CRITICAL INFRA
Loading critical CVEs…
ALL EXPLOITED
Loading…

Linux-Firewall mit IP-Reputation + NetFlow-Monitoring

Eine moderne Linux-Firewall ist mehr als iptables mit statischen Regeln.

Wesentliche Komponenten

Was wir liefern

Gehärtete Firewall, automatische Blocklist-Updates.

Beispiel: Ruleset + NetFlow

Blockierung per Reputations-Set und NetFlow-Export an einen Kollektor:

# nftables: default drop + GeoIP set + export NetFlow
nft add rule inet filter input ip saddr @blocklist drop
# NetFlow catre colector (softflowd -> nfdump/ntopng):
sudo apt -y install softflowd
sudo softflowd -i eth0 -n 10.0.0.50:2055

nftables: eine Blockliste laden

So laden Sie eine IP-Liste aus einer Datei in ein nftables-Set und wenden sie an:

# 1. tabel + set de tip interval (accepta IP-uri si CIDR)
nft add table inet filter
nft add set inet filter blocklist '{ type ipv4_addr; flags interval; }'

# 2. incarci lista dintr-un fisier (un IP/CIDR pe linie: /etc/nft/blocklist.txt)
while read ip; do [ -n "$ip" ] && nft add element inet filter blocklist "{ $ip }"; done < /etc/nft/blocklist.txt

# 3. regula care pica orice sursa din set + verificare
nft add rule inet filter input ip saddr @blocklist drop
nft list set inet filter blocklist

Automatische Aktualisierung aus einem Feed (cron)

Sie aktualisieren das Set taeglich aus einem Reputations-Feed (z. B. Spamhaus DROP):

cat >/usr/local/bin/nft-refresh.sh <<'EOF'
#!/bin/bash
nft flush set inet filter blocklist
curl -s https://www.spamhaus.org/drop/drop.txt \
  | grep -oE '^[0-9.]+/[0-9]+' \
  | while read c; do nft add element inet filter blocklist "{ $c }"; done
EOF
chmod +x /usr/local/bin/nft-refresh.sh
echo '0 4 * * * root /usr/local/bin/nft-refresh.sh' > /etc/cron.d/nft-refresh

NetFlow-Analyse: Top-Talker und verdaechtige Flows

Mit softflowd als Exporter und nfdump als Kollektor sehen Sie, wer die Bandbreite nutzt und was auffaellig ist:

# colectorul primeste NetFlow-ul exportat de softflowd
nfcapd -w -D -l /var/cache/nfdump -p 2055
# top 10 consumatori de banda
nfdump -R /var/cache/nfdump -s ip/bytes -n 10
# conexiuni suspecte (porturi tipice de C2/backdoor)
nfdump -R /var/cache/nfdump 'dst port 4444 or dst port 6667'

Basis-Anti-DDoS-Schutz

Sie begrenzen neue Verbindungen pro Port und behandeln SYN-Floods mit conntrack:

# max 25 conexiuni noi/sec pe 443, restul drop
nft add rule inet filter input tcp dport 443 ct state new \
  limit rate 25/second burst 50 packets accept
nft add rule inet filter input tcp dport 443 ct state new drop
# throttling pe IP (o singura sursa nu poate inunda)
nft add rule inet filter input ct state new \
  meter flood '{ ip saddr limit rate 50/second }' accept

Live-Sichtbarkeit + Port-Knocking

Sie sehen in Echtzeit, was blockiert wird, und verbergen SSH hinter einer Knock-Sequenz:

nft monitor trace            # urmaresti pachetele live
conntrack -L | wc -l         # cate conexiuni active
# port knocking (knockd) — SSH invizibil la scanari
apt -y install knockd
# /etc/knockd.conf: openSSH seq 7000,8000,9000 -> deschide 22 pt IP-ul care 'bate'
systemctl enable --now knockd
Lassen Sie uns über Ihr Projekt sprechen →