{"id":992,"date":"2023-04-14T19:50:52","date_gmt":"2023-02-03T11:27:59","guid":{"rendered":"https:\/\/www.silicloud.com\/ja\/blog\/index.php\/2023\/11\/30\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/"},"modified":"2025-08-01T04:06:40","modified_gmt":"2025-07-31T19:06:40","slug":"%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/","title":{"rendered":"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u3001Iptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5"},"content":{"rendered":"<h3>\u306f\u3058\u3081\u306b<\/h3>\n<p>\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u306b\u304a\u3044\u3066\u3001\u7570\u306a\u308b\u30ce\u30fc\u30c9\u306b\u5206\u6563\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3092\u5c55\u958b\u3059\u308b\u3053\u3068\u306f\u3001\u8ca0\u8377\u3092\u6e1b\u3089\u3057\u3001\u6c34\u5e73\u65b9\u5411\u306b\u62e1\u5f35\u3059\u308b\u4e00\u822c\u7684\u306a\u65b9\u6cd5\u3067\u3059\u3002\u5178\u578b\u7684\u306a\u4f8b\u3068\u3057\u3066\u306f\u3001\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u3092\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3068\u306f\u5225\u306e\u30b5\u30fc\u30d0\u30fc\u306b\u914d\u7f6e\u3059\u308b\u3053\u3068\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306e\u3088\u3046\u306a\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u306b\u306f\u591a\u304f\u306e\u5229\u70b9\u304c\u3042\u308a\u307e\u3059\u304c\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7d4c\u7531\u3067\u306e\u63a5\u7d9a\u306b\u306f\u65b0\u305f\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u61f8\u5ff5\u304c\u4f34\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30ac\u30a4\u30c9\u3067\u306f\u3001\u5206\u6563\u578b\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u306b\u304a\u3044\u3066\u3001\u5404\u30b5\u30fc\u30d0\u30fc\u306b\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3092\u8a2d\u5b9a\u3059\u308b\u65b9\u6cd5\u3092\u8aac\u660e\u3057\u307e\u3059\u3002\u79c1\u305f\u3061\u306f\u3001\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u9593\u306e\u610f\u56f3\u3057\u305f\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u8a31\u53ef\u3057\u3001\u4ed6\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u62d2\u5426\u3059\u308b\u30dd\u30ea\u30b7\u30fc\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<p>\u3042\u306a\u305f\u306f\u30c7\u30b8\u30bf\u30eb\u30aa\u30fc\u30b7\u30e3\u30f3\u306e\u30af\u30e9\u30a6\u30c9\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3082\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u30c7\u30b8\u30bf\u30eb\u30aa\u30fc\u30b7\u30e3\u30f3\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u4e0a\u306e\u30b5\u30fc\u30d0\u30fc\u306e\u8ffd\u52a0\u7684\u306a\u5916\u90e8\u5c64\u3068\u3057\u3066\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u30b5\u30fc\u30d0\u30fc\u81ea\u4f53\u306b\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3092\u8a2d\u5b9a\u3059\u308b\u5fc5\u8981\u306f\u3042\u308a\u307e\u305b\u3093\u3002<\/p>\n<p>\u3053\u306e\u30ac\u30a4\u30c9\u306e\u30c7\u30e2\u30f3\u30b9\u30c8\u30ec\u30fc\u30b7\u30e7\u30f3\u3067\u306f\u30012\u3064\u306eUbuntu 22.04\u30b5\u30fc\u30d0\u30fc\u3092\u4f7f\u7528\u3057\u307e\u3059\u30021\u3064\u306fNginx\u3067\u63d0\u4f9b\u3055\u308c\u308bWeb\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u6301\u3061\u3001\u3082\u30461\u3064\u306f\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306eMySQL\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u3092\u30db\u30b9\u30c8\u3057\u307e\u3059\u3002\u3053\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u306f\u4f8b\u3068\u3057\u3066\u4f7f\u7528\u3057\u307e\u3059\u304c\u3001\u3042\u306a\u305f\u81ea\u8eab\u306e\u30b5\u30fc\u30d0\u30fc\u306e\u8981\u4ef6\u306b\u5408\u308f\u305b\u3066\u6280\u8853\u3092\u63a8\u6e2c\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u306f\u305a\u3067\u3059\u3002<\/p>\n<h3>\u524d\u63d0\u6761\u4ef6<\/h3>\n<p>\u59cb\u3081\u308b\u305f\u3081\u306b\u306f\u3001\u65b0\u3057\u3044Ubuntu 22.04\u30b5\u30fc\u30d0\u30fc\u30922\u3064\u6e96\u5099\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u305d\u308c\u305e\u308c\u306bsudo\u6a29\u9650\u3092\u6301\u3064\u901a\u5e38\u306e\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002\u3053\u308c\u3092\u884c\u3046\u305f\u3081\u306b\u306f\u3001\u5f53\u793e\u306eUbuntu 22.04\u521d\u671f\u30b5\u30fc\u30d0\u30fc\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u30ac\u30a4\u30c9\u306b\u5f93\u3063\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u3053\u306e\u30ac\u30a4\u30c9\u306b\u57fa\u3065\u3044\u3066\u3001\u79c1\u305f\u3061\u304c\u4fdd\u8b77\u3059\u308b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u3092\u884c\u3044\u307e\u3059\u3002\u3082\u3057\u540c\u3058\u4f8b\u306b\u6cbf\u3063\u3066\u9032\u3081\u305f\u3044\u5834\u5408\u306f\u3001\u305d\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u306b\u793a\u3055\u308c\u3066\u3044\u308b\u901a\u308a\u306b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3068\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u3092\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u305d\u308c\u4ee5\u5916\u306e\u5834\u5408\u306f\u3001\u3053\u306e\u8a18\u4e8b\u3092\u4e00\u822c\u7684\u306a\u53c2\u8003\u3068\u3057\u3066\u3054\u5229\u7528\u3044\u305f\u3060\u3051\u307e\u3059\u3002<\/p>\n<h2>\u30b9\u30c6\u30c3\u30d71\u301c\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u8a2d\u5b9a<\/h2>\n<p>\u6700\u521d\u306b\u3001\u30b5\u30fc\u30d0\u30fc\u3054\u3068\u306b\u30d9\u30fc\u30b9\u30e9\u30a4\u30f3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u8a2d\u5b9a\u3092\u5b9f\u88c5\u3057\u307e\u3059\u3002\u79c1\u305f\u3061\u304c\u5b9f\u65bd\u3059\u308b\u30dd\u30ea\u30b7\u30fc\u306f\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u6700\u512a\u5148\u306b\u8003\u3048\u3066\u3044\u307e\u3059\u3002SSH\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u4ee5\u5916\u306e\u307b\u3068\u3093\u3069\u3059\u3079\u3066\u3092\u5236\u9650\u3057\u3001\u305d\u306e\u5f8c\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306b\u7279\u5b9a\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u7528\u306e\u7a74\u3092\u958b\u3051\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30ac\u30a4\u30c9\u306fiptables\u306e\u69cb\u6587\u306b\u5f93\u3044\u307e\u3059\u3002Ubuntu 22.04\u3067\u306f\u3001nftables\u30d0\u30c3\u30af\u30a8\u30f3\u30c9\u3092\u4f7f\u7528\u3057\u3066iptables\u304c\u81ea\u52d5\u7684\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u308b\u305f\u3081\u3001\u8ffd\u52a0\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u5fc5\u8981\u306f\u3042\u308a\u307e\u305b\u3093\u3002<\/p>\n<p>\u30ca\u30ce\u307e\u305f\u306f\u304a\u6c17\u306b\u5165\u308a\u306e\u30c6\u30ad\u30b9\u30c8\u30a8\u30c7\u30a3\u30bf\u3092\u4f7f\u7528\u3057\u3066\u3001\/etc\/iptables\/rules.v4 \u30d5\u30a1\u30a4\u30eb\u3092\u958b\u3044\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">nano<\/span> \/etc\/iptables\/rules.v4<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u30ac\u30a4\u30c9\u304b\u3089\u8a2d\u5b9a\u3092\u8cbc\u308a\u4ed8\u3051\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<div>\n<p>\/etc\/iptables\/rules.v4\u306e\u6587\u3092\u65e5\u672c\u8a9e\u3067\u8a00\u3044\u63db\u3048\u308b\u3068\u6b21\u306e\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>&#8211; \/etc\/iptables\/rules.v4<\/p>\n<\/div>\n<pre class=\"post-pre\"><code>*filter\r\n# Allow all outgoing, but drop incoming and forwarding packets by default\r\n:INPUT DROP [0:0]\r\n:FORWARD DROP [0:0]\r\n:OUTPUT ACCEPT [0:0]\r\n\r\n# Custom per-protocol chains\r\n:UDP - [0:0]\r\n:TCP - [0:0]\r\n:ICMP - [0:0]\r\n\r\n# Acceptable UDP traffic\r\n\r\n# Acceptable TCP traffic\r\n-A TCP -p tcp --dport 22 -j ACCEPT\r\n\r\n# Acceptable ICMP traffic\r\n\r\n# Boilerplate acceptance policy\r\n-A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT\r\n-A INPUT -i lo -j ACCEPT\r\n\r\n# Drop invalid packets\r\n-A INPUT -m conntrack --ctstate INVALID -j DROP\r\n\r\n# Pass traffic to protocol-specific chains\r\n## Only allow new connections (established and related should already be handled)\r\n## For TCP, additionally only allow new SYN packets since that is the only valid\r\n## method for establishing a new TCP connection\r\n-A INPUT -p udp -m conntrack --ctstate NEW -j UDP\r\n-A INPUT -p tcp --syn -m conntrack --ctstate NEW -j TCP\r\n-A INPUT -p icmp -m conntrack --ctstate NEW -j ICMP\r\n\r\n# Reject anything that's fallen through to this point\r\n## Try to be protocol-specific w\/ rejection message\r\n-A INPUT -p udp -j REJECT --reject-with icmp-port-unreachable\r\n-A INPUT -p tcp -j REJECT --reject-with tcp-reset\r\n-A INPUT -j REJECT --reject-with icmp-proto-unreachable\r\n\r\n# Commit the changes\r\nCOMMIT\r\n\r\n*raw\r\n:PREROUTING ACCEPT [0:0]\r\n:OUTPUT ACCEPT [0:0]\r\nCOMMIT\r\n\r\n*nat\r\n:PREROUTING ACCEPT [0:0]\r\n:INPUT ACCEPT [0:0]\r\n:OUTPUT ACCEPT [0:0]\r\n:POSTROUTING ACCEPT [0:0]\r\nCOMMIT\r\n\r\n*security\r\n:INPUT ACCEPT [0:0]\r\n:FORWARD ACCEPT [0:0]\r\n:OUTPUT ACCEPT [0:0]\r\nCOMMIT\r\n\r\n*mangle\r\n:PREROUTING ACCEPT [0:0]\r\n:INPUT ACCEPT [0:0]\r\n:FORWARD ACCEPT [0:0]\r\n:OUTPUT ACCEPT [0:0]\r\n:POSTROUTING ACCEPT [0:0]\r\nCOMMIT\r\n<\/code><\/pre>\n<p>\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\u3057\u3066\u9589\u3058\u3066\u304f\u3060\u3055\u3044\u3002\u3082\u3057nano\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u5834\u5408\u306f\u3001\u7d42\u4e86\u3059\u308b\u305f\u3081\u306bCtrl+X\u3092\u62bc\u3057\u3001\u6b21\u306b\u30d7\u30ed\u30f3\u30d7\u30c8\u304c\u8868\u793a\u3055\u308c\u305f\u3089Y\u3068Enter\u3092\u62bc\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u3082\u3057\u3082\u3053\u308c\u3092\u5b9f\u969b\u306e\u74b0\u5883\u3067\u5b9f\u884c\u3059\u308b\u5834\u5408\u306f\u3001\u307e\u3060\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30eb\u30fc\u30eb\u3092\u518d\u8aad\u307f\u8fbc\u307f\u3057\u306a\u3044\u3067\u304f\u3060\u3055\u3044\u3002\u3053\u3053\u3067\u793a\u3055\u308c\u305f\u30eb\u30fc\u30eb\u30bb\u30c3\u30c8\u3092\u8aad\u307f\u8fbc\u3080\u3068\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3068\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u63a5\u7d9a\u304c\u76f4\u3061\u306b\u5207\u65ad\u3055\u308c\u307e\u3059\u3002\u518d\u8aad\u307f\u8fbc\u307f\u3059\u308b\u524d\u306b\u3001\u904b\u7528\u4e0a\u306e\u30cb\u30fc\u30ba\u306b\u5408\u308f\u305b\u3066\u30eb\u30fc\u30eb\u3092\u8abf\u6574\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<h2>\u30b9\u30c6\u30c3\u30d72 &#8211; \u30b5\u30fc\u30d3\u30b9\u3067\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u30dd\u30fc\u30c8\u3092\u7279\u5b9a\u3059\u308b<\/h2>\n<p>\u81ea\u5206\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u9593\u3067\u901a\u4fe1\u3092\u8a31\u53ef\u3059\u308b\u305f\u3081\u306b\u306f\u3001\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30dd\u30fc\u30c8\u3092\u628a\u63e1\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u69cb\u6210\u30d5\u30a1\u30a4\u30eb\u3092\u8abf\u3079\u308b\u3053\u3068\u3067\u6b63\u3057\u3044\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30dd\u30fc\u30c8\u3092\u898b\u3064\u3051\u308b\u3053\u3068\u3082\u3067\u304d\u307e\u3059\u304c\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u4f9d\u5b58\u3057\u306a\u3044\u6b63\u3057\u3044\u30dd\u30fc\u30c8\u3092\u898b\u3064\u3051\u308b\u65b9\u6cd5\u306f\u3001\u5404\u30de\u30b7\u30f3\u4e0a\u3067\u63a5\u7d9a\u5f85\u3061\u306e\u30b5\u30fc\u30d3\u30b9\u3092\u78ba\u8a8d\u3059\u308b\u3060\u3051\u3067\u3059\u3002<\/p>\n<p>\u3053\u308c\u3092\u78ba\u8a8d\u3059\u308b\u305f\u3081\u306b\u3001netstat\u30c4\u30fc\u30eb\u3092\u4f7f\u7528\u3067\u304d\u307e\u3059\u3002\u3042\u306a\u305f\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306fIPv4\u306e\u307f\u3092\u4f7f\u7528\u3057\u3066\u901a\u4fe1\u3057\u3066\u3044\u308b\u305f\u3081\u3001-4\u5f15\u6570\u3092\u8ffd\u52a0\u3057\u307e\u3059\u304c\u3001IPv6\u3082\u4f7f\u7528\u3057\u3066\u3044\u308b\u5834\u5408\u306f\u305d\u308c\u3092\u524a\u9664\u3067\u304d\u307e\u3059\u3002\u5b9f\u884c\u4e2d\u306e\u30b5\u30fc\u30d3\u30b9\u3092\u898b\u3064\u3051\u308b\u305f\u3081\u306b\u5fc5\u8981\u306a\u4ed6\u306e\u5f15\u6570\u306f\u3001-p\u3001-l\u3001-u\u3001-n\u3001\u304a\u3088\u3073 -t\u3067\u3059\u3002\u3053\u308c\u3089\u306f\u3001-plunt\u3068\u3057\u3066\u63d0\u4f9b\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u8b70\u8ad6\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u5206\u89e3\u3067\u304d\u307e\u3059\u3002<\/p>\n<ul class=\"post-ul\">\n<li>p: Show the PID and name of the program to which each socket belongs.<\/li>\n<li>l: Show only listening sockets.<\/li>\n<li>u: Show UDP traffic.<\/li>\n<li>n: Show numeric output instead of service names.<\/li>\n<li>t: Show TCP traffic.<\/li>\n<\/ul>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"web_server$\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">netstat<\/span> <span class=\"token parameter variable\">-4plunt<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u3042\u306a\u305f\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u30fc\u3067\u306f\u3001\u51fa\u529b\u306f\u6b21\u306e\u3088\u3046\u306b\u306a\u308b\u304b\u3082\u3057\u308c\u307e\u305b\u3093:<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div class=\"secondary-code-label\" title=\"Output\">Output<\/div>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID\/Program name tcp 0 0 <mark>0.0.0.0:22<\/mark> 0.0.0.0:* LISTEN 1058\/<mark>sshd<\/mark> tcp 0 0 <mark>0.0.0.0:80<\/mark> 0.0.0.0:* LISTEN 4187\/<mark>nginx<\/mark><\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u6700\u521d\u306b\u30cf\u30a4\u30e9\u30a4\u30c8\u3055\u308c\u305f\u5217\u306f\u3001\u884c\u306e\u6700\u5f8c\u306b\u30cf\u30a4\u30e9\u30a4\u30c8\u3055\u308c\u305f\u30b5\u30fc\u30d3\u30b9\u304c\u30ea\u30c3\u30b9\u30f3\u3057\u3066\u3044\u308bIP\u30a2\u30c9\u30ec\u30b9\u3068\u30dd\u30fc\u30c8\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u7279\u5225\u306a0.0.0.0\u30a2\u30c9\u30ec\u30b9\u306f\u3001\u8a72\u5f53\u3059\u308b\u30b5\u30fc\u30d3\u30b9\u304c\u5229\u7528\u53ef\u80fd\u306a\u3059\u3079\u3066\u306e\u30a2\u30c9\u30ec\u30b9\u3067\u30ea\u30c3\u30b9\u30f3\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u610f\u5473\u3057\u307e\u3059\u3002<\/p>\n<p>\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u4e0a\u306e\u51fa\u529b\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u306a\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"db_server$\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">netstat<\/span> <span class=\"token parameter variable\">-4plunt<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div class=\"secondary-code-label\" title=\"Output\">Output<\/div>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID\/Program name tcp 0 0 <mark>0.0.0.0:22<\/mark> 0.0.0.0:* LISTEN 1097\/<mark>sshd<\/mark> tcp 0 0 <mark>192.0.2.30:3306<\/mark> 0.0.0.0:* LISTEN 3112\/<mark>mysqld<\/mark><\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u3053\u308c\u3089\u306e\u5217\u306f\u307e\u3063\u305f\u304f\u540c\u3058\u3088\u3046\u306b\u8aad\u3081\u307e\u3059\u3002\u3053\u306e\u4f8b\u3067\u306f\u3001192.0.2.30\u306e\u30a2\u30c9\u30ec\u30b9\u306f\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u306e\u30d7\u30e9\u30a4\u30d9\u30fc\u30c8IP\u30a2\u30c9\u30ec\u30b9\u3092\u8868\u3057\u3066\u3044\u307e\u3059\u3002\u524d\u63d0\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3067\u306f\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u7406\u7531\u304b\u3089MySQL\u3092\u30d7\u30e9\u30a4\u30d9\u30fc\u30c8\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u306b\u5236\u9650\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u306e\u30b9\u30c6\u30c3\u30d7\u3067\u898b\u3064\u3051\u305f\u5024\u3092\u30e1\u30e2\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u3053\u308c\u306f\u3001\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u8a2d\u5b9a\u3092\u8abf\u6574\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u306a\u30cd\u30c3\u30c8\u30ef\u30fc\u30ad\u30f3\u30b0\u306e\u8a73\u7d30\u3067\u3059\u3002<\/p>\n<p>\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u30fc\u4e0a\u3067\u3001\u4ee5\u4e0b\u306e\u30dd\u30fc\u30c8\u304c\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u3067\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<ul class=\"post-ul\">\n<li>Port 80 on all addresses<\/li>\n<li>Port 22 on all addresses (already accounted for in firewall rules)<\/li>\n<\/ul>\n<p>\u3042\u306a\u305f\u306e\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u306f\u3001\u6b21\u306e\u30dd\u30fc\u30c8\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<ul class=\"post-ul\">\n<li>Port 3306 on the address 192.0.2.30 (or the interface associated with it)<\/li>\n<li>Port 22 on all addresses (already accounted for in firewall rules)<\/li>\n<\/ul>\n<h2>\u30b9\u30c6\u30c3\u30d73 \u2014 \u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u306e\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u30eb\u30fc\u30eb\u3092\u8abf\u6574\u3057\u307e\u3059\u3002<\/h2>\n<p>\u5fc5\u8981\u306a\u30dd\u30fc\u30c8\u60c5\u5831\u304c\u5165\u624b\u3067\u304d\u305f\u306e\u3067\u3001\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u30fc\u306e\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30eb\u30fc\u30eb\u30bb\u30c3\u30c8\u3092\u8abf\u6574\u3057\u307e\u3059\u3002sudo\u7279\u6a29\u3067\u30a8\u30c7\u30a3\u30bf\u3067\u30eb\u30fc\u30eb\u30d5\u30a1\u30a4\u30eb\u3092\u958b\u3044\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"web_server$\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">nano<\/span> \/etc\/iptables\/rules.v4<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u30fc\u4e0a\u3067\u3001\u8a31\u53ef\u3055\u308c\u308b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u30ea\u30b9\u30c8\u306b\u30dd\u30fc\u30c880\u3092\u8ffd\u52a0\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u30b5\u30fc\u30d0\u30fc\u306f\u5229\u7528\u53ef\u80fd\u306a\u30a2\u30c9\u30ec\u30b9\u5168\u3066\u3067\u30ea\u30c3\u30b9\u30f3\u3057\u3066\u3044\u308b\u305f\u3081\u3001\u901a\u5e38\u306f\u3069\u3053\u304b\u3089\u3067\u3082\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306a\u3053\u3068\u3092\u60f3\u5b9a\u3057\u3066\u3044\u307e\u3059\u3002\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u3084\u5b9b\u5148\u30a2\u30c9\u30ec\u30b9\u306b\u3088\u3063\u3066\u30eb\u30fc\u30eb\u3092\u5236\u9650\u3057\u306a\u3044\u3067\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u3042\u306a\u305f\u306e\u30a6\u30a7\u30d6\u8a2a\u554f\u8005\u306f\u3001TCP\u30d7\u30ed\u30c8\u30b3\u30eb\u3092\u4f7f\u7528\u3057\u3066\u63a5\u7d9a\u3057\u307e\u3059\u3002\u3042\u306a\u305f\u306e\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u306b\u306f\u3059\u3067\u306b\u3001TCP\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u4f8b\u5916\u7528\u306e\u30ab\u30b9\u30bf\u30e0\u30c1\u30a7\u30a4\u30f3\u304c\u3042\u308a\u307e\u3059\u3002\u3042\u306a\u305f\u306f\u305d\u306e\u30c1\u30a7\u30a4\u30f3\u306b\u3001SSH\u30dd\u30fc\u30c8\u306e\u4f8b\u5916\u306e\u3059\u3050\u4e0b\u306b\u30dd\u30fc\u30c880\u3092\u8ffd\u52a0\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<div>\u4ee5\u4e0b\u306f\u65e5\u672c\u8a9e\u3067\u306e\u8868\u73fe\u4f8b\u3067\u3059\uff1a<br \/>\n\u300c\/etc\/iptables\/rules.v4\u300d<\/div>\n<pre class=\"post-pre\"><code>*filter\r\n. . .\r\n\r\n# Acceptable TCP traffic\r\n-A TCP -p tcp --dport 22 -j ACCEPT\r\n<mark>-A TCP -p tcp --dport 80 -j ACCEPT<\/mark>\r\n\r\n. . .\r\n<\/code><\/pre>\n<p>\u3042\u306a\u305f\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u30fc\u304c\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u63a5\u7d9a\u3092\u958b\u59cb\u3057\u307e\u3059\u3002\u3042\u306a\u305f\u306e\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3067\u306f\u9001\u4fe1\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u5236\u9650\u306f\u306a\u304f\u3001\u78ba\u7acb\u3055\u308c\u305f\u63a5\u7d9a\u306b\u95a2\u9023\u3059\u308b\u53d7\u4fe1\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3082\u8a31\u53ef\u3055\u308c\u3066\u3044\u308b\u305f\u3081\u3001\u3053\u306e\u63a5\u7d9a\u3092\u8a31\u53ef\u3059\u308b\u305f\u3081\u306b\u3053\u306e\u30b5\u30fc\u30d0\u30fc\u3067\u8ffd\u52a0\u306e\u30dd\u30fc\u30c8\u3092\u958b\u3051\u308b\u5fc5\u8981\u306f\u3042\u308a\u307e\u305b\u3093\u3002<\/p>\n<p>\u4f5c\u696d\u304c\u7d42\u4e86\u3057\u305f\u3089\u3001\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\u3057\u3066\u9589\u3058\u3066\u304f\u3060\u3055\u3044\u3002\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u30fc\u306b\u306f\u3001\u3059\u3079\u3066\u306e\u6b63\u898f\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u8a31\u53ef\u3057\u3001\u305d\u308c\u4ee5\u5916\u306e\u3082\u306e\u306f\u3059\u3079\u3066\u30d6\u30ed\u30c3\u30af\u3059\u308b\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u30dd\u30ea\u30b7\u30fc\u304c\u8a2d\u5b9a\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<p>\u30eb\u30fc\u30eb\u30d5\u30a1\u30a4\u30eb\u306e\u69cb\u6587\u30a8\u30e9\u30fc\u3092\u30c6\u30b9\u30c8\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"web_server$\"><span class=\"token function\">sudo<\/span> iptables-restore <span class=\"token parameter variable\">-t<\/span> <span class=\"token operator\">&lt;<\/span> \/etc\/iptables\/rules.v4<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u69cb\u6587\u30a8\u30e9\u30fc\u304c\u8868\u793a\u3055\u308c\u306a\u3044\u5834\u5408\u306f\u3001\u65b0\u3057\u3044\u30eb\u30fc\u30eb\u30bb\u30c3\u30c8\u3092\u5b9f\u88c5\u3059\u308b\u305f\u3081\u306b\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3092\u518d\u8aad\u307f\u8fbc\u307f\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"web_server$\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">service<\/span> iptables-persistent reload<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<h2>\u30b9\u30c6\u30c3\u30d7\uff14 \u2014 \u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u306e\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u30eb\u30fc\u30eb\u3092\u8abf\u6574\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/h2>\n<p>\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u3067\u306f\u3001\u30b5\u30fc\u30d0\u30fc\u306e\u30d7\u30e9\u30a4\u30d9\u30fc\u30c8IP\u30a2\u30c9\u30ec\u30b9\u3067\u3042\u308b\u30dd\u30fc\u30c83306\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u8a31\u53ef\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306e\u5834\u5408\u3001\u305d\u306e\u30a2\u30c9\u30ec\u30b9\u306f192.0.2.30\u3067\u3057\u305f\u3002\u3053\u306e\u30a2\u30c9\u30ec\u30b9\u306b\u5bfe\u3057\u3066\u7279\u306b\u30a2\u30af\u30bb\u30b9\u3092\u5236\u9650\u3059\u308b\u3053\u3068\u3082\u3067\u304d\u307e\u3059\u3057\u3001\u305d\u306e\u30a2\u30c9\u30ec\u30b9\u306b\u5272\u308a\u5f53\u3066\u3089\u308c\u3066\u3044\u308b\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u306b\u5bfe\u3057\u3066\u4e00\u81f4\u3055\u305b\u308b\u3053\u3068\u3067\u3082\u30a2\u30af\u30bb\u30b9\u3092\u5236\u9650\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u305d\u306e\u30a2\u30c9\u30ec\u30b9\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u3092\u898b\u3064\u3051\u308b\u306b\u306f\u3001ip -4 addr show scope global\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"db_server$\"><span class=\"token function\">ip<\/span> <span class=\"token parameter variable\">-4<\/span> addr show scope global<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div class=\"secondary-code-label\" title=\"Output\">Output<\/div>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>2: eth0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc pfifo_fast state UP group default qlen 1000 inet 203.0.113.5\/24 brd 104.236.113.255 scope global eth0 valid_lft forever preferred_lft forever 3: <mark>eth1<\/mark>: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc pfifo_fast state UP group default qlen 1000 inet <mark>192.0.2.30<\/mark>\/24 brd 192.0.2.255 scope global eth1 valid_lft forever preferred_lft forever<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u30cf\u30a4\u30e9\u30a4\u30c8\u3055\u308c\u305f\u9818\u57df\u306f\u3001eth1\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u304c\u305d\u306e\u30a2\u30c9\u30ec\u30b9\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u6b21\u306b\u3001\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u306e\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30eb\u30fc\u30eb\u3092\u8abf\u6574\u3057\u307e\u3059\u3002\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u3067sudo\u6a29\u9650\u3092\u6301\u3063\u3066\u3044\u308b\u72b6\u614b\u3067\u30eb\u30fc\u30eb\u30d5\u30a1\u30a4\u30eb\u3092\u958b\u3044\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"db_server$\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">nano<\/span> \/etc\/iptables\/rules.v4<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u3042\u306a\u305f\u306f\u518d\u3073\u3001\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u30fc\u3068\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30b5\u30fc\u30d0\u30fc\u306e\u63a5\u7d9a\u306b\u4f8b\u5916\u3092\u5f62\u6210\u3059\u308b\u305f\u3081\u306b\u3001\u79c1\u305f\u3061\u306eTCP\u30c1\u30a7\u30fc\u30f3\u306b\u30eb\u30fc\u30eb\u3092\u8ffd\u52a0\u3059\u308b\u3053\u3068\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>\u8a72\u5f53\u3059\u308b\u5b9f\u969b\u306e\u30a2\u30c9\u30ec\u30b9\u306b\u57fa\u3065\u3044\u3066\u30a2\u30af\u30bb\u30b9\u3092\u5236\u9650\u3059\u308b\u5834\u5408\u3001\u6b21\u306e\u3088\u3046\u306b\u30eb\u30fc\u30eb\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/p>\n<div>\/etc\/iptables\/rules.v4\u3092\u65e5\u672c\u8a9e\u3067\u8a00\u3044\u63db\u3048\u308b\u3068\u300c\/etc\/iptables\/rules.v4\u300d\u3068\u306a\u308a\u307e\u3059\u3002<\/div>\n<pre class=\"post-pre\"><code>*filter\r\n. . .\r\n\r\n# Acceptable TCP traffic\r\n-A TCP -p tcp --dport 22 -j ACCEPT\r\n<mark>-A TCP -p tcp --dport 3306 -d 192.0.2.30 -j ACCEPT<\/mark>\r\n\r\n. . .\r\n<\/code><\/pre>\n<p>\u3082\u3057\u3082\u305d\u306e\u30a2\u30c9\u30ec\u30b9\u3092\u542b\u3080\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u306b\u57fa\u3065\u3044\u3066\u4f8b\u5916\u3092\u8a31\u53ef\u3057\u305f\u3044\u306e\u3067\u3042\u308c\u3070\u3001\u4ee3\u308f\u308a\u306b\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30eb\u30fc\u30eb\u3092\u8ffd\u52a0\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<div>\/etc\/iptables\/rules.v4 \u3092\u65e5\u672c\u8a9e\u3067\u4e00\u3064\u306e\u30aa\u30d7\u30b7\u30e7\u30f3\u3067\u8a00\u3044\u63db\u3048\u3066\u304f\u3060\u3055\u3044\u3002<\/div>\n<pre class=\"post-pre\"><code>*filter\r\n. . .\r\n\r\n# Acceptable TCP traffic\r\n-A TCP -p tcp --dport 22 -j ACCEPT\r\n<mark>-A TCP -p tcp --dport 3306 -i eth1 -j ACCEPT<\/mark>\r\n\r\n. . .\r\n<\/code><\/pre>\n<p>\u4f5c\u696d\u304c\u7d42\u308f\u3063\u305f\u3089\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\u3057\u3001\u9589\u3058\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u3053\u306e\u30b3\u30de\u30f3\u30c9\u3067\u69cb\u6587\u30a8\u30e9\u30fc\u3092\u30c1\u30a7\u30c3\u30af\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"db_server$\"><span class=\"token function\">sudo<\/span> iptables-restore <span class=\"token parameter variable\">-t<\/span> <span class=\"token operator\">&lt;<\/span> \/etc\/iptables\/rules.v4<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u6e96\u5099\u304c\u3067\u304d\u305f\u3089\u3001\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30eb\u30fc\u30eb\u3092\u30ea\u30ed\u30fc\u30c9\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"db_server$\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">service<\/span> iptables-persistent reload<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u4e21\u65b9\u306e\u30b5\u30fc\u30d0\u30fc\u306f\u3001\u5fc5\u8981\u306a\u30c7\u30fc\u30bf\u306e\u6d41\u308c\u3092\u5236\u9650\u305b\u305a\u306b\u4fdd\u8b77\u3055\u308c\u308b\u3079\u304d\u3067\u3059\u3002<\/p>\n<h2>\u7d50\u8ad6<\/h2>\n<p>\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u8a2d\u5b9a\u6642\u306b\u306f\u3001\u9069\u5207\u306a\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u5c0e\u5165\u306f\u5e38\u306b\u5c55\u958b\u8a08\u753b\u306e\u4e00\u90e8\u3067\u3042\u308b\u3079\u304d\u3067\u3059\u3002\u4e0a\u8a18\u3067\u793a\u3057\u305f\u8a2d\u5b9a\u306f\u3001Nginx\u3068MySQL\u3092\u5b9f\u884c\u3059\u308b\u4e8c\u3064\u306e\u30b5\u30fc\u30d0\u30fc\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u5177\u4f53\u7684\u306a\u6280\u8853\u306e\u9078\u629e\u306b\u95a2\u4fc2\u306a\u304f\u3001\u4e0a\u8a18\u3067\u793a\u3057\u305f\u6280\u8853\u306f\u9069\u7528\u53ef\u80fd\u3067\u3059\u3002<\/p>\n<p>\u7279\u306b\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3068iptables\u306b\u3064\u3044\u3066\u8a73\u3057\u304f\u5b66\u3073\u305f\u3044\u5834\u5408\u306f\u3001\u4ee5\u4e0b\u306e\u30ac\u30a4\u30c9\u3092\u53c2\u8003\u306b\u3057\u3066\u307f\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<ul class=\"post-ul\">\n<li>How To Choose an Effective Firewall Policy to Secure your Servers<\/li>\n<li>A Deep Dive into Iptables and Netfilter Architecture<\/li>\n<li>How To Test your Firewall Configuration with Nmap and Tcpdump<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u306f\u3058\u3081\u306b \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u306b\u304a\u3044\u3066\u3001\u7570\u306a\u308b\u30ce\u30fc\u30c9\u306b\u5206\u6563\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3092\u5c55\u958b\u3059\u308b\u3053\u3068\u306f\u3001\u8ca0\u8377\u3092\u6e1b\u3089\u3057\u3001\u6c34\u5e73\u65b9\u5411\u306b\u62e1\u5f35\u3059\u308b\u4e00\u822c\u7684\u306a\u65b9\u6cd5\u3067\u3059\u3002\u5178\u578b\u7684\u306a\u4f8b\u3068\u3057\u3066\u306f\u3001\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u3092\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3068\u306f\u5225\u306e\u30b5\u30fc\u30d0\u30fc\u306b\u914d [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[26,18],"class_list":["post-992","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-26","tag-18"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u3001Iptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5 - Blog - Silicon Cloud<\/title>\n<meta name=\"description\" content=\"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306bIptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/ja\/blog\/\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u3001Iptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5\" \/>\n<meta property=\"og:description\" content=\"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306bIptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/ja\/blog\/\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-02-03T11:27:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-31T19:06:40+00:00\" \/>\n<meta name=\"author\" content=\"\u512a\u6597, \u671d\u967d\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u57f7\u7b46\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u512a\u6597, \u671d\u967d\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u63a8\u5b9a\u8aad\u307f\u53d6\u308a\u6642\u9593\" \/>\n\t<meta name=\"twitter:data2\" content=\"19\u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/\",\"url\":\"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/\",\"name\":\"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u3001Iptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/#website\"},\"datePublished\":\"2023-02-03T11:27:59+00:00\",\"dateModified\":\"2025-07-31T19:06:40+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/cab7534c71201607a41f395de14d7d28\"},\"description\":\"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306bIptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002\",\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/#breadcrumb\"},\"inLanguage\":\"ja\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/ja\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u3001Iptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/ja\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"ja\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/cab7534c71201607a41f395de14d7d28\",\"name\":\"\u512a\u6597, \u671d\u967d\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ja\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/56ecb1d20648a2ff67709eeaa7b6eddeb4d52aca0d46febc7f12bbef507187d0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/56ecb1d20648a2ff67709eeaa7b6eddeb4d52aca0d46febc7f12bbef507187d0?s=96&d=mm&r=g\",\"caption\":\"\u512a\u6597, \u671d\u967d\"},\"url\":\"https:\/\/www.silicloud.com\/ja\/blog\/author\/yutoasahi\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"ja\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u3001Iptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5 - Blog - Silicon Cloud","description":"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306bIptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/ja\/blog\/\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\/","og_locale":"ja_JP","og_type":"article","og_title":"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u3001Iptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5","og_description":"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306bIptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002","og_url":"https:\/\/www.silicloud.com\/ja\/blog\/\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-02-03T11:27:59+00:00","article_modified_time":"2025-07-31T19:06:40+00:00","author":"\u512a\u6597, \u671d\u967d","twitter_card":"summary_large_image","twitter_misc":{"\u57f7\u7b46\u8005":"\u512a\u6597, \u671d\u967d","\u63a8\u5b9a\u8aad\u307f\u53d6\u308a\u6642\u9593":"19\u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/","url":"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/","name":"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u3001Iptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/ja\/blog\/#website"},"datePublished":"2023-02-03T11:27:59+00:00","dateModified":"2025-07-31T19:06:40+00:00","author":{"@id":"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/cab7534c71201607a41f395de14d7d28"},"description":"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306bIptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002","breadcrumb":{"@id":"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/ja\/blog\/"},{"@type":"ListItem","position":2,"name":"\u3042\u306a\u305f\u306e\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306b\u3001Iptables\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u65b9\u6cd5"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/ja\/blog\/#website","url":"https:\/\/www.silicloud.com\/ja\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/cab7534c71201607a41f395de14d7d28","name":"\u512a\u6597, \u671d\u967d","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/56ecb1d20648a2ff67709eeaa7b6eddeb4d52aca0d46febc7f12bbef507187d0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/56ecb1d20648a2ff67709eeaa7b6eddeb4d52aca0d46febc7f12bbef507187d0?s=96&d=mm&r=g","caption":"\u512a\u6597, \u671d\u967d"},"url":"https:\/\/www.silicloud.com\/ja\/blog\/author\/yutoasahi\/"},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/www.silicloud.com\/ja\/blog\/%e3%81%82%e3%81%aa%e3%81%9f%e3%81%ae%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e9%96%93%e3%81%ae%e3%83%88%e3%83%a9%e3%83%95%e3%82%a3%e3%83%83%e3%82%af%e3%82%92%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e3%81%9f\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/posts\/992","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/comments?post=992"}],"version-history":[{"count":1,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/posts\/992\/revisions"}],"predecessor-version":[{"id":47673,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/posts\/992\/revisions\/47673"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/media?parent=992"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/categories?post=992"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/tags?post=992"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}