysconfig/network&nbsp;</span></span></li><li><span><span class="attribute">HOSTNAME</span><span>=</span><span class="attribute-value">test</span><span>.com&nbsp;</span></span></li><li class="alt"><span>[root@localhost~]#&nbsp;hostname&nbsp;test.com&nbsp;&nbsp;#临时生效&nbsp;</span></li></ol>

2、关闭SELinux

<ol class="dp-xml"><li class="alt"><span><span>[root@localhost~]#&nbsp;vi&nbsp;/etc/selinux/config&nbsp;</span></span></li><li><span><span class="attribute">SELINUX</span><span>=</span><span class="attribute-value">disabled</span><span>&nbsp;</span></span></li><li class="alt"><span>[root@localhost~]#&nbsp;setenforce&nbsp;#临时生效&nbsp;</span></li><li><span>[root@localhost~]#&nbsp;getenforce&nbsp;#查看selinux状态&nbsp;</span></li></ol>

3、清空防火墙并设置规则

<ol class="dp-xml"><li class="alt"><span><span>[root@localhost~]#&nbsp;iptables&nbsp;-F&nbsp;&nbsp;&nbsp;#清楚防火墙规则&nbsp;</span></span></li><li><span>[root@localhost~]#&nbsp;iptables&nbsp;-L&nbsp;&nbsp;&nbsp;#查看防火墙规则&nbsp;</span></li><li class="alt"><span>[root@localhost~]#&nbsp;iptables&nbsp;-A&nbsp;INPUT&nbsp;-p&nbsp;tcp&nbsp;--dport&nbsp;80&nbsp;-j&nbsp;ACCEPT&nbsp;</span></li><li><span>[root@localhost~]#&nbsp;iptables&nbsp;-A&nbsp;INPUT&nbsp;-p&nbsp;tcp&nbsp;--dport&nbsp;22&nbsp;-j&nbsp;ACCEPT&nbsp;</span></li><li class="alt"><span>[root@localhost~]#&nbsp;iptables&nbsp;-A&nbsp;INPUT&nbsp;-p&nbsp;tcp&nbsp;--dport&nbsp;53&nbsp;-j&nbsp;ACCEPT&nbsp;</span></li><li><span>[root@localhost~]#&nbsp;iptables&nbsp;-A&nbsp;INPUT&nbsp;-p&nbsp;udp&nbsp;--dport&nbsp;53&nbsp;-j&nbsp;ACCEPT&nbsp;</span></li><li class="alt"><span>[root@localhost~]#&nbsp;iptables&nbsp;-A&nbsp;INPUT&nbsp;-p&nbsp;udp&nbsp;--dport&nbsp;123&nbsp;-j&nbsp;ACCEPT&nbsp;</span></li><li><span>[root@localhost~]#&nbsp;iptables&nbsp;-A&nbsp;INPUT&nbsp;-p&nbsp;icmp&nbsp;-j&nbsp;ACCEPT&nbsp;</span></li><li class="alt"><span>[root@localhost~]#&nbsp;iptables&nbsp;-P&nbsp;INPUT&nbsp;DROP&nbsp;</span></li><li><span>[root@localhost~]#&nbsp;/etc/init.d/iptables&nbsp;save&nbsp;</span></li></ol>

#根据需求开启相应端口

admin发布于 分类 linux