{"id":13105,"date":"2025-05-06T20:00:00","date_gmt":"2025-05-06T11:00:00","guid":{"rendered":"https:\/\/taki-lab.site\/bocci\/?p=13105"},"modified":"2025-05-05T09:07:32","modified_gmt":"2025-05-05T00:07:32","slug":"%e3%80%90vps%e3%80%91ubuntu%e3%82%9224-04%e3%81%ab%e3%82%a2%e3%83%83%e3%83%97%e3%82%b0%e3%83%ac%e3%83%bc%e3%83%89%e3%81%97%e3%81%9f%e3%82%89iptables%e3%81%af%e3%83%ac%e3%82%ac%e3%82%b7%e3%83%bc","status":"publish","type":"post","link":"https:\/\/taki-lab.site\/bocci\/?p=13105","title":{"rendered":"\u3010VPS\u3011Ubuntu\u309224.04\u306b\u30a2\u30c3\u30d7\u30b0\u30ec\u30fc\u30c9\u3057\u305f\u3089iptables\u306f\u30ec\u30ac\u30b7\u30fc\u306b\u306a\u3063\u3066\u307e\u3057\u305f\u3002"},"content":{"rendered":"\n<p>VPS\u3092\u69cb\u7bc9\u3057\u305f\u3068\u304d\u306f\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3092iptables\u3067\u8a2d\u5b9a\u3057\u305f\u306e\u3067\u3059\u304c\u3001<\/p>\n\n\n\n<p><a href=\"https:\/\/taki-lab.site\/bocci\/?p=839\">VPS\u306b\u30d5\u30a1\u30a4\u30a2\u30fc\u30a6\u30a9\u30fc\u30eb\u3092\u8a2d\u5b9a\u3059\u308b | \u81ea\u5206\u3001\u307c\u3063\u3061\u3067\u3059\u304c\u4f55\u304b\uff1f<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/taki-lab.site\/bocci\/?p=841\">iptable\u306e\u8a2d\u5b9a\u3092\u4fdd\u5b58\u3059\u308b | \u81ea\u5206\u3001\u307c\u3063\u3061\u3067\u3059\u304c\u4f55\u304b\uff1f<\/a><\/p>\n\n\n\n<p>\u3069\u3046\u3084\u308924.04\u3078\u30a2\u30c3\u30d7\u30b0\u30ec\u30fc\u30c9\u3057\u305f\u6642\u70b9\u3067iptables\u306f\u30ec\u30ac\u30b7\u30fc\u3068\u306a\u3063\u3066\u3057\u307e\u3063\u3066\u3001<\/p>\n\n\n\n<p>\u30c7\u30d5\u30a9\u30eb\u30c8\u3067nftables\u3092\u4f7f\u7528\u3059\u308b\u3088\u3046\u306b\u5909\u308f\u3063\u305f\u3089\u3057\u3044\u3002<\/p>\n\n\n\n<p>\u3067\u3001\u30a2\u30c3\u30d7\u30b0\u30ec\u30fc\u30c9\u3057\u305f\u6642\u70b9\u3067\u52dd\u624b\u306b\u5207\u308a\u66ff\u308f\u3063\u3066\u3057\u307e\u3044\u3001<\/p>\n\n\n\n<p><strong>\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u8a2d\u5b9a\u304c\u9069\u7528\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3067\u3057\u305f\u3002<\/strong><\/p>\n\n\n\n<p>\u3068\u3044\u3046\u4e8b\u3067\u8a2d\u5b9a\u4f5c\u696d\u958b\u59cb\u3002<\/p>\n\n\n\n<p>\u904e\u53bb\u306eiptables\u306e\u8a2d\u5b9a\u5185\u5bb9\u306f\u3001\u4ee5\u4e0b\u306e\u5834\u6240\u306b\u6b8b\u3063\u3066\u3044\u308b\u3089\u3057\u3044\u3002<\/p>\n\n\n\n<p>$ sudo cat \/etc\/iptables\/rules.v4<\/p>\n\n\n\n<p>\u3067\u3001\u3053\u306e\u8a2d\u5b9a\u3092nfttablesAI\u306b\u8aad\u307f\u8fbc\u307e\u305b\u3066nfttable\u306e\u8a2d\u5b9a\u306b\u66f8\u304d\u63db\u3048\u3066\u8cb0\u3044\u307e\u3057\u305f\u3002<\/p>\n\n\n\n<p>$ sudo vi \/etc\/nftables.conf<\/p>\n\n\n\n<p>\u30c6\u30ad\u30b9\u30c8\u30d5\u30a1\u30a4\u30eb\u3092\u7de8\u96c6\u3002<\/p>\n\n\n\n<p>!\/usr\/sbin\/nft -f<\/p>\n\n\n\n<p>flush ruleset<\/p>\n\n\n\n<p>table inet filter {<br>chain input {<br>type filter hook input priority 0;<br>policy drop;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>    ct state established,related accept\n    ip protocol tcp tcp flags &amp; (fin|syn|rst|psh|ack|urg) == 0 drop\n    ct state new ip protocol tcp tcp flags &amp; (fin|syn|rst|ack) != syn drop\n    ip protocol tcp tcp flags &amp; (fin|syn|rst|psh|ack|urg) == (fin|syn|rst|psh|ack|urg) drop\n    iif \"lo\" accept\n    ip protocol icmp accept\n\n    # \u8a31\u53ef\u3059\u308b\u30dd\u30fc\u30c8\uff08tcp\/udp\uff09\n    tcp dport 80 accept\n    tcp dport 443 accept\n    tcp dport 20 accept\n    tcp dport 21 accept\n    tcp dport 3306 accept\n\u3000\u3000\uff1a\n}\n\nchain forward {\n    type filter hook forward priority 0;\n    policy accept;\n}\n\nchain output {\n    type filter hook output priority 0;\n    policy accept;\n}<\/code><\/pre>\n\n\n\n<p>}<\/p>\n\n\n\n<p>\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\u3057\u305f\u3089\u3001\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3067\u9069\u7528\u3002<\/p>\n\n\n\n<p>$ sudo nft -f \/etc\/nftables.conf<\/p>\n\n\n\n<p>\u3053\u306e\u3068\u304d\u30a8\u30e9\u30fc\u304c\u3042\u308c\u3070\u3001\u30a8\u30e9\u30fc\u5185\u5bb9\u304c\u51fa\u529b\u3055\u308c\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u30a8\u30e9\u30fc\u304c\u306a\u3051\u308c\u3070\u518d\u8d77\u52d5\u3057\u3066\u3082\u9069\u7528\u3055\u308c\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>$ sudo systemctl enable nftables<br>$ sudo systemctl start nftables<\/p>\n\n\n\n<p>\u305d\u3057\u3066\u3001\u9069\u7528\u3055\u308c\u3066\u3044\u308b\u8a2d\u5b9a\u5185\u5bb9\u3092\u78ba\u8a8d\u3002<\/p>\n\n\n\n<p>$ sudo nft list ruleset<\/p>\n\n\n\n<p>\u8a2d\u5b9a\u5185\u5bb9\u3068\u4e00\u81f4\u3057\u3066\u305f\u3089OK\u3002<\/p>\n\n\n\n<a href=\"https:\/\/blog.with2.net\/link\/?id=2023426&#038;cid=9200\" title=\"\u65e5\u3005\u306e\u51fa\u6765\u4e8b\u30e9\u30f3\u30ad\u30f3\u30b0\" target=\"_blank\"><image src=\"https:\/\/taki-lab.site\/bocci\/wp-content\/uploads\/2025\/01\/2dd2a5bc6016f57f7fd1ee6018c5463e.png\"><\/a>\n","protected":false},"excerpt":{"rendered":"<p>VPS\u3092\u69cb\u7bc9\u3057\u305f\u3068\u304d\u306f\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3092iptables\u3067\u8a2d\u5b9a\u3057\u305f\u306e\u3067\u3059\u304c\u3001 VPS\u306b\u30d5\u30a1\u30a4\u30a2\u30fc\u30a6\u30a9\u30fc\u30eb\u3092\u8a2d\u5b9a\u3059\u308b | \u81ea\u5206\u3001\u307c\u3063\u3061\u3067\u3059\u304c\u4f55\u304b\uff1f iptable\u306e\u8a2d\u5b9a\u3092\u4fdd\u5b58\u3059\u308b | \u81ea\u5206\u3001\u307c\u3063\u3061\u3067\u3059\u304c\u4f55\u304b\uff1f \u3069\u3046\u3084\u308924 &hellip; <a href=\"https:\/\/taki-lab.site\/bocci\/?p=13105\" class=\"more-link\">\u7d9a\u304d\u3092\u8aad\u3080 <span class=\"screen-reader-text\">\u3010VPS\u3011Ubuntu\u309224.04\u306b\u30a2\u30c3\u30d7\u30b0\u30ec\u30fc\u30c9\u3057\u305f\u3089iptables\u306f\u30ec\u30ac\u30b7\u30fc\u306b\u306a\u3063\u3066\u307e\u3057\u305f\u3002<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[8,3],"tags":[],"class_list":["post-13105","post","type-post","status-publish","format-standard","hentry","category-linux","category-3"],"aioseo_notices":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p8SDbY-3pn","jetpack-related-posts":[{"id":839,"url":"https:\/\/taki-lab.site\/bocci\/?p=839","url_meta":{"origin":13105,"position":0},"title":"VPS\u306b\u30d5\u30a1\u30a4\u30a2\u30fc\u30a6\u30a9\u30fc\u30eb\u3092\u8a2d\u5b9a\u3059\u308b","author":"taki","date":"2019\u5e742\u67083\u65e5","format":false,"excerpt":"\u4eca\u56de\u306fVPS\u306b\u30d5\u30a1\u30a4\u30a2\u30fc\u30a6\u30a9\u30fc\u30eb\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002 \u4f7f\u7528\u3059\u308b\u306e\u306fiptables\u3067\u3059\u3002 \u3053\u308c\u3092\u8a2d\u5b9a\u3057\u306a\u3044\u2026","rel":"","context":"Linux","block_context":{"text":"Linux","link":"https:\/\/taki-lab.site\/bocci\/?cat=8"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":843,"url":"https:\/\/taki-lab.site\/bocci\/?p=843","url_meta":{"origin":13105,"position":1},"title":"VPS\u306eFTP\u30dd\u30fc\u30c8\u3092\u5909\u66f4\u3059\u308b","author":"taki","date":"2019\u5e742\u67083\u65e5","format":false,"excerpt":"\u3053\u308c\u306f\u3048\u3089\u3044\u4eba\u304b\u3089\u306e\u6307\u793a\u3067\u8abf\u3079\u305f\u3002 \u307e\u305a\u306f\u3001vsftps\u306b\u30dd\u30fc\u30c8\u8a2d\u5b9a\u3092\u66f8\u304d\u8db3\u3059\u3002 $ sudo vi\u2026","rel":"","context":"Linux","block_context":{"text":"Linux","link":"https:\/\/taki-lab.site\/bocci\/?cat=8"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":13409,"url":"https:\/\/taki-lab.site\/bocci\/?p=13409","url_meta":{"origin":13105,"position":2},"title":"\u306a\u305c\u304b\u7a81\u7136VPS\u306b\u30a2\u30af\u30bb\u30b9\u51fa\u6765\u306a\u304f\u306a\u308b\u554f\u984c\u3002","author":"taki","date":"2025\u5e747\u670827\u65e5","format":false,"excerpt":"\u306a\u305c\u304b\u3053\u3053\u6700\u8fd1\u306b\u306a\u3063\u3066\u3001\u7a81\u7136VPS\u306e\u30d6\u30ed\u30b0\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u306a\u3044\u4e8b\u614b\u304c\u304a\u304d\u307e\u3057\u3066\u3001 \u30d6\u30e9\u30a6\u30b6\u304b\u3089\u30d6\u30ed\u30b0\u306b\u2026","rel":"","context":"Linux","block_context":{"text":"Linux","link":"https:\/\/taki-lab.site\/bocci\/?cat=8"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2025\/07\/386a7216123a64d1bfc688a82390e4e5.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2025\/07\/386a7216123a64d1bfc688a82390e4e5.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2025\/07\/386a7216123a64d1bfc688a82390e4e5.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2025\/07\/386a7216123a64d1bfc688a82390e4e5.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2025\/07\/386a7216123a64d1bfc688a82390e4e5.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2025\/07\/386a7216123a64d1bfc688a82390e4e5.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":841,"url":"https:\/\/taki-lab.site\/bocci\/?p=841","url_meta":{"origin":13105,"position":3},"title":"iptable\u306e\u8a2d\u5b9a\u3092\u4fdd\u5b58\u3059\u308b","author":"taki","date":"2019\u5e742\u67083\u65e5","format":false,"excerpt":"VPS\u3067iptable\u306e\u8a2d\u5b9a\u3057\u307e\u3057\u305f\u304c\u3001 \u3053\u308c\u3060\u3051\u3067\u306f\u518d\u8d77\u52d5\u3059\u308b\u3068\u8a2d\u5b9a\u304c\u6d88\u3048\u3066\u3057\u307e\u3044\u307e\u3059\u3002 \u3053\u308c\u3092\u89e3\u2026","rel":"","context":"Linux","block_context":{"text":"Linux","link":"https:\/\/taki-lab.site\/bocci\/?cat=8"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":4462,"url":"https:\/\/taki-lab.site\/bocci\/?p=4462","url_meta":{"origin":13105,"position":4},"title":"\u30de\u30a4\u30f3\u30af\u30e9\u30d5\u30c8\u30b5\u30fc\u30d0(\u4eee\u60f3PC)\u306b\u30d5\u30a1\u30a4\u30a2\u30fc\u30a6\u30a9\u30fc\u30eb\u3092\u8a2d\u5b9a\u3059\u308b\u3002","author":"taki","date":"2020\u5e7411\u67082\u65e5","format":false,"excerpt":"https:\/\/taki-lab.site\/bocci\/?p=4447 \u3053\u306e\u3084\u308a\u65b9\u3067\u8a2d\u5b9a\u3067\u304d\u308b\u306f\u305a\u3002\u2026","rel":"","context":"\u30b2\u30fc\u30e0","block_context":{"text":"\u30b2\u30fc\u30e0","link":"https:\/\/taki-lab.site\/bocci\/?cat=10"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":11722,"url":"https:\/\/taki-lab.site\/bocci\/?p=11722","url_meta":{"origin":13105,"position":5},"title":"\u3010Linux\u3011php\u30d0\u30fc\u30b8\u30e7\u30f3\u304c\u5909\u308f\u308b\u3068nginx\u306e\u8a2d\u5b9a\u3092\u5909\u3048\u306a\u304f\u3061\u3083\u3044\u3051\u306a\u3044\u306e\u304c\u3081\u3093\u3069\u304f\u3055\u3044\u3002","author":"taki","date":"2024\u5e744\u670818\u65e5","format":false,"excerpt":"\u3053\u308c\u306f\u3001\u5143\u3005VPS\u306b\u30d6\u30ed\u30b0\u30b5\u30fc\u30d0\u3092\u7acb\u3061\u4e0a\u3052\u308b\u306e\u306b VPS\u306bPHP\u3092\u5165\u308c\u308b | \u81ea\u5206\u3001\u307c\u3063\u3061\u3067\u3059\u304c\u4f55\u304b\u2026","rel":"","context":"Linux","block_context":{"text":"Linux","link":"https:\/\/taki-lab.site\/bocci\/?cat=8"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2024\/04\/70f98b945e85e23b7989f307f4752845.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2024\/04\/70f98b945e85e23b7989f307f4752845.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2024\/04\/70f98b945e85e23b7989f307f4752845.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2024\/04\/70f98b945e85e23b7989f307f4752845.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/taki-lab.site\/bocci\/wp-content\/uploads\/2024\/04\/70f98b945e85e23b7989f307f4752845.png?resize=1050%2C600&ssl=1 3x"},"classes":[]}],"jetpack_likes_enabled":true,"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/taki-lab.site\/bocci\/index.php?rest_route=\/wp\/v2\/posts\/13105","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/taki-lab.site\/bocci\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/taki-lab.site\/bocci\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/taki-lab.site\/bocci\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/taki-lab.site\/bocci\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13105"}],"version-history":[{"count":1,"href":"https:\/\/taki-lab.site\/bocci\/index.php?rest_route=\/wp\/v2\/posts\/13105\/revisions"}],"predecessor-version":[{"id":13107,"href":"https:\/\/taki-lab.site\/bocci\/index.php?rest_route=\/wp\/v2\/posts\/13105\/revisions\/13107"}],"wp:attachment":[{"href":"https:\/\/taki-lab.site\/bocci\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/taki-lab.site\/bocci\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13105"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/taki-lab.site\/bocci\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}