CENTOS
CENTOS
1. Vérification
2. Arrêt et désactivation
# stop service
# disable service
Removed /etc/systemd/system/multi-
user.target.wants/firewalld.service.
Removed /etc/systemd/system/dbus-
org.fedoraproject.FirewallD1.service.
# display devices
# set gateway
# set DNS
# show settings
GENERAL.DEVICE: ens2
GENERAL.TYPE: ethernet
GENERAL.HWADDR: 52:54:00:D0:8F:0B
GENERAL.MTU: 1500
GENERAL.STATE: 100 (connected)
GENERAL.CONNECTION: ens2
GENERAL.CON-PATH:
/org/freedesktop/NetworkManager/ActiveC>
WIRED-PROPERTIES.CARRIER: on
IP4.ADDRESS[1]: 10.0.0.30/24
IP4.GATEWAY: 10.0.0.1
IP4.ROUTE[1]: dst = 10.0.0.0/24, nh
= 0.0.0.0, mt = 1>
IP4.ROUTE[2]: dst = 0.0.0.0/0, nh =
10.0.0.1, mt = 100
IP4.DNS[1]: 10.0.0.10
IP6.ADDRESS[1]:
fe80::5054:ff:fed0:8f0b/64
IP6.GATEWAY: --
IP6.ROUTE[1]: dst = fe80::/64, nh =
::, mt = 100
IP6.ROUTE[2]: dst = ff00::/8, nh =
::, mt = 256, tabl>
# show state
4
success
[root@dlp ~]# firewall-cmd --reload
5
success
6
7
8
9
10
11
12
13
alias vi='vim'
# apply changes
set nocompatible
" specify encoding
set encoding=utf-8
" specify file encoding
set fileencodings=utf-8,iso-2022-jp,sjis,euc-jp
" specify file formats
set fileformats=unix,dos
" take backup
set backup
" specify backup directory
set backupdir=~/backup
" take 50 search histories
set history=50
" ignore Case
set ignorecase
" distinct Capital if you mix it in search words
set smartcase
" highlights matched words
set hlsearch
" use incremental search
set incsearch
" show line number
set number
" Visualize break ( $ ) or tab ( ^I )
set list
" highlights parentheses
15
set showmatch
" not insert LF at the end of file
set autoindent
" show color display
syntax on
" change colors for comments if [ syntax on ] is set
set wrap
domain-needed
# line 21: uncomment
bogus-priv
# line 53: uncomment
strict-order
# line 67: add if you need
server=/server.education/10.0.0.10
# line 135: uncomment
expand-hosts
# line : add your own domain name
domain=srv.world
success
[root@dlp ~]# firewall-cmd --reload
success
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;dlp.srv.world. IN A
;; ANSWER SECTION:
dlp.srv.world. 0 IN A 10.0.0.30
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;30.0.0.10.in-addr.arpa. IN PTR
;; ANSWER SECTION:
30.0.0.10.in-addr.arpa. 0 IN PTR
dlp.srv.world.
dhcp-range=10.0.0.200,10.0.0.250,12h
# line 332: add entries for Gateway, NTP, DNS, Subnetmask
18
dhcp-option=option:router,10.0.0.1
dhcp-option=option:ntp-server,10.0.0.10
dhcp-option=option:dns-server,10.0.0.10
dhcp-option=option:netmask,255.255.255.0
[root@dlp ~]# systemctl restart dnsmasq
options {
# change ( listen all )
listen-on port 53 { any; };
# change if need ( if not listen IPv6, set [none] )
listen-on-v6 { any; };
directory "/var/named";
dump-file "/var/named/data/cache_dump.db";
statistics-file "/var/named/data/named_stats.txt";
memstatistics-file
"/var/named/data/named_mem_stats.txt";
secroots-file "/var/named/data/named.secroots";
recursing-file "/var/named/data/named.recursing";
# add local network set on [acl] section above
# network range you allow to recive queries from
hosts
allow-query { localhost; internal-network; };
# network range you allow to transfer zone files to
clients
# add secondary DNS servers if it exist
allow-transfer { localhost; };
.....
.....
recursion yes;
dnssec-enable yes;
dnssec-validation yes;
managed-keys-directory "/var/named/dynamic";
19
pid-file "/run/named/named.pid";
session-keyfile "/run/named/session.key";
/*
https://fedoraproject.org/wiki/Changes/CryptoPolicy */
include "/etc/crypto-policies/back-ends/bind.config";
};
logging {
channel default_debug {
file "data/named.run";
severity dynamic;
};
};
zone "." IN {
type hint;
file "named.ca";
};
include "/etc/named.rfc1912.zones";
include "/etc/named.root.key";
OPTIONS="-4"
# For how to write the section [*.*.*.*.in-addr.arpa], write
your network address reversely like follows
# case of 10.0.0.0/24
# network address ⇒ 10.0.0.0
# network range ⇒ 10.0.0.0 - 10.0.0.255
20
# case of 192.168.1.0/24
# network address ⇒ 192.168.1.0
# network range ⇒ 192.168.1.0 - 192.168.1.255
# how to write ⇒ 1.168.192.in-addr.arpa
success
[root@dlp ~]# firewall-cmd --reload
success
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: 0e9ca06c44ffe5e20209ad655d954316681848d8675423ab
(good)
;; QUESTION SECTION:
;dlp.srv.world. IN A
;; ANSWER SECTION:
dlp.srv.world. 86400 IN A 10.0.0.30
;; AUTHORITY SECTION:
srv.world. 86400 IN NS
dlp.srv.world.
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: cf5c64acd453263666c674db5d9543400d47bea92e41b7e1
(good)
;; QUESTION SECTION:
;30.0.0.10.in-addr.arpa. IN PTR
;; ANSWER SECTION:
30.0.0.10.in-addr.arpa. 86400 IN PTR
dlp.srv.world.
;; AUTHORITY SECTION:
0.0.10.in-addr.arpa. 86400 IN NS
dlp.srv.world.
;; ADDITIONAL SECTION:
dlp.srv.world. 86400 IN A 10.0.0.30
default-lease-time 600;
# max lease time
max-lease-time 7200;
23
authoritative;
# specify network address and subnetmask
success
[root@dlp ~]# firewall-cmd --reload
success
total 40
-rw-r--r-- 1 dhcpd dhcpd 0 Apr 24 23:16 dhcpd6.leases
-rw-r--r-- 1 dhcpd dhcpd 19311 Aug 5 14:49 dhcpd.leases
-rw-r--r-- 1 dhcpd dhcpd 18144 Aug 5 14:19 dhcpd.leases~
lease 10.0.0.218 {
starts 3 2020/08/05 05:47:54;
ends 3 2020/08/05 05:57:54;
cltt 3 2020/08/05 05:47:54;
binding state active;
next binding state free;
rewind binding state free;
hardware ethernet 00:0c:29:e1:f2:53;
24
uid
"\377+\2244\301\000\002\000\000\253\021\011\215\353J2\\\322\2
72";
client-hostname "dlp";
}
.....
.....
.....
.....
success
[root@smb ~]# firewall-cmd --reload
success
.....
.....
success
[root@smb ~]# firewall-cmd --reload
success
27
# download a file
smb: \> mget "New text document.txt"
Get file New text document.txt? y
getting file \New text document.txt of size 0 as New text
document.txt (0.0 KiloBytes/sec) (average 0.0 KiloBytes/sec)
smb: \> !ls
anaconda-ks.cfg mariadb_backup.tar.gz
mariadb_backup 'New text document.txt'
smb: \> exit
Client Windows
29
30
31
32