This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
cluster:154 [2017/04/05 12:36] hmeij07 |
cluster:154 [2018/08/17 12:48] (current) hmeij07 |
||
---|---|---|---|
Line 10: | Line 10: | ||
< | < | ||
- | + | ||
- | [root@ohpc0-test ~]# systemctl | + | [root@ohpc0-test ~]# systemctl |
+ | |||
[root@ohpc0-test ~]# systemctl disable firewalld | [root@ohpc0-test ~]# systemctl disable firewalld | ||
- | [root@ohpc0-test ~]# yum install iptables-services -y | + | [root@ohpc0-test ~]# yum install iptables-services -y |
+ | |||
[root@ohpc0-test ~]# systemctl enable iptables | [root@ohpc0-test ~]# systemctl enable iptables | ||
- | [root@ohpc0-test ~]# systemctl enable ip6tables | ||
[root@ohpc0-test ~]# vi / | [root@ohpc0-test ~]# vi / | ||
# lock up port 22: note " | # lock up port 22: note " | ||
- | -A INPUT -i enp8s0 | + | -A INPUT -p tcp -m state --state NEW -m tcp -s 129.133.0.0/ |
# local allow: note " | # local allow: note " | ||
- | -A INPUT -i enp4s0 | + | -A INPUT -d 192.168.0.0/ |
- | -A INPUT -i enp4s0 | + | -A INPUT -d 192.168.0.0/ |
- | [root@ohpc0-test ~]# vi / | + | [root@ohpc0-test ~]# reboot |
- | # comment out port 22 | + | # check firwewall |
- | + | ||
- | [root@ohpc0-test ~]# systemctl restart iptables | + | |
- | [root@ohpc0-test ~]# systemctl restart ip6tables | + | |
[root@ohpc0-test ~]# iptables -L | [root@ohpc0-test ~]# iptables -L | ||
Chain INPUT (policy ACCEPT) | Chain INPUT (policy ACCEPT) | ||
- | target | + | ... |
- | ACCEPT | + | |
- | ACCEPT | + | |
- | ACCEPT | + | |
ACCEPT | ACCEPT | ||
ACCEPT | ACCEPT | ||
Line 44: | Line 39: | ||
REJECT | REJECT | ||
- | Chain FORWARD (policy ACCEPT) | + | # copy global hpc /etc/hosts in place |
- | target | + | # check hostname is on provisioning network |
- | REJECT | + | [root@ohpc0-test ~]# ping `hostname` |
- | + | PING ohpc0-test (192.168.1.249) 56(84) bytes of data. | |
- | Chain OUTPUT (policy ACCEPT) | + | 64 bytes from ohpc0-test (192.168.1.249): |
- | target | + | |
- | + | ||
- | [root@ohpc0-test ~]# reboot | + | |
</ | </ |