当前位置: 技术问答>linux和unix
请大侠帮忙看一下下面的一组命令是干什么的???
来源: 互联网 发布时间:2016-04-16
本文导语: 命令组1: /usr/local/sbin/iptables -t mangle -F; rmmod ipt_nmsensor; insmod /lib/modules/`uname -r`/kernel/net/ipv4/netfilter/ipt_nmsensor.ko; rm -f /dev/httpsensormap; mknod /dev/httpsensormap c `cat /proc/devices | grep httpmmap | awk '{print $1}'` 0;" ...
命令组1:
/usr/local/sbin/iptables -t mangle -F;
rmmod ipt_nmsensor;
insmod /lib/modules/`uname -r`/kernel/net/ipv4/netfilter/ipt_nmsensor.ko;
rm -f /dev/httpsensormap;
mknod /dev/httpsensormap c `cat /proc/devices | grep httpmmap | awk '{print $1}'` 0;"
命令组2:
/usr/local/sbin/iptables -t mangle -F;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br1 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br2 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br3 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br4 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br5 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br6 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br7 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br8 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br9 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br10 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br11 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br12 -m nmsensor --http -j DROP;"
命令组3:
/usr/local/sbin/iptables -t mangle -F
/usr/local/sbin/iptables -t mangle -F;
rmmod ipt_nmsensor;
insmod /lib/modules/`uname -r`/kernel/net/ipv4/netfilter/ipt_nmsensor.ko;
rm -f /dev/httpsensormap;
mknod /dev/httpsensormap c `cat /proc/devices | grep httpmmap | awk '{print $1}'` 0;"
命令组2:
/usr/local/sbin/iptables -t mangle -F;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br1 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br2 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br3 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br4 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br5 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br6 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br7 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br8 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br9 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br10 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br11 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br12 -m nmsensor --http -j DROP;"
命令组3:
/usr/local/sbin/iptables -t mangle -F
|
命令组1:
/usr/local/sbin/iptables -t mangle -F; // 刷新table mangle里的所有rules
rmmod ipt_nmsensor; // 重新加载模块ipt_nmsensor
insmod /lib/modules/`uname -r`/kernel/net/ipv4/netfilter/ipt_nmsensor.ko;
rm -f /dev/httpsensormap; // 重新创建设备节点:/dev/httpsensormap
mknod /dev/httpsensormap c `cat /proc/devices | grep httpmmap | awk '{print $1}'` 0;"
命令组2:
/usr/local/sbin/iptables -t mangle -F; // 刷新mangle table里的全部规则
//在链PREROUTING中定义11(从接口br1到br11)条规则: 该规则采用你前面加载的模块nmsensor来进行包过滤。
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br1 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br2 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br3 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br4 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br5 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br6 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br7 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br8 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br9 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br10 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br11 -m nmsensor --http -j DROP;
/usr/local/sbin/iptables -t mangle -A PREROUTING -p tcp -i br12 -m nmsensor --http -j DROP;"