linux系统可以ping,Linux系统禁ping
1.修改配置文件對系統(tǒng)臨時生效,系統(tǒng)重啟后設(shè)置不起作用。
[root@208 ~]# echo? "1" > /proc/sys/net/ipv4/icmp_echo_ignore_all
2.永久生效,修改系統(tǒng)的配置文件
[root@208 ~]# vim /etc/sysctl.conf
net.ipv4.icmp_echo_ignore_all = 1? ? ? ? ? --添加這一行
[root@208 ~]# sysctl? -p
net.ipv4.ip_forward = 0
net.ipv4.conf.default.rp_filter = 1
net.ipv4.conf.default.accept_source_route = 0
kernel.sysrq = 0
kernel.core_uses_pid = 1
net.ipv4.tcp_syncookies = 1
net.bridge.bridge-nf-call-ip6tables = 0
net.bridge.bridge-nf-call-iptables = 0
net.bridge.bridge-nf-call-arptables = 0
net.ipv4.icmp_echo_ignore_all = 1
net.ipv4.conf.all.arp_notify = 1
3.如果生效時有錯誤,錯誤處理
[root@208 ~]# sysctl? -p
net.ipv4.ip_forward = 0
net.ipv4.conf.default.rp_filter = 1
net.ipv4.conf.default.accept_source_route = 0
kernel.sysrq = 0
kernel.core_uses_pid = 1
net.ipv4.tcp_syncookies = 1
error: "net.bridge.bridge-nf-call-ip6tables" is an unknown key? ? --錯誤信息
error: "net.bridge.bridge-nf-call-iptables" is an unknown key
error: "net.bridge.bridge-nf-call-arptables" is an unknown key
net.ipv4.icmp_echo_ignore_all = 1
net.ipv4.conf.all.arp_notify = 1
解決方法:
[root@208 ~]# modprobe bridge
[root@208 ~]# lsmod | grep bridge
bridge? ? ? ? ? ? ? ? 83177? 0
stp? ? ? ? ? ? ? ? ? ? 2218? 1 bridge
llc? ? ? ? ? ? ? ? ? ? 5546? 2 bridge,stp
推薦閱讀:
總結(jié)
以上是生活随笔為你收集整理的linux系统可以ping,Linux系统禁ping的全部內(nèi)容,希望文章能夠幫你解決所遇到的問題。
- 上一篇: 怎么用python进行回归预测_使用Py
- 下一篇: python后台返回cookie_Dja