/l3/trainings/nt-lnet/2006-02-18/fbsd2/root :1 :2 :3 :4 :5 :6 :7 :8 :9 :10 :11 :12 :13 :14 :15 :16 :17 :18 :19 :20 :21 :22 :23 :24 |
|
#[root@fbsd2:~]# ipfw show
00030 2 120 allow tcp from any to me dst-port 22 setup 00030 2 128 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 2350809 1976312998 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 40 4190 allow udp from me to any dst-port 53 keep-state 01000 46 3413 unreach port udp from any to any 01200 12 1008 allow icmp from me to any keep-state 01300 0 0 deny icmp from any to any 64000 15 1016 count log ip from any to any 65000 11934055 9850110469 allow ip from any to any 65535 16 8360 deny ip from any to any |
#ipfw zeroo
ipfw: bad command `zeroo' |
#ipfw zero
Accounting cleared. |
#[root@fbsd2:~]# ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 10344 8320204 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any dst-port 53 keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 01300 0 0 deny icmp from any to any 64000 0 0 count log ip from any to any 65000 0 0 allow ip from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 14024 11236380 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any dst-port 53 keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 01300 0 0 deny icmp from any to any 64000 0 0 count log ip from any to any 65000 0 0 allow ip from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 20200 16118344 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any dst-port 53 keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 01300 0 0 deny icmp from any to any 64000 0 0 count log ip from any to any 65000 0 0 allow ip from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 45186 37393524 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any dst-port 53 keep-state 01000 3 234 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 01300 0 0 deny icmp from any to any 64000 0 0 count log ip from any to any 65000 0 0 allow ip from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 707171 577715392 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 6 468 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 01300 0 0 deny icmp from any to any 64000 0 0 count log ip from any to any 65000 0 0 allow ip from any to any 65535 0 0 deny ip from any to any |
#[root@fbsd2:~]# ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 178216 144675188 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any dst-port 53 keep-state 01000 3 234 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 01300 0 0 deny icmp from any to any 64000 0 0 count log ip from any to any 65000 0 0 allow ip from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 185535 150545984 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any dst-port 53 keep-state 01000 3 234 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 01300 0 0 deny icmp from any to any 64000 0 0 count log ip from any to any 65000 0 0 allow ip from any to any 65535 0 0 deny ip from any to any |
#ipfw delete 50
|
#ipfw add 50 allow udp from me to any keep-state
00050 allow udp from me to any keep-state |
#[root@fbsd2:~]# ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 553909 450561012 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 6 468 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 01300 0 0 deny icmp from any to any 64000 0 0 count log ip from any to any 65000 0 0 allow ip from any to any 65535 0 0 deny ip from any to any |
#ping 192.168.15..4
ping: cannot resolve 192.168.15..254: Unknown host |
#ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 1020307 830460940 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 4 351 allow udp from me to any keep-state 01000 9 702 unreach port udp from any to any 01200 18 1512 allow icmp from me to any keep-state 64000 61 2484 count log ip from any to any 65535 61 2484 deny ip from any to any |
#ping 192.168.15.254
PING 192.168.15.254 (192.168.15.254): 56 data bytes 64 bytes from 192.168.15.254: icmp_seq=0 ttl=64 time=0.781 ms 64 bytes from 192.168.15.254: icmp_seq=1 ttl=64 time=0.328 ms 64 bytes from 192.168.15.254: icmp_seq=2 ttl=64 time=0.296 ms 64 bytes from 192.168.15.254: icmp_seq=3 ttl=64 time=0.716 ms ^C --- 192.168.15.254 ping statistics --- 4 packets transmitted, 4 packets received, 0% packet loss round-trip min/avg/max/stddev = 0.296/0.530/0.781/0.220 ms |
#ipfw delete 1300
|
#ipfw delete 65000
|
#[root@fbsd2:~]# ping 192.168.15.254
PING 192.168.15.254 (192.168.15.254): 56 data bytes 64 bytes from 192.168.15.254: icmp_seq=0 ttl=64 time=0.337 ms 64 bytes from 192.168.15.254: icmp_seq=1 ttl=64 time=1.042 ms 64 bytes from 192.168.15.254: icmp_seq=2 ttl=64 time=0.295 ms 64 bytes from 192.168.15.254: icmp_seq=3 ttl=64 time=0.329 ms 64 bytes from 192.168.15.254: icmp_seq=4 ttl=64 time=0.529 ms ^C --- 192.168.15.254 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max/stddev = 0.295/0.506/1.042/0.280 ms |
#ping show
ping: cannot resolve show: No address associated with name |
#ipfw
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 913856 742975220 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 4 351 allow udp from me to any keep-state 01000 6 468 unreach port udp from any to any 01200 18 1512 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65535 0 0 deny ip from any to any |
#ipfw add 65000 reset tcp from any to any
65000 reset tcp from any to any |
#[root@fbsd2:~]# ipf show
usage: ipf [-6AdDEInoPrRsvVyzZ] [-l block|pass|nomatch|state|nat] [-cc] [-F i|o|a|s|S|u] [-f filename] [-T <tuneopts>] |
#ipfwshow
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 1193058 969442416 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 4 351 allow udp from me to any keep-state 01000 9 702 unreach port udp from any to any 01200 18 1512 allow icmp from me to any keep-state 64000 61 2484 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 61 2484 deny ip from any to any |
#ipfw zero
Accounting cleared. |
#ipfw list
00030 allow tcp from any to me dst-port 22 setup 00030 allow tcp from any to me dst-port 25 setup 00030 allow tcp from any to me dst-port 80 setup 00035 allow tcp from any to any established 00040 allow udp from any to me dst-port 53 in keep-state 00050 allow udp from me to any keep-state 01000 unreach port udp from any to any 01200 allow icmp from me to any keep-state 64000 count log ip from any to any 65000 reset tcp from any to any 65535 deny ip from any to any |
#ipfw show
00030 2 100 allow tcp from any to me dst-port 22 setup 00030 1 40 allow tcp from any to me dst-port 25 setup 00030 1 40 allow tcp from any to me dst-port 80 setup 00035 1535570 1259821498 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 40 3623 allow udp from me to any keep-state 01000 12 936 unreach port udp from any to any 01200 18 1512 allow icmp from me to any keep-state 64000 1718 68764 count log ip from any to any 65000 1657 66280 reset tcp from any to any 65535 61 2484 deny ip from any to any |
#ipfw list
00030 allow tcp from any to me dst-port 22 setup 00030 allow tcp from any to me dst-port 25 setup 00030 allow tcp from any to me dst-port 80 setup 00035 allow tcp from any to any established 00040 allow udp from any to me dst-port 53 in keep-state 00050 allow udp from me to any keep-state 01000 unreach port udp from any to any 01200 allow icmp from me to any keep-state 64000 count log ip from any to any 65000 reset tcp from any to any 65535 deny ip from any to any |
#[root@fbsd2:~]# ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 29564 23962720 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 32490 26274236 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 34208 27604788 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#[root@fbsd2:~]# ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 75581 60967304 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw list | grep -v ^65535 | sed s/^ /add \/
sed: 1: "s/^": unterminated substitute pattern |
#ipfw list | sed s/^/add\ /
add 00030 allow tcp from any to me dst-port 22 setup add 00030 allow tcp from any to me dst-port 25 setup add 00030 allow tcp from any to me dst-port 80 setup add 00035 allow tcp from any to any established add 00040 allow udp from any to me dst-port 53 in keep-state add 00050 allow udp from me to any keep-state add 01000 unreach port udp from any to any add 01200 allow icmp from me to any keep-state add 64000 count log ip from any to any add 65000 reset tcp from any to any add 65535 deny ip from any to any |
#ipfw list | grep -v ^65535 |
add 00030 allow tcp from any to me dst-port 22 setup add 00030 allow tcp from any to me dst-port 25 setup add 00030 allow tcp from any to me dst-port 80 setup add 00035 allow tcp from any to any established add 00040 allow udp from any to me dst-port 53 in keep-state add 00050 allow udp from me to any keep-state add 01000 unreach port udp from any to any add 01200 allow icmp from me to any keep-state add 64000 count log ip from any to any add 65000 reset tcp from any to any |
#ipfw list | grep -v ^65535 | sed s/^/add\ / Ð> /etc/myfirewall
sed: Ð: No such file or directory |
#ipfw list | grep -v ^65535 | sed s/^/add\ / > /etc/myfirewall
|
#vi /etc/myfirewall
|
#vi /etc/rc.con
|
#vi /etc/rc.conf
31a32,35 > > firewall_enable="YES" > firewall_type="/etc/myfirewall" > |
#l3-agent
l3-agent is already running: pid=562; pidfile=/root/.lilalo/l3-agent.pid |
#ps waux | grep l3-age
|
#rm /root/.lilalo/l3-agent.pid
|
#ipfw list | grep -v ^65535 | sed s/^add \/
sed: 1: "s/^/add": unterminated substitute in regular expression |
#hostname
fbsd2 |
#ipfw list | grep -v ^65535
00030 allow tcp from any to me dst-port 22 setup 00030 allow tcp from any to me dst-port 25 setup 00030 allow tcp from any to me dst-port 80 setup 00035 allow tcp from any to any established 00040 allow udp from any to me dst-port 53 in keep-state 00050 allow udp from me to any keep-state 01000 unreach port udp from any to any 01200 allow icmp from me to any keep-state 64000 count log ip from any to any 65000 reset tcp from any to any |
#ipfw list | grep -v ^65535 | sed s/^
sed: 1: "s/^": unterminated substitute pattern |
#w
17:29 up 8:07, 8 users, load averages: 1,39 1,11 0,94 USER TTY FROM LOGIN@ IDLE WHAT root v0 - 9:25 13 script -t 0 -q /root/.lilalo/ttyv0 user v1 - 9:25 8:03 script -t 0 -q /home/user/.lilalo/ root v2 - 9:25 8:02 script -t 0 -q /root/.lilalo/ttyv2 root v4 - 10:15 7:13 script -t 0 -q /root/.lilalo/ttyv4 root p4 192.168.15.215 17:03 1 script -t 0 -q /root/.lilalo/ttyp4 root p6 :0.0 14:15 3:12 script -t 0 -q /root/.lilalo/ttyp6 root p8 192.168.15.215 14:20 1:51 script -t 0 -q /root/.lilalo/ttyp8 root pa linux.nt 17:19 - script -t 0 -q /root/.lilalo/ttypa |
#netstat -ln
Active Internet connections Proto Recv-Q Send-Q Local Address Foreign Address (state) tcp4 0 0 192.168.15.22.22 192.168.15.254.53674 ESTABLISHED tcp4 0 0 192.168.15.22.22 192.168.15.215.39619 ESTABLISHED tcp4 0 0 192.168.15.22.22 192.168.15.215.39911 ESTABLISHED tcp4 0 10984 192.168.15.22.22 192.168.15.215.35625 ESTABLISHED Netgraph sockets Type Recv-Q Send-Q Node Address #Hooks ctrl 0 0 data 0 0 ... c26f3e38 dgram 0 0 0 c26f2e38 0 c2ad3118 c2ad3118 dgram 0 0 0 c26f2e38 0 c26f2834 c26f2834 dgram 0 0 0 c26f2e38 0 c26f28c0 c26f28c0 dgram 0 0 0 c26f2e38 0 c26f294c c26f294c dgram 0 0 0 c26f2e38 0 c26f29d8 c26f29d8 dgram 0 0 0 c26f2e38 0 c26f2d20 c26f2af0 dgram 0 0 0 c26f2ec4 0 0 c26f2d20 dgram 0 0 0 c26f2e38 0 0 c26f2e38 dgram 0 0 c26f9cc0 0 c26f3e38 0 /var/run/logpriv c26f2ec4 dgram 0 0 c26f9dd0 0 c26f2af0 0 /var/run/log |
#netstat -ln -A inet
Active Internet connections Socket Proto Recv-Q Send-Q Local Address Foreign Address (state) c274b000 tcp4 0 0 192.168.15.22.22 192.168.15.254.53674 ESTABLISHED c274c398 tcp4 0 0 192.168.15.22.22 192.168.15.215.39619 ESTABLISHED c274b398 tcp4 0 0 192.168.15.22.22 192.168.15.215.39911 ESTABLISHED c274b8fc tcp4 0 4368 192.168.15.22.22 192.168.15.215.35625 ESTABLISHED Netgraph sockets PCB Type Recv-Q Send-Q Node Address #Hooks c25b6d40 ctrl 0 0 c25b6de0 data 0 0 ... c26f3e38 dgram 0 0 0 c26f2e38 0 c2ad3118 c2ad3118 dgram 0 0 0 c26f2e38 0 c26f2834 c26f2834 dgram 0 0 0 c26f2e38 0 c26f28c0 c26f28c0 dgram 0 0 0 c26f2e38 0 c26f294c c26f294c dgram 0 0 0 c26f2e38 0 c26f29d8 c26f29d8 dgram 0 0 0 c26f2e38 0 c26f2d20 c26f2af0 dgram 0 0 0 c26f2ec4 0 0 c26f2d20 dgram 0 0 0 c26f2e38 0 0 c26f2e38 dgram 0 0 c26f9cc0 0 c26f3e38 0 /var/run/logpriv c26f2ec4 dgram 0 0 c26f9dd0 0 c26f2af0 0 /var/run/log |
#netstat -n -A inet
Active Internet connections Socket Proto Recv-Q Send-Q Local Address Foreign Address (state) c274b000 tcp4 0 0 192.168.15.22.22 192.168.15.254.536 ESTABLISHED c274c398 tcp4 0 0 192.168.15.22.22 192.168.15.215.396 ESTABLISHED c274b398 tcp4 0 0 192.168.15.22.22 192.168.15.215.399 ESTABLISHED c274b8fc tcp4 0 2648 192.168.15.22.22 192.168.15.215.356 ESTABLISHED Netgraph sockets PCB Type Recv-Q Send-Q Node Address #Hooks c25b6d40 ctrl 0 0 c25b6de0 data 0 0 ... c26f3e38 dgram 0 0 0 c26f2e38 0 c2ad3118 c2ad3118 dgram 0 0 0 c26f2e38 0 c26f2834 c26f2834 dgram 0 0 0 c26f2e38 0 c26f28c0 c26f28c0 dgram 0 0 0 c26f2e38 0 c26f294c c26f294c dgram 0 0 0 c26f2e38 0 c26f29d8 c26f29d8 dgram 0 0 0 c26f2e38 0 c26f2d20 c26f2af0 dgram 0 0 0 c26f2ec4 0 0 c26f2d20 dgram 0 0 0 c26f2e38 0 0 c26f2e38 dgram 0 0 c26f9cc0 0 c26f3e38 0 /var/run/logpriv c26f2ec4 dgram 0 0 c26f9dd0 0 c26f2af0 0 /var/run/log |
#netstat -n -finet
Active Internet connections Proto Recv-Q Send-Q Local Address Foreign Address (state) tcp4 0 0 192.168.15.22.22 192.168.15.254.53674 ESTABLISHED tcp4 0 0 192.168.15.22.22 192.168.15.215.39619 ESTABLISHED tcp4 0 0 192.168.15.22.22 192.168.15.215.39911 ESTABLISHED tcp4 0 4728 192.168.15.22.22 192.168.15.215.35625 ESTABLISHED |
#telnet unix.nt 25
Trying 192.168.15.254... telnet: connect to address 192.168.15.254: Permission denied telnet: Unable to connect to remote host |
#ipfw list
00030 allow tcp from any to me dst-port 22 setup 00030 allow tcp from any to me dst-port 25 setup 00030 allow tcp from any to me dst-port 80 setup 00035 allow tcp from any to any established 00040 allow udp from any to me dst-port 53 in keep-state 00050 allow udp from me to any keep-state 01000 unreach port udp from any to any 01200 allow icmp from me to any keep-state 64000 count log ip from any to any 65000 reset tcp from any to any 65535 deny ip from any to any |
#ipfw show
00030 0 0 allow tcp from any to me dst-port 22 setup 00030 2 128 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 743187 626688546 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 50 4372 allow udp from me to any keep-state 01000 3 234 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 14 896 count log ip from any to any 65000 14 896 reset tcp from any to any 65535 0 0 deny ip from any to any |
#[root@fbsd2:~]# ipfw show
00010 4770 6407486 allow ip from me to any 00030 2 120 allow tcp from any to me dst-port 22 setup 00030 2 128 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 941668 840917602 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 98 8580 allow udp from me to any keep-state 01000 6 468 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 25 1600 count log ip from any to any 65000 25 1600 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw delete 10
|
#[root@fbsd2:~]# ipfw show
00010 4768 6092944 allow tcp from me to any 00030 2 120 allow tcp from any to me dst-port 22 setup 00030 2 128 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 1057969 866614094 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 98 8580 allow udp from me to any keep-state 01000 15 1336 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 27 1728 count log ip from any to any 65000 27 1728 reset tcp from any to any 65535 0 0 deny ip from any to any |
#host unix.nt
|
#hist linux.nt
bash: hist: command not found |
#hot linux.nt
|
#host mail.ru
|
#ipfw list
00010 allow ip from me to any 00030 allow tcp from any to me dst-port 22 setup 00030 allow tcp from any to me dst-port 25 setup 00030 allow tcp from any to me dst-port 80 setup 00035 allow tcp from any to any established 00040 allow udp from any to me dst-port 53 in keep-state 00050 allow udp from me to any keep-state 01000 unreach port udp from any to any 01200 allow icmp from me to any keep-state 64000 count log ip from any to any 65000 reset tcp from any to any 65535 deny ip from any to any |
#shutdown -p now
Shutdown NOW! shutdown: [pid 14409] |
#ipfw show
00020 5 320 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 189951 156962295 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 3 234 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw zero
Accounting cleared. |
#[root@fbsd2:~]# ipfw show
00010 4455 5750029 allow tcp from me to any 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 3066 220832 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00010 22252 28572744 allow tcp from me to any 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 15231 1098148 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00010 25600 32951272 allow tcp from me to any 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 17457 1262572 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00010 28956 37454272 allow tcp from me to any 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 19758 1432288 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#[root@fbsd2:~]# ipfw show
00010 43316 56509028 allow tcp from me to any 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 29854 2168584 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw add 20 allow tcp from me any setup
00020 allow tcp from me to any setup |
#[root@fbsd2:~]# ipfw show
00010 98021 129956543 allow tcp from me to any 00020 0 0 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 67469 4934544 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw delete 10
|
#[root@fbsd2:~]# ipfw show
00020 0 0 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 87709 10613912 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 1 64 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 92130 14332466 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 1 64 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 93961 15778402 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 1 64 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 98000 19053934 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 1 64 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 99618 20391234 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw zero
Accounting cleared. |
#[root@fbsd2:~]# ipfw show
00020 0 0 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 7046 5754296 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 1 64 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 9773 8198169 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 1 64 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 13954 11640397 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 1 64 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 15888 13235101 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 1 64 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 18314 15202785 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 1 64 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 20179 16674949 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 1 64 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 21293 17586377 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 2 128 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 24229 20083885 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 2 128 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 26578 22169217 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 2 128 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 27933 23282129 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 2 128 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 29795 24838769 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
#ipfw show
00020 2 128 allow tcp from me to any setup 00030 0 0 allow tcp from any to me dst-port 22 setup 00030 0 0 allow tcp from any to me dst-port 25 setup 00030 0 0 allow tcp from any to me dst-port 80 setup 00035 31638 26394605 allow tcp from any to any established 00040 0 0 allow udp from any to me dst-port 53 in keep-state 00050 0 0 allow udp from me to any keep-state 01000 0 0 unreach port udp from any to any 01200 0 0 allow icmp from me to any keep-state 64000 0 0 count log ip from any to any 65000 0 0 reset tcp from any to any 65535 0 0 deny ip from any to any |
Время первой команды журнала | 17:04:07 2006- 2-25 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Время последней команды журнала | 17:39:04 2006- 2-25 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Количество командных строк в журнале | 101 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Процент команд с ненулевым кодом завершения, % | 15.84 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Процент синтаксически неверно набранных команд, % | 0.99 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Суммарное время работы с терминалом *, час | 0.58 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Количество командных строк в единицу времени, команда/мин | 2.89 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Частота использования команд |
|
В журнал автоматически попадают все команды, данные в любом терминале системы.
Для того чтобы убедиться, что журнал на текущем терминале ведётся, и команды записываются, дайте команду w. В поле WHAT, соответствующем текущему терминалу, должна быть указана программа script.
Команды, при наборе которых были допущены синтаксические ошибки, выводятся перечёркнутым текстом:
$ l s-l bash: l: command not found |
Если код завершения команды равен нулю, команда была выполнена без ошибок. Команды, код завершения которых отличен от нуля, выделяются цветом.
$ test 5 -lt 4 |
Команды, ход выполнения которых был прерван пользователем, выделяются цветом.
$ find / -name abc find: /home/devi-orig/.gnome2: Keine Berechtigung find: /home/devi-orig/.gnome2_private: Keine Berechtigung find: /home/devi-orig/.nautilus/metafiles: Keine Berechtigung find: /home/devi-orig/.metacity: Keine Berechtigung find: /home/devi-orig/.inkscape: Keine Berechtigung ^C |
Команды, выполненные с привилегиями суперпользователя, выделяются слева красной чертой.
# id uid=0(root) gid=0(root) Gruppen=0(root) |
Изменения, внесённые в текстовый файл с помощью редактора, запоминаются и показываются в журнале в формате ed. Строки, начинающиеся символом "<", удалены, а строки, начинающиеся символом ">" -- добавлены.
$ vi ~/.bashrc
|
Для того чтобы изменить файл в соответствии с показанными в диффшоте изменениями, можно воспользоваться командой patch. Нужно скопировать изменения, запустить программу patch, указав в качестве её аргумента файл, к которому применяются изменения, и всавить скопированный текст:
$ patch ~/.bashrc |
Для того чтобы получить краткую справочную информацию о команде, нужно подвести к ней мышь. Во всплывающей подсказке появится краткое описание команды.
Если справочная информация о команде есть, команда выделяется голубым фоном, например: vi. Если справочная информация отсутствует, команда выделяется розовым фоном, например: notepad.exe. Справочная информация может отсутствовать в том случае, если (1) команда введена неверно; (2) если распознавание команды LiLaLo выполнено неверно; (3) если информация о команде неизвестна LiLaLo. Последнее возможно для редких команд.
Большие, в особенности многострочные, всплывающие подсказки лучше всего показываются браузерами KDE Konqueror, Apple Safari и Microsoft Internet Explorer. В браузерах Mozilla и Firefox они отображаются не полностью, а вместо перевода строки выводится специальный символ.
Время ввода команды, показанное в журнале, соответствует времени начала ввода командной строки, которое равно тому моменту, когда на терминале появилось приглашение интерпретатора
Имя терминала, на котором была введена команда, показано в специальном блоке. Этот блок показывается только в том случае, если терминал текущей команды отличается от терминала предыдущей.
Вывод не интересующих вас в настоящий момент элементов журнала, таких как время, имя терминала и других, можно отключить. Для этого нужно воспользоваться формой управления журналом вверху страницы.
Небольшие комментарии к командам можно вставлять прямо из командной строки. Комментарий вводится прямо в командную строку, после символов #^ или #v. Символы ^ и v показывают направление выбора команды, к которой относится комментарий: ^ - к предыдущей, v - к следующей. Например, если в командной строке было введено:
$ whoami
user
$ #^ Интересно, кто я?в журнале это будет выглядеть так:
$ whoami
user
Интересно, кто я? |
Если комментарий содержит несколько строк, его можно вставить в журнал следующим образом:
$ whoami
user
$ cat > /dev/null #^ Интересно, кто я?
Программа whoami выводит имя пользователя, под которым мы зарегистрировались в системе. - Она не может ответить на вопрос о нашем назначении в этом мире.В журнале это будет выглядеть так:
$ whoami user
|
Комментарии, не относящиеся непосредственно ни к какой из команд, добавляются точно таким же способом, только вместо симолов #^ или #v нужно использовать символы #=
1 2 3 4Группы команд, выполненных на разных терминалах, разделяются специальной линией. Под этой линией в правом углу показано имя терминала, на котором выполнялись команды. Для того чтобы посмотреть команды только одного сенса, нужно щёкнуть по этому названию.
LiLaLo (L3) расшифровывается как Live Lab Log.
Программа разработана для повышения эффективности обучения Unix/Linux-системам.
(c) Игорь Чубин, 2004-2008