This shows you the differences between two versions of the page.
Next revision Both sides next revision | |||
cluster:154 [2017/03/03 19:02] hmeij07 created |
cluster:154 [2017/03/03 19:14] hmeij07 [OpenHPC] |
||
---|---|---|---|
Line 5: | Line 5: | ||
* install vanilla CentOS 7.2 | * install vanilla CentOS 7.2 | ||
+ | * find Install_guide-CentOS7.2-SLURM-1.2.1-x86_64.pdf recipe guide on http:// | ||
+ | * turn selinux off | ||
+ | * next switch to iptables | ||
+ | |||
+ | < | ||
+ | |||
+ | [root@ohpc0-test ~]# systemctl stop firewalld | ||
+ | [root@ohpc0-test ~]# systemctl disable firewalld | ||
+ | |||
+ | [root@ohpc0-test ~]# yum install iptables-services -y | ||
+ | [root@ohpc0-test ~]# systemctl enable iptables | ||
+ | [root@ohpc0-test ~]# systemctl enable ip6tables | ||
+ | |||
+ | [root@ohpc0-test ~]# vi / | ||
+ | |||
+ | # lock up port 22 | ||
+ | -A INPUT -i eth0 -p tcp -m state --state NEW -m tcp -s 129.133.0.0/ | ||
+ | |||
+ | # local allow: note eth1 | ||
+ | -A INPUT -i eth1 -d 192.168.0.0/ | ||
+ | -A INPUT -i eth1 -d 192.168.0.0/ | ||
+ | |||
+ | [root@ohpc0-test ~]# vi / | ||
+ | |||
+ | # comment out port 22 | ||
+ | |||
+ | [root@ohpc0-test ~]# systemctl restart iptables | ||
+ | [root@ohpc0-test ~]# systemctl restart ip6tables | ||
+ | [root@ohpc0-test ~]# iptables -L | ||
+ | Chain INPUT (policy ACCEPT) | ||
+ | target | ||
+ | ACCEPT | ||
+ | ACCEPT | ||
+ | ACCEPT | ||
+ | ACCEPT | ||
+ | ACCEPT | ||
+ | ACCEPT | ||
+ | REJECT | ||
+ | |||
+ | Chain FORWARD (policy ACCEPT) | ||
+ | target | ||
+ | REJECT | ||
+ | |||
+ | Chain OUTPUT (policy ACCEPT) | ||
+ | target | ||
+ | |||
+ | [root@ohpc0-test ~]# reboot | ||
+ | |||
+ | </ | ||
- | * disable firewalld, install iptables | ||
- | * | ||
\\ | \\ | ||
**[[cluster: | **[[cluster: |