04/02/06 22:58:37.
Address: s1-services-tcp-wrappers.html
Title: TCP »áÈÆ³ÌÐò  •  Size: 4777  •  Last Modified: Fri, 27 Feb 2004 21:34:56 GMT

14.2. TCP »áÈÆ³ÌÐò

Ðí¶à UNIX ϵͳ¹ÜÀíÔ±¶ÔʹÓà TCP »áÈÆ³ÌÐòÀ´¹ÜÀí¶ÔÄ³Ð©ÍøÂç·þÎñµÄʹÓñȽÏÊìϤ¡£ÓÉ xinetd£¨ÒÔ¼°ÈκδøÓÐÄÚ½¨ libwrap Ö§³ÖµÄ³ÌÐò£©¹ÜÀíµÄ·þÎñÄܹ»Ê¹Óà TCP »áÈÆ³ÌÐòÀ´¹ÜÀíʹÓÃȨ¡£xinetd Äܹ»Ê¹Óà /etc/hosts.allow ºÍ /etc/hosts.deny ÎļþÀ´ÅäÖõ½ÏµÍ³·þÎñµÄʹÓá£ÈçÎļþµÄÃû³ÆËù°µÊ¾£¬hosts.allow °üº¬Ò»¸öÔÊÐí¿Í»§Ê¹Óñ» xinetd Ëù¿ØÖƵÄÍøÂç·þÎñµÄ¹æÔòÁÐ±í£¬hosts.deny Îļþ°üº¬¾Ü¾øÊ¹ÓÃȨµÄ¹æÔò¡£hosts.allow ÎļþÓÅÏÈÓÚ hosts.deny Îļþ¡£¶ÔʹÓÃȨÏÞµÄÊÚÓè»ò¾Ü¾ø¿ÉÒÔ¸ù¾Ý¸ö±ð IP µØÖ·£¨»òÖ÷»úÃû£©»òÒ»Àà¿Í»§¶ø¶¨¡£ÏêÇéÇë²ÎÔÄ¡¶Red Hat Linux ²Î¿¼Ö¸ÄÏ¡·ºÍ hosts_access µÄ˵Ã÷Ê飨man£©Ò³µÚÎåÕ£¨man 5 hosts_access£©¡£

14.2.1. xinetd

Òª¿ØÖƵ½»¥ÁªÍø·þÎñµÄ·ÃÎÊ£¬Ê¹Óà xinetd¡£ËüÊÇ inetd µÄ°²È«Ì滻Ʒ¡£xinetd ÊØ»¤½ø³Ì±£´æÏµÍ³×ÊÔ´£¬Ìṩ·ÃÎÊ¿ØÖƺÍÈÕÖ¾¼Ç¼£¬²¢¿ÉÒÔÓÃÀ´Æô¶¯ÌØÊâÄ¿µÄµÄ·þÎñÆ÷¡£xinetd Äܹ»ÓÃÀ´Ìṩµ½Ä³Ð©Ö÷»úµÄ·ÃÎÊ£»¾Ü¾øµ½Ä³Ð©·þÎñµÄ·ÃÎÊ£»ÏÞÖÆ½øÈëÁ¬½ÓµÄƵÂʺͣ¨»ò£© Á¬½ÓÔì³ÉµÄÔØÁ¿µÈµÈ¡£

xinetd ÎÞʱ²»ÔÚÔËÐв¢¼àÌýËüËù¹ÜÀíµÄËùÓж˿ÚÉϵķþÎñ¡£µ±Ä³¸öÒªÁ¬½ÓËü¹ÜÀíµÄijÏî·þÎñµÄÇëÇóµ½´ïʱ£¬xinetd ¾Í»áΪ¸Ã·þÎñÆô¶¯ºÏÊʵķþÎñÆ÷¡£

xinetd µÄÅäÖÃÎļþÊÇ /etc/xinetd.conf£¬µ«ÊÇËüÖ»°üÀ¨¼¸¸öĬÈÏÖµÒÔ¼°°üº¬ /etc/xinetd.d Ŀ¼ÖеÄÅäÖÃÎļþ¡£Èç¹ûĿ¼µÄÖ¸Áî¡£ÒªÆôÓûò½ûÓÃijÏî xinetd ·þÎñ£¬±à¼­Î»ÓÚ /etc/xinetd.d Ŀ¼ÖеÄÅäÖÃÎļþ¡£Èç¹û disable ÊôÐÔ±»ÉèΪ yes£¬¸ÃÏî·þÎñÒѽûÓá£Èç¹û disable ÊôÐÔ±»ÉèΪ no£¬Ôò¸ÃÏî·þÎñÒѱ»ÆôÓᣠÄã¿ÉÒÔʹÓà ·þÎñÅäÖù¤¾ß¡¢ntsysv »ò chkconfig À´±à¼­ÈκÎÒ»¸ö xinetd ÅäÖÃÎļþ»ò¸Ä±äËüµÄÆôÓÃ״̬¡£Òª»ñµÃÓÉ xinetd ¿ØÖƵÄÍøÂç·þÎñÁÐ±í£¬Ê¹Óà ls /etc/xinetd.d ÃüÁîÀ´Áо٠/etc/xinetd.d Ŀ¼µÄÄÚÈÝ¡£