社区讨论
add action=dst-nat chain=dstnat comment="SSH server" dst-address=159.54.54.54 dst-port=3999 protocol=tcp src-address=[填写允许的IP地址]to-addresses=10.0.0.2 to-ports=22
nox@macbook ~ % ssh -p 3999 root@159.54.54.54 ssh:连接主机159.54.54.54端口3999:操作超时
[admin@雷竞技网站MikroTik] > ping 10.0.0.2 SEQ HOST SIZE TTL TIME STATUS 0 10.0.0.2 56 64 0ms 1 10.0.0.2 56 64 0ms 2 10.0.0.2 56 64 0ms 3 10.0.0.2 56 64 0ms sent=4 received=4 packet-loss=0% min-rtt=0ms avg-rtt=0ms max-rtt=0ms
user@randomPC:~# ssh root@10.0.0.2权限被拒绝(公钥)。
[admin@雷竞技网站MikroTik] > /ip firewall export # jun/25/2021 05:21:04 by l雷竞技RouterOS 雷电竞app下载官方版苹果6.48.3 # software id = # # # /ip firewall nat add action=dst-nat chain=dstnat comment="SSH server" dst-address=\ 159.54.54.54 dst-port=3999 log=yes protocol=tcp src-address=\ 104.230.44.200 to-addresses=10.0.0.2 to-ports=22 [admin@MikroTik] >
root@server:~# ps aux | grep SSHD root 692 0.0 0.3 12176 7508 ?s Jun24 00:00 sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups root 14182 0.0 0.4 13808 9008 ?S 09:11 0:00 sshd: root@pts/0 root 14330 0.0 0.0 8160 736 pts/0 S+ 09:32 0:00 grep—color=auto sshd
root@server:~# netstat -plant | grep:22 tcp 00 0.0.0.0:22 0.0.0.0:* LISTEN 692/sshd: /usr/sbin tcp 0 36 159.54.54.54:22 104.230.44.200:49651 ESTABLISHED 14182/sshd: root@pt tcp6 00:::22:::* LISTEN 692/sshd: /usr/sbin
/ip firewall nat remove [find where comment="SSH server"] add action=dst-nat chain=dstnat comment=" nat SSH" dst-address=159.54.54.54 dst-port=3999 protocol=tcp to-addresses=10.0.0.2 to-ports=22 add action=src-nat chain=srcnat comment="reverse path SSH" dst-address=10.0.0.2 to-addresses=10.0.0.1
/ip firewall raw add action=drop chain=prerouting dst-address=159.54.54.54 dst-port=3999 protocol=tcp src-address-list=!allowed_ssh_access
在图表上是缺少什么IP有服务器端的CHR假设CHR可以ping 10.0.0.2(测试!)服务器端IP为10.0.0.1 (/24? 将此粘贴到终端并重试: 代码:选择所有 /ip firewall nat remove [find where comment="SSH server"] add action=dst-nat chain=dstnat comment=" nat SSH" dst-address=159.54.54.54 dst-port=3999 protocol=tcp to-addresses=10.0.0.2 to-ports=22 add action=src-nat chain=srcnat comment="reverse path SSH" dst-address=10.0.0.2 to-addresses=10.0.0.1 警告:您没有任何规则来保护CHR免受互联网的侵害。
让包裹进入办公室,然后再检查它们是否危险,即使里面有炸弹,