时间:2021-07-01 10:21:17 帮助过:28人阅读
- <span style="color: #000000;">ntp
- </span><span style="color: #800080;">1</span><span style="color: #000000;">.作用:同步时间.
- </span><span style="color: #800080;">2</span><span style="color: #000000;">.原理:分层式结构.
- </span><span style="color: #800080;">3</span><span style="color: #000000;">.软件:el6:ntp
- el7:chrony
- </span><span style="color: #800080;">4</span>.el6主配置文件 /etc/<span style="color: #000000;">ntp.conf
- restrict </span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.0</span> mask <span style="color: #800080;">255.255</span>.<span style="color: #800080;">255.0</span> --><span style="color: #000000;">允许谁来和我做同步
- server </span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.10</span> --><span style="color: #000000;">我要找谁做同步
- 特殊的表达方式 </span><span style="color: #800080;">127.127</span>.<span style="color: #800080;">1.0</span><span style="color: #000000;"> 代表的是本地系统时间.
- 和本地时间同步,指定层数的方式:
- server </span><span style="color: #800080;">127.127</span>.<span style="color: #800080;">1.0</span><span style="color: #000000;"> fudge
- </span><span style="color: #800080;">127.127</span>.<span style="color: #800080;">1.0</span> stratum <span style="color: #800080;">10</span><span style="color: #000000;">
- 在客户端上,使用ntpdate </span>-u <span style="color: #800080;">172.25</span>.<span style="color: #800080;">0</span><span style="color: #000000;">.11来同步时间
- 当我们重启ntp服务后,需要等5</span>-<span style="color: #000000;">10分钟才能够被同步成功.
- </span><span style="color: #800080;">5</span>. el7 主配置文件 /etc/<span style="color: #000000;">chrony.conf
- allow </span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0</span>/<span style="color: #800080;">24</span> --><span style="color: #000000;"> 允许谁来和我做同步
- server </span>--><span style="color: #000000;">和谁做同步
- 和本地时间做同步,指定层数的方式
- server </span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.10</span><span style="color: #000000;">
- local stratum </span><span style="color: #800080;">10</span><span style="color: #000000;">
- 在客户端上,使用ntpdate </span>-u <span style="color: #800080;">172.25</span>.<span style="color: #800080;">0</span><span style="color: #000000;">.10来和服务端做同步
- </span><span style="color: #800080;">6</span><span style="color: #000000;">.启服务
- el6 service ntpd restart
- el7 systemctl restart chronyd.service
- </span>
- <span style="color: #0000ff;">ftp</span>
- <span style="color: #800080;">1</span><span style="color: #000000;">.作用:共享文件
- </span><span style="color: #800080;">2</span><span style="color: #000000;">.软件 vsftpd
- </span><span style="color: #800080;">3</span><span style="color: #000000;">.工作原理:
- 主动模式: 服务端21号端口处理链接请求,通过20号端口向客户端传输数据.
- 被动模式: 服务端通过21端口处理链接请求,随后开启一个随即端口号通知客户端从该端口号获取数据.
- </span><span style="color: #800080;">4</span><span style="color: #000000;">.vsftpd支持的用户类型:匿名用户和本地用户
- 匿名用户:在ftp服务器中没有指定账户,但是能访问ftp服务器相应资源的用户.
- 本地用户:</span>/etc/<span style="color: #000000;">passwd用户
- </span><span style="color: #800080;">5</span><span style="color: #000000;">.vsftpd结构
- </span><span style="color: #800080;">1</span>) 主配置文件/etc/vsftpd/<span style="color: #000000;">vsftpd.conf
- </span><span style="color: #800080;">2</span>) 数据文件 /var/<span style="color: #0000ff;">ftp</span>/<span style="color: #000000;">pub 目录
- </span><span style="color: #800080;">6</span><span style="color: #000000;">.访问方式
- </span><span style="color: #800080;">1</span>) 匿名访问 [<span style="color: #800080;">1</span>] 浏览器ftp:<span style="color: #008000;">//</span><span style="color: #008000;">172.25.0.11/pub/</span>
- lftp工具 --><span style="color: #000000;">对应的软件名:lftp
- [</span><span style="color: #800080;">2</span><span style="color: #000000;">] lftp ip地址
- [root@rhel7 </span>~]# lftp <span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span><span style="color: #000000;">
- lftp </span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span>:~> <span style="color: #0000ff;">ls</span><span style="color: #000000;">
- drwxr</span>-xr-x <span style="color: #800080;">2</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">4096</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> pub
- lftp </span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span>:/> cd pub/<span style="color: #000000;">
- lftp </span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span>:/pub> <span style="color: #0000ff;">ls</span>
- -rw-r--r-- <span style="color: #800080;">1</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> file1
- </span>-rw-r--r-- <span style="color: #800080;">1</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> file10
- </span>-rw-r--r-- <span style="color: #800080;">1</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> file2
- </span>-rw-r--r-- <span style="color: #800080;">1</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> file3
- </span>-rw-r--r-- <span style="color: #800080;">1</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> file4
- </span>-rw-r--r-- <span style="color: #800080;">1</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> file5
- </span>-rw-r--r-- <span style="color: #800080;">1</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> file6
- </span>-rw-r--r-- <span style="color: #800080;">1</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> file7
- </span>-rw-r--r-- <span style="color: #800080;">1</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> file8
- </span>-rw-r--r-- <span style="color: #800080;">1</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> <span style="color: #800080;">0</span> Jan <span style="color: #800080;">06</span> <span style="color: #800080;">06</span>:<span style="color: #800080;">43</span><span style="color: #000000;"> file9
- lftp </span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span>:/pub><span style="color: #000000;"> exit
- </span><span style="color: #800080;">2</span><span style="color: #000000;">) 本地用户访问 lftp工具:
- 对于本地用户来说,它的共享目录是他的家目录.
- lftp testuser@</span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span><span style="color: #000000;">
- [root@rhel7 </span>~]# lftp testuser@<span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span><span style="color: #000000;">
- Password:
- lftp testuser@</span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span>:~> <span style="color: #0000ff;">ls</span>
- <span style="color: #0000ff;">ls</span>: Login failed: <span style="color: #800080;">500</span> OOPS: cannot change directory:/home/<span style="color: #000000;">testuser
- lftp testuser@</span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span>:~><span style="color: #000000;">
- 读取不到家目录下文件的原因是selinux造成的
- 需要打开setsebool </span>-P ftp_home_dir <span style="color: #800080;">1</span>
- <span style="color: #800080;">7</span><span style="color: #000000;">.下载
- lftp登陆以后,使用get去下载
- lftp </span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span>:/pub><span style="color: #000000;"> get file1
- 下载的位置是在你当前位置.
- </span><span style="color: #800080;">8</span><span style="color: #000000;">.上传
- 本地用户的上传: lftp 登陆以后,使用put去上传
- lftp testuser@</span><span style="color: #800080;">172.25</span>.<span style="color: #800080;">0.11</span>:~><span style="color: #000000;"> put testuserfile
- 可以通过绝对路径上传我们当前位置所在目录下的文件
- 匿名用户的上传:
- </span><span style="color: #800080;">1</span><span style="color: #000000;">) 程序限制
- vim </span>/etc/vsftpd/<span style="color: #000000;">vsftpd.conf
- 打开anon_upload_enable</span>=<span style="color: #000000;">YES
- </span><span style="color: #800080;">2</span><span style="color: #000000;">) UGO 给ftp用户进入目录所用的rwx权限.
- </span><span style="color: #800080;">3</span><span style="color: #000000;">) selinux权限
- semanage fcontext </span>-a -t public_content_rw_t pub -->注意路径 /var/<span style="color: #0000ff;">ftp</span>/<span style="color: #000000;">pub
- restorecon </span>-R -v pub -->针对的是 /var/<span style="color: #0000ff;">ftp</span>/<span style="color: #000000;">pub
- setsebool </span>-P allow_ftpd_anon_write <span style="color: #800080;">1</span>
- <span style="color: #800080;">9</span><span style="color: #000000;">.黑白名单
- 黑名单:</span>/etc/vsftpd/<span style="color: #000000;">ftpusers
- 在主配置文件里面有一行参数:userlist_enable</span>=<span style="color: #000000;">YES
- 如果参数是YES,则代表</span>/etc/vsftpd/<span style="color: #000000;">user_list是黑名单.
- 如果参数是NO,则代表</span>/etc/vsftpd/<span style="color: #000000;">user_list是白名单.
- 如果没有该行配置,默认参数是NO.
- </span><span style="color: #0000ff;">man</span> <span style="color: #800080;">5</span> vsftpd.conf
零基础学习云计算及大数据DBA集群架构师【Linux系统\网络服务及安全配置2015年1月4日周一】
标签: